HomeFrameworksDefense, Supply Chain & NIST CatalogueNIST SP 800-37

Framework  Defense, Supply Chain & NIST Catalogue

NIST SP 800-37

NIST Special Publication 800-37 Revision 2, "Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy", published December 2018, defines the Risk Management Framework (RMF) that US federal agencies use to authorize information systems.

It has seven steps: Prepare (organization and system level groundwork), Categorize (impact level under FIPS 199), Select (controls from NIST SP 800-53 baselines, tailored), Implement, Assess (independent assessment under NIST SP 800-53A), Authorize (a senior official accepts the risk and signs an authorization to operate), and Monitor (continuous monitoring and reauthorization).

Revision 2 added the Prepare step, integrated privacy alongside security, and aligned the RMF with the Cybersecurity Framework and system engineering processes. FedRAMP is an RMF implementation for cloud services and DoD applies it through DoDI 8510.01.

In writing, the RMF produces the security categorization, system security and privacy plans, control assessment plans and reports, plans of action and milestones, the authorization package and decision letter, and continuous monitoring strategy and reports.

AI-compiled
Share
Sponsored
NIST
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NIST SP 800-37
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Mandatory for US federal agencies and the systems they own or that are operated on their behalf, under FISMA and OMB Circular A-130. Cloud providers meet it through FedRAMP; contractors running federal systems meet it under agency direction. Private organizations use it voluntarily as a governance model.

What the assessor asks to see

Security categorization (FIPS 199) and privacy risk determination; system security plan and privacy plan; control tailoring rationale; security assessment plan; assessment report with findings; plan of action and milestones; authorization package and ATO letter; continuous monitoring strategy, scan results, and periodic reports; change control records; incident response and contingency plans referenced by the SSP.

Assessors

Who assesses NIST SP 800-37

Independent control assessors: agency or contracted assessment teams for FISMA systems, FedRAMP-recognized 3PAOs for cloud services, and DoD assessment teams (security control assessors) for defense systems. The authorization decision itself is made by a government authorizing official.

Accredited by For FedRAMP, 3PAOs are accredited by A2LA (and other bodies recognized by the FedRAMP PMO) to ISO/IEC 17020 with FedRAMP requirements. Agency assessors are designated by the agency.

Public register of assessors: https://marketplace.fedramp.gov/assessors

No firm has claimed a NIST SP 800-37 assessor listing yet. Claim yours →

Consultants

Who helps with NIST SP 800-37

A large federal security consulting market: firms prepare authorization packages, write system security plans, and run continuous monitoring. Engagements run several months to a year for a first authorization.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST SP 800-37 consultant listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for NIST SP 800-37

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NIST SP 800-37

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.