Framework Defense, Supply Chain & NIST Catalogue
NIST SP 800-37
NIST Special Publication 800-37 Revision 2, "Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy", published December 2018, defines the Risk Management Framework (RMF) that US federal agencies use to authorize information systems.
It has seven steps: Prepare (organization and system level groundwork), Categorize (impact level under FIPS 199), Select (controls from NIST SP 800-53 baselines, tailored), Implement, Assess (independent assessment under NIST SP 800-53A), Authorize (a senior official accepts the risk and signs an authorization to operate), and Monitor (continuous monitoring and reauthorization).
Revision 2 added the Prepare step, integrated privacy alongside security, and aligned the RMF with the Cybersecurity Framework and system engineering processes. FedRAMP is an RMF implementation for cloud services and DoD applies it through DoDI 8510.01.
In writing, the RMF produces the security categorization, system security and privacy plans, control assessment plans and reports, plans of action and milestones, the authorization package and decision letter, and continuous monitoring strategy and reports.
help
Who has to comply
Mandatory for US federal agencies and the systems they own or that are operated on their behalf, under FISMA and OMB Circular A-130. Cloud providers meet it through FedRAMP; contractors running federal systems meet it under agency direction. Private organizations use it voluntarily as a governance model.
What the assessor asks to see
Security categorization (FIPS 199) and privacy risk determination; system security plan and privacy plan; control tailoring rationale; security assessment plan; assessment report with findings; plan of action and milestones; authorization package and ATO letter; continuous monitoring strategy, scan results, and periodic reports; change control records; incident response and contingency plans referenced by the SSP.
Assessors
Who assesses NIST SP 800-37
Independent control assessors: agency or contracted assessment teams for FISMA systems, FedRAMP-recognized 3PAOs for cloud services, and DoD assessment teams (security control assessors) for defense systems. The authorization decision itself is made by a government authorizing official.
Accredited by For FedRAMP, 3PAOs are accredited by A2LA (and other bodies recognized by the FedRAMP PMO) to ISO/IEC 17020 with FedRAMP requirements. Agency assessors are designated by the agency.
Public register of assessors: https://marketplace.fedramp.gov/assessors
No firm has claimed a NIST SP 800-37 assessor listing yet. Claim yours →
Consultants
Who helps with NIST SP 800-37
A large federal security consulting market: firms prepare authorization packages, write system security plans, and run continuous monitoring. Engagements run several months to a year for a first authorization.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a NIST SP 800-37 consultant listing yet. Claim yours →
Software
Tools for NIST SP 800-37
Tools that name this framework in their own material.
Need a hand implementing it?
Find a Consultant for NIST SP 800-37
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with NIST SP 800-37
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.