Zero trust for operational technology is moving from vendor frameworks to federal guidance. NIST has published the Initial Public Draft of Special Publication 800-82 Revision 4, “Guide to Operational Technology (OT) Security,” dated September 21, 2026. This is an unapproved draft: the document’s approval date and final DOI are still marked as pending.
The revision expands beyond its previous industrial control systems (ICS) focus. It now covers building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and IIoT and cloud convergence.
NIST’s own summary of changes says the draft adds security architecture guidelines focused on protecting system management functions and applying zero trust principles, alongside a restructuring around the Cybersecurity Framework 2.0.
The draft recommends network separation, stating that OT networks be split from enterprise networks because traffic patterns, access needs, and change-management rigor differ. NIST warns that shared infrastructure exposes OT to denial-of-service and man-in-the-middle attacks, noting that “enterprise networks typically permit internet access, email, and remote access, incompatible with OT security.”
Because SP 800-82 anchors FISMA-driven programs, security leaders now have a citable standard for zero trust budget requests. Compliance teams will likely begin mapping to Revision 4 before it is finalized.
The comment window runs through November 30, 2026, with feedback going to sp800-82rev4@nist.gov and subject to FOIA. Security teams can use this window to flag legacy-protocol and availability constraints before the guidance is finalized.
Sources: NIST SP 800-82r4 (initial public draft), Industrial Cyber



Leave a Reply