Skip to content
Log inRegister

NIST Now Publishes the Prompts: What SP 1353 Does and Does Not Authorise

Dr. Abeer Alshammari · Published 8/22/2026 · Updated 8/24/2026

IntermediateProfessionalsCISOsExecutives

On 19 August 2026, NIST released the initial public draft of Special Publication 1353, a quick-start guide showing how generative AI can be used to analyse, plan and report against the Cybersecurity Framework 2.0. It is a short document with a long implication: the institution that defines the framework has now published the prompts for working inside it.

What the guide actually contains

SP 1353 belongs to the portfolio of CSF 2.0 quick-start guides NIST has been releasing since February 2024, each aimed at making the framework easier for a particular audience to implement. This one is built around three notional use cases.

The first is an AI-assisted review of an organisation's cybersecurity policy, strategy and risk governance against CSF 2.0 outcomes. The second produces a draft Organisation Current State Profile by mapping existing artefacts and personnel interview notes to CSF outcomes, documenting assumptions along the way and recording observed gaps in the interviews and the evidence. The third drafts a target state profile from internal and industry references, describing the outcomes an organisation needs in order to meet its mission objectives, stakeholder expectations and requirements.

Each use case ships with structured prompts and a set of simulated organisational documents for a fictitious company, so a practitioner can run the whole workflow before pointing it at anything real. The comment period is open through 15 October 2026.

The sentence that does the most work

NIST attaches a qualification that GRC leaders should read twice: the use case examples illustrate a possible approach and are not prescriptive assessment or assurance methodologies. The guide also marks specific precautions inline with a warning notation, and NIST is explicit that it wants comment on the prompts themselves, not on the fictional company files supplied for illustration.

That qualification is the governance question in one line. A current state profile generated from interview notes and policy documents is a hypothesis about your control environment. It is not evidence that the controls exist, and it is certainly not an assessment that they operate effectively. Draft, evidence and assurance are three different things, and the difficulty is that the output looks the same in all three cases. A well-formatted profile carries identical visual authority whether a model inferred it or an assessor tested it.

Why this lands differently from earlier AI guidance

Almost all AI governance material published so far treats AI as the object of control: govern the model, govern the agent, govern the training data. SP 1353 places AI inside the control function itself. The model is not the thing being assessed; it is helping to produce the assessment.

That inverts the assurance chain, and very few second-line functions have a documented position on it. Most AI acceptable-use policies were written with marketing copy and developer productivity in mind. They rarely say anything about whether a model may draft the artefact a board committee will later rely on, or what an internal auditor should do when the workpaper under review was itself machine-drafted.

Three things to settle before you use these prompts

First, label provenance. Any artefact a model drafts should carry that fact on its face, and the label should survive into whatever document the artefact is later pasted into. The failure mode here is not a bad draft; it is a good draft that quietly becomes a cited source six months later.

Second, define what the human reviewer is attesting to. "Reviewed" is not a control. Reviewed against what -- the source artefacts, the CSF outcome text, or the reviewer's own knowledge of the environment? Write it down, because that is the sentence an assessor will ask you to defend.

Third, control the input, not just the prompt. These use cases involve feeding policies, strategy documents, architecture detail and interview notes into a general-purpose model. That is a data classification and tenancy decision before it is a productivity decision, and it should pass through the same review any other third-party processing of internal security documentation would receive.

SP 1353 is a genuinely useful document, and the honest reading is that it accelerates the least valuable part of framework work -- the writing -- while leaving the most valuable part, the judgement, exactly where it was. That is the right division of labour. It only holds if the organisation is disciplined enough to keep the two visibly apart on the page.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights