Skip to main content
Category: Risk Management Framework

NIST SP 800-37

Also known as: RMF, NIST Special Publication 800-37, SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations, Risk Management Framework
Simply put

NIST SP 800-37 is a publication from the National Institute of Standards and Technology (NIST) that describes the Risk Management Framework (RMF), a structured approach for managing security and privacy risk in information systems. It provides guidelines for applying the RMF across a system's life cycle rather than serving as a ready-made, off-the-shelf risk program. Organizations generally use it as a methodology to plan, assess, authorize, and monitor their systems.

Formal definition

NIST SP 800-37, currently in Revision 2 (2018), titled 'Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach,' is maintained by NIST and describes the RMF and guidelines for applying it to information systems and organizations. Revision 2 introduced comprehensive updates addressing both security and privacy, broadened the scope of system planning, aligned plan development with the RMF steps and tasks, and emphasized the use of machine-readable data. The RMF is a methodology for building a risk management program and is not itself a control catalog; practitioners typically pair it with related NIST guidance such as control baselines during implementation. Readers should verify the current revision and applicable agency tailoring against the official NIST source, as authorization under the RMF is generally time-bound and subject to continuous monitoring rather than permanent.

Why it matters

NIST SP 800-37 establishes the structured methodology that many federal agencies and their contractors use to manage security and privacy risk across a system's life cycle. Rather than functioning as a checklist or a control catalog, it defines how organizations plan, assess, authorize, and continuously monitor their information systems, giving disparate stakeholders a common process for making risk-based decisions. For defense and public sector practitioners, this matters because authorization decisions carry real accountability: an authorizing official accepts risk on behalf of the organization, and that decision must be grounded in a repeatable, documented process rather than ad hoc judgment.

A critical point that experts frequently emphasize is that authorization under the RMF is time-bound and subject to continuous monitoring, not a permanent status. Treating an Authority to Operate as a one-time achievement, or equating completion of the RMF process with being secure, misunderstands the framework's intent. The RMF is designed to sustain ongoing risk awareness across the system life cycle, so an organization that stops actively monitoring after authorization has effectively abandoned the methodology it claims to follow.

Revision 2, published in 2018, is significant because it broadened the framework's scope to integrate privacy risk alongside security risk, aligned system planning with the RMF steps and tasks, and emphasized the use of machine-readable data to support automation. Because control baselines, agency tailoring, and revisions change over time, practitioners should always confirm the current revision and any applicable agency-specific interpretations against the official NIST source before relying on it for compliance decisions.

Who it's relevant to

Authorizing Officials
Authorizing officials rely on the RMF process to make and document risk-based authorization decisions. NIST SP 800-37 provides the structured basis for those decisions, but officials should remember that authorization is time-bound and dependent on continuous monitoring rather than a permanent grant.
Information System Security Managers and Practitioners
Those responsible for implementing and sustaining a risk management program use NIST SP 800-37 as the methodology for planning, assessing, authorizing, and monitoring systems across their life cycle. Because it is not a control catalog, practitioners generally pair it with related NIST guidance such as control baselines during implementation.
Compliance Officers and Auditors
Compliance and audit personnel reference NIST SP 800-37 to evaluate whether an organization's risk management process aligns with the RMF steps and tasks. They should confirm the current revision and any applicable agency tailoring against the official NIST source, and distinguish assessment activities from the separate act of authorization.
Government Contractors
Contractors supporting federal or defense systems may be expected to operate within an RMF-based process. They should verify how the framework has been tailored by the responsible agency, and recognize that Revision 2 broadened the scope to address privacy alongside security.

Inside RMF

Risk Management Framework (RMF)
NIST SP 800-37 establishes the RMF, a structured, repeatable process for managing information security and privacy risk across the system life cycle. It is maintained by NIST and is applied to federal information systems, including DoD systems that have adopted RMF in place of the older DIACAP process.
RMF Steps
The publication organizes risk management into a set of sequential yet iterative steps. As of the applicable revision, these generally include Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. Practitioners should confirm the exact steps against the current revision, as the framework has evolved across versions.
System Categorization
The Categorize step draws on related standards (such as FIPS 199 and NIST SP 800-60) to determine the impact level of a system based on confidentiality, integrity, and availability. This categorization drives the selection of an appropriate control baseline.
Control Selection and Tailoring
The Select step points to control catalogs maintained separately (notably NIST SP 800-53) for choosing and tailoring baselines. SP 800-37 defines the process, while SP 800-53 supplies the actual controls; the two are distinct and should not be conflated.
Authorization and the ATO
The Authorize step results in an authorizing official making a risk-based decision, commonly documented as an Authority to Operate (ATO). This is a time-bound decision that accepts risk on behalf of the organization, not a permanent certification.
Continuous Monitoring
The Monitor step requires ongoing assessment of controls, security posture, and changes to the system and its environment. Authorization decisions depend on maintaining an accurate, current understanding of risk over time rather than a one-time review.
Roles and Responsibilities
The framework defines organizational roles that participate in the process, such as the authorizing official, system owner, and security assessor, to separate the functions of implementing, assessing, and authorizing systems.

