A new draft guide wants to help organizations use artificial intelligence for cybersecurity work. The National Institute of Standards and Technology released NIST SP 1353 on August 19, 2026. It’s called the “Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting.” The document is an initial public draft. It carries the DOI 10.6028/NIST.SP.1353.ipd.
This guide is part of NIST’s CSF 2.0 quick-start resources page. CSF 2.0 stands for Cybersecurity Framework 2.0. It gives businesses, government agencies, and other groups a way to manage cybersecurity risks. The framework covers six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the newest addition. It sets CSF 2.0 apart from the earlier five-function version. NIST also offers separate quick-start guides tailored for small businesses with limited budgets and little to no existing cybersecurity framework.
SP 1353 shows practical ways AI can support CSF 2.0 work. It offers structured prompts that practitioners can use with generative AI tools. These prompts help create CSF-related artifacts. The draft doesn’t replace human judgment. Instead, it supports tasks like analyzing, planning, and monitoring progress toward CSF outcomes.
The guide includes three notional use cases. It also has example prompts for producing specific CSF 2.0 outputs. Simulated files from a fictitious company appear in the draft too. Tips for getting started with AI-assisted CSF work round out the content. NIST notes that these examples illustrate possible approaches and are not meant as prescriptive methodologies.
Three notional use cases, example prompts, and simulated files from a fictitious company show AI-assisted CSF work in action.
The prompts inside SP 1353 target several reporting needs. They support governance reviews. They help build current-state profiles. They also assist with target-state profile development. These outputs tie directly to CSF 2.0’s goal of helping organizations communicate cybersecurity risk and progress clearly.
NIST is accepting public comments on the draft. The comment period runs through October 15, 2026, at 11:59 PM. People can send feedback to the email address listed on the publication’s CSRC page.
This draft fits into a larger, growing set of CSF 2.0 resources. NIST continues to build out quick-start guides and informative references for organizations at any stage of cybersecurity maturity. SP 1353 appears in NIST’s recent news and CSRC updates as one of its 2026 draft releases. The guide reflects current thinking on how AI prompt engineering can support cybersecurity framework work today.
References
- https://csrc.nist.gov/pubs/sp/1353/ipd
- https://www.nist.gov/cyberframework/quick-start-guides
- https://www.nist.gov/cyberframework
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
- https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
- https://www.linkedin.com/posts/andreyprozorov_nist-sp-1353-activity-7496108071648370689-e0hZ
- https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
- https://csrc.nist.gov/News/2026/using-ai-for-csf-2-analysis-reporting-draft-qsg
- https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.ipd.pdf
- https://www.nist.gov/cyberframework/informative-references