Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST Risk Assessment Template showing threat source, event, vulnerability, and controls.

NIST Risk Assessment Template: A Clear Guide to 4 Steps

A NIST risk assessment template is only useful if its columns force the judgements
NIST SP 800-30 actually asks for. Most of the spreadsheets circulating under that name are generic
risk registers with the word NIST in the filename — they capture a threat, a score and an owner,
and skip the reasoning that makes an assessment defensible.

NIST risk assessment template: the SP 800-30 columns and the four-step process
The columns a NIST risk assessment template needs, and the four steps of SP 800-30 Rev 1.

What a NIST risk assessment template has to contain

SP 800-30 assesses risk as a function of the likelihood of a threat event and the impact if it
occurs — but the value is in the chain that gets you there. A template that captures only the
endpoints cannot be reviewed by anybody who was not in the room.

Column What it records
Threat source Who or what initiates it — adversarial, accidental, structural, environmental
Threat event What that source actually does
Vulnerability The weakness the event exploits
Predisposing condition The circumstance that makes it more likely — the column everyone drops
Existing controls What is already in place, so the score is of residual risk
Likelihood Of initiation and of adverse impact, on a defined scale
Impact Consequence if it occurs, in terms your business recognises
Risk The combination, and the reasoning behind the rating
Response and owner Accept, mitigate, transfer or avoid — with a named individual and a date

The predisposing condition column is the one that separates a real NIST risk assessment template
from a generic register. It is what lets you explain why the same threat event scores differently in
two parts of the business.

Score residual risk, not theoretical risk

If the existing controls column is missing, everything gets scored as though nothing were in place,
and the register fills with reds that nobody believes. Rate the risk as it stands today, then record
separately what the target rating is after the planned response. Two numbers, both meaningful.

The four steps SP 800-30 sets out

NIST SP
800-30 Revision 1
, Guide for Conducting Risk Assessments, was published in September 2012
and remains current — there is no withdrawal or superseding notice on NIST’s own catalogue
entry. It amplifies SP 800-39 and sets out a four-step process:

  1. Prepare. Define purpose, scope, assumptions and constraints, and the sources of
    information you will use. Skipping this is why assessments produce incomparable results year on
    year.
  2. Conduct. Identify threat sources and events, vulnerabilities and predisposing
    conditions, then determine likelihood, impact and risk.
  3. Communicate. Share the results with the people who make decisions, in a form
    they can act on.
  4. Maintain. Keep it current. An assessment that is a point-in-time artefact stops
    being true almost immediately.

Three tiers, and why your template needs to know which one it is

NIST carries out risk assessments at all three tiers of the risk management hierarchy —
organisation, mission and business process, and information system. A single flat spreadsheet mixing
all three produces a register where “supply chain concentration” sits next to
“unpatched web server” and neither can be prioritised sensibly.

Either keep a tier column and filter on it, or run separate assessments per tier. Which you choose
matters less than making the choice deliberately.

The NIST 800-30 risk assessment template, already built.

The NIST Cyber Risk Management Toolkit ships an editable NIST 800-30 Risk Assessment Template and a CSF 2.0 Maturity Assessment Template in Excel, a complete guide to running 800-30 assessments, a risk assessment report, risk assessment and treatment procedure, risk treatment plan and a cyber security risk management framework — alongside 45+ supporting security policies.

Explore the NIST Cyber Risk Management Toolkit →

Risk assessment, risk register and CSF maturity assessment

Three artefacts get confused, and searching for one often means wanting another.

A NIST risk assessment template is the analytical workbook: threat sources and
events through to a rated risk with reasoning. It is the SP 800-30 output.

A risk register is the ongoing management record — the live list of rated
risks with owners, responses and review dates. The assessment feeds it; it is not the same document,
and keeping them separate stops the analysis being overwritten every time somebody updates a status.

A CSF maturity assessment answers a different question entirely: not
“what could go wrong?” but “how good are our practices?” It scores the
organisation against the Cybersecurity Framework’s outcomes. Note that
CSF 2.0, published in
February 2024, restructured the framework around six functions — Govern,
Identify, Protect, Detect, Respond and Recover — with 22 categories and 106 subcategories. Any
maturity template still built on the five functions of CSF 1.1 is assessing a withdrawn structure.

