A NIST risk assessment template is only useful if its columns force the judgements
NIST SP 800-30 actually asks for. Most of the spreadsheets circulating under that name are generic
risk registers with the word NIST in the filename — they capture a threat, a score and an owner,
and skip the reasoning that makes an assessment defensible.

What a NIST risk assessment template has to contain
SP 800-30 assesses risk as a function of the likelihood of a threat event and the impact if it
occurs — but the value is in the chain that gets you there. A template that captures only the
endpoints cannot be reviewed by anybody who was not in the room.
| Column | What it records |
|---|---|
| Threat source | Who or what initiates it — adversarial, accidental, structural, environmental |
| Threat event | What that source actually does |
| Vulnerability | The weakness the event exploits |
| Predisposing condition | The circumstance that makes it more likely — the column everyone drops |
| Existing controls | What is already in place, so the score is of residual risk |
| Likelihood | Of initiation and of adverse impact, on a defined scale |
| Impact | Consequence if it occurs, in terms your business recognises |
| Risk | The combination, and the reasoning behind the rating |
| Response and owner | Accept, mitigate, transfer or avoid — with a named individual and a date |
The predisposing condition column is the one that separates a real NIST risk assessment template
from a generic register. It is what lets you explain why the same threat event scores differently in
two parts of the business.
Score residual risk, not theoretical risk
If the existing controls column is missing, everything gets scored as though nothing were in place,
and the register fills with reds that nobody believes. Rate the risk as it stands today, then record
separately what the target rating is after the planned response. Two numbers, both meaningful.
The four steps SP 800-30 sets out
NIST SP
800-30 Revision 1, Guide for Conducting Risk Assessments, was published in September 2012
and remains current — there is no withdrawal or superseding notice on NIST’s own catalogue
entry. It amplifies SP 800-39 and sets out a four-step process:
- Prepare. Define purpose, scope, assumptions and constraints, and the sources of
information you will use. Skipping this is why assessments produce incomparable results year on
year. - Conduct. Identify threat sources and events, vulnerabilities and predisposing
conditions, then determine likelihood, impact and risk. - Communicate. Share the results with the people who make decisions, in a form
they can act on. - Maintain. Keep it current. An assessment that is a point-in-time artefact stops
being true almost immediately.
Three tiers, and why your template needs to know which one it is
NIST carries out risk assessments at all three tiers of the risk management hierarchy —
organisation, mission and business process, and information system. A single flat spreadsheet mixing
all three produces a register where “supply chain concentration” sits next to
“unpatched web server” and neither can be prioritised sensibly.
Either keep a tier column and filter on it, or run separate assessments per tier. Which you choose
matters less than making the choice deliberately.
The NIST 800-30 risk assessment template, already built.
The NIST Cyber Risk Management Toolkit ships an editable NIST 800-30 Risk Assessment Template and a CSF 2.0 Maturity Assessment Template in Excel, a complete guide to running 800-30 assessments, a risk assessment report, risk assessment and treatment procedure, risk treatment plan and a cyber security risk management framework — alongside 45+ supporting security policies.
Risk assessment, risk register and CSF maturity assessment
Three artefacts get confused, and searching for one often means wanting another.
A NIST risk assessment template is the analytical workbook: threat sources and
events through to a rated risk with reasoning. It is the SP 800-30 output.
A risk register is the ongoing management record — the live list of rated
risks with owners, responses and review dates. The assessment feeds it; it is not the same document,
and keeping them separate stops the analysis being overwritten every time somebody updates a status.
A CSF maturity assessment answers a different question entirely: not
“what could go wrong?” but “how good are our practices?” It scores the
organisation against the Cybersecurity Framework’s outcomes. Note that
CSF 2.0, published in
February 2024, restructured the framework around six functions — Govern,
Identify, Protect, Detect, Respond and Recover — with 22 categories and 106 subcategories. Any
maturity template still built on the five functions of CSF 1.1 is assessing a withdrawn structure.
Five mistakes that make a NIST risk assessment template useless
- Scoring without a defined scale. If “high likelihood” is not written
down somewhere, two assessors will disagree and neither is wrong. - Threat events written as vulnerabilities. “No MFA” is a
vulnerability. “An adversary authenticates using credentials obtained by phishing” is the
threat event. Templates that conflate them produce registers of missing controls rather than
risks. - Impact expressed in security language. “Loss of confidentiality”
means little to a board. Downtime, regulatory exposure, contractual penalty and customer loss
do. - No review date. Step four is maintain, and a register without review dates is
never maintained. - One assessment for the whole organisation, forever. Scope it, date it, and repeat
it — that is what makes year-on-year comparison possible.
The underlying discipline is the same one that applies to any risk work: the register has to be
legible to somebody who was not present when it was written. Our guide to
ISO 31000 covers the vocabulary
side if you need project and cyber risk to be comparable with enterprise risk.
Building the NIST risk assessment template your organisation will actually use
The template is the easy part. Getting it populated with judgements people stand behind is where
assessments succeed or quietly fail, and a few decisions made up front do most of the work.
- Write the scales before the first row. Define what very low through very high
mean for likelihood and for impact, in your own terms — pounds, hours of downtime, records
exposed, regulatory consequence. Put the definitions on a tab of the workbook, not in a separate
document nobody opens. - Agree the scope and write it down. Which systems, which business units, which
tier. Step one of SP 800-30 exists because undocumented scope is what makes this year’s assessment
incomparable with last year’s. - Seed it from real sources. Incident history, vulnerability scans, audit findings,
supplier assessments and the threat intelligence you already subscribe to. A workshop starting from a
blank sheet produces the risks people can imagine, not the ones that have been happening. - Run scoring as a group, not as a survey. The disagreement is the value. Two
people scoring the same threat event differently is a conversation about assumptions, and it is where
the predisposing conditions come from. - Record the reasoning, briefly. One line per risk explaining why the rating is
what it is. This is what makes the assessment reviewable and what makes next year’s update an edit
rather than a rebuild. - Set review dates per risk, not per document. A critical risk on a supplier
contract renewing in March does not want an annual review in November.
One thing worth resisting: the urge to make the NIST risk assessment template comprehensive on the
first pass. An assessment covering thirty well-reasoned risks that people revisit is worth
considerably more than two hundred rows nobody reads. Scope narrowly, do it properly, and widen the
scope next cycle.
Frequently asked questions
Is there an official NIST risk assessment template?
No. NIST publishes the methodology in SP 800-30 Rev 1, including illustrative tables in its
appendices, but it does not issue a fill-in workbook. Any template is somebody’s implementation of the
method, which is why the columns matter.
Is SP 800-30 still current?
Yes. Revision 1 was published in September 2012 and NIST’s catalogue entry carries no withdrawal or
superseding notice.
What format should the template be in?
Excel, in practice. Filtering, sorting and scoring across a few hundred rows is what the assessment
needs, and a Word table cannot do it.
How does this relate to the Cybersecurity Framework?
SP 800-30 tells you how to assess risk; CSF 2.0 describes the outcomes a programme should achieve.
Most organisations run an 800-30 assessment and use CSF to structure the response.
How often should the assessment be repeated?
Annually as a baseline, and on significant change — a new system, a major incident, a
substantial supplier change or a shift in the threat picture.
Where this leaves you
A NIST risk assessment template is a method made operable, not a spreadsheet with a logo. Get the
columns right so the reasoning is captured, define the scales before the first row, score residual
rather than theoretical risk, and separate the assessment