Common questions

Answers to the questions practitioners most commonly ask about RMF.

Does an Authority to Operate (ATO) granted through the NIST SP 800-37 process last indefinitely?
No. An ATO is a time-bound authorization decision made by an authorizing official, not a permanent status. The Risk Management Framework (RMF) described in NIST SP 800-37 concludes its authorization step with a decision that is generally subject to defined conditions and an expiration, and it is sustained through the framework's continuous monitoring step (Step 7 in most implementations). Changes to the system, its environment, or its risk posture can trigger reauthorization. Readers should confirm specific authorization terms, durations, and reauthorization triggers against their organization's policy and the applicable revision of the publication.
If a system completes the NIST SP 800-37 RMF process, does that mean it is secure?
Not necessarily. Completing the RMF and achieving authorization demonstrates that a structured risk management process was followed, that controls were selected and assessed, and that an authorizing official formally accepted the residual risk. That is a compliance and risk-acceptance outcome, not a guarantee of security. The framework is designed to manage risk to an acceptable level as determined by the authorizing official, not to eliminate it. Security depends on effective implementation, ongoing monitoring, and response to evolving threats, which is why continuous monitoring is an integral part of the process rather than an optional add-on.
How does NIST SP 800-37 relate to NIST SP 800-53 during control selection?
NIST SP 800-37 provides the overall Risk Management Framework process, while NIST SP 800-53, maintained by NIST, provides the catalog of security and privacy controls from which baselines are selected and tailored. In the select step of the RMF, organizations generally choose a control baseline and tailor it to the system's categorization and operating conditions. The two publications are complementary: 800-37 governs the process and 800-53 supplies the controls. Consult the applicable revisions of both, since baselines and tailoring guidance can change across revisions.
What is the difference between assessing controls and authorizing a system under the RMF?
Assessment and authorization are distinct steps. Control assessment generally involves an assessor evaluating whether implemented controls are operating as intended and producing the desired outcome, with results typically documented in an assessment report. Authorization is the separate decision by an authorizing official to accept the residual risk and permit the system to operate, informed by the assessment results and other risk information. Treating a completed assessment as if it were an authorization is a common error; the two involve different roles and different outcomes.
Which roles are involved in carrying out the NIST SP 800-37 process?
The RMF assigns responsibilities across several defined roles, which commonly include the authorizing official who accepts risk and issues the authorization decision, the system owner, the information system security officer or manager responsible for security implementation, and the assessor who evaluates control effectiveness. Organizations may assign additional roles related to risk executive functions and privacy. Exact role definitions, titles, and responsibilities can vary by organization and by the applicable revision, so confirm assignments against your organization's policy and the current publication text.
How does continuous monitoring fit into the RMF once a system is authorized?
Continuous monitoring is a core, ongoing step of the RMF rather than a one-time activity that ends at authorization. In most implementations it involves tracking the status of implemented controls, assessing the security and privacy posture over time, and reporting relevant information to the authorizing official so that risk decisions remain current. This step supports ongoing authorization decisions and can inform whether reauthorization is warranted. The specific frequency, metrics, and reporting mechanisms are typically defined by organizational policy and should be verified against the applicable revision.

Common misconceptions

An ATO issued under the RMF is a permanent approval that remains valid indefinitely.
An ATO is a time-bound, risk-based decision that is subject to continuous monitoring and periodic reauthorization. Changes to the system, its environment, or the threat landscape can require reassessment, and the authorization can expire or be revoked.
Completing the RMF assessment step is the same as authorizing a system to operate.
Assessment and authorization are distinct activities. The Assess step evaluates whether controls are implemented and effective, while the Authorize step is a separate decision made by an authorizing official who accepts the residual risk. Assessment produces findings; authorization produces a decision.
Following NIST SP 800-37 and satisfying its control requirements means a system is secure.
Compliance with the RMF process is not equivalent to security. The framework manages and documents risk in a structured way, but a compliant system can still carry residual risk or be vulnerable. Practitioners should treat compliance as a baseline discipline, not a guarantee of protection.

Best practices

Treat authorization as an ongoing state rather than a one-time milestone by establishing a continuous monitoring program that keeps the authorizing official informed of changes to the system and its risk posture.
Keep the RMF process (SP 800-37) and the control catalog (SP 800-53) clearly separated in your documentation, using SP 800-37 for the workflow and SP 800-53 for control selection and tailoring.
Confirm the applicable revision of SP 800-37 and the exact sequence of RMF steps against the current NIST publication before building or updating your process, since the framework has evolved across versions.
Ground system categorization in the appropriate supporting standards (such as FIPS 199 and SP 800-60) so that the selected control baseline is proportionate to the system's impact level.
Clearly separate the roles of implementing, assessing, and authorizing systems to preserve the independence between assessment findings and the authorization decision.
For DoD or CUI-related systems, verify scope-specific obligations against current authoritative sources, since adopting the RMF process does not by itself satisfy contractual, DFARS, or CMMC-related requirements that a reader must confirm independently.