Five mistakes that make a NIST risk assessment template useless

  • Scoring without a defined scale. If “high likelihood” is not written
    down somewhere, two assessors will disagree and neither is wrong.
  • Threat events written as vulnerabilities. “No MFA” is a
    vulnerability. “An adversary authenticates using credentials obtained by phishing” is the
    threat event. Templates that conflate them produce registers of missing controls rather than
    risks.
  • Impact expressed in security language. “Loss of confidentiality”
    means little to a board. Downtime, regulatory exposure, contractual penalty and customer loss
    do.
  • No review date. Step four is maintain, and a register without review dates is
    never maintained.
  • One assessment for the whole organisation, forever. Scope it, date it, and repeat
    it — that is what makes year-on-year comparison possible.

The underlying discipline is the same one that applies to any risk work: the register has to be
legible to somebody who was not present when it was written. Our guide to
ISO 31000 covers the vocabulary
side if you need project and cyber risk to be comparable with enterprise risk.

Building the NIST risk assessment template your organisation will actually use

The template is the easy part. Getting it populated with judgements people stand behind is where
assessments succeed or quietly fail, and a few decisions made up front do most of the work.

  1. Write the scales before the first row. Define what very low through very high
    mean for likelihood and for impact, in your own terms — pounds, hours of downtime, records
    exposed, regulatory consequence. Put the definitions on a tab of the workbook, not in a separate
    document nobody opens.
  2. Agree the scope and write it down. Which systems, which business units, which
    tier. Step one of SP 800-30 exists because undocumented scope is what makes this year’s assessment
    incomparable with last year’s.
  3. Seed it from real sources. Incident history, vulnerability scans, audit findings,
    supplier assessments and the threat intelligence you already subscribe to. A workshop starting from a
    blank sheet produces the risks people can imagine, not the ones that have been happening.
  4. Run scoring as a group, not as a survey. The disagreement is the value. Two
    people scoring the same threat event differently is a conversation about assumptions, and it is where
    the predisposing conditions come from.
  5. Record the reasoning, briefly. One line per risk explaining why the rating is
    what it is. This is what makes the assessment reviewable and what makes next year’s update an edit
    rather than a rebuild.
  6. Set review dates per risk, not per document. A critical risk on a supplier
    contract renewing in March does not want an annual review in November.

One thing worth resisting: the urge to make the NIST risk assessment template comprehensive on the
first pass. An assessment covering thirty well-reasoned risks that people revisit is worth
considerably more than two hundred rows nobody reads. Scope narrowly, do it properly, and widen the
scope next cycle.

Frequently asked questions

Is there an official NIST risk assessment template?
No. NIST publishes the methodology in SP 800-30 Rev 1, including illustrative tables in its
appendices, but it does not issue a fill-in workbook. Any template is somebody’s implementation of the
method, which is why the columns matter.

Is SP 800-30 still current?
Yes. Revision 1 was published in September 2012 and NIST’s catalogue entry carries no withdrawal or
superseding notice.

What format should the template be in?
Excel, in practice. Filtering, sorting and scoring across a few hundred rows is what the assessment
needs, and a Word table cannot do it.

How does this relate to the Cybersecurity Framework?
SP 800-30 tells you how to assess risk; CSF 2.0 describes the outcomes a programme should achieve.
Most organisations run an 800-30 assessment and use CSF to structure the response.

How often should the assessment be repeated?
Annually as a baseline, and on significant change — a new system, a major incident, a
substantial supplier change or a shift in the threat picture.

Where this leaves you

A NIST risk assessment template is a method made operable, not a spreadsheet with a logo. Get the
columns right so the reasoning is captured, define the scales before the first row, score residual
rather than theoretical risk, and separate the assessment from the register it feeds. Do that and the
assessment survives review, comparison year on year, and the question an auditor or a customer
eventually asks: how did you arrive at that rating?

References

More on NIST risk management

All of these are covered by the NIST Cyber Risk Management Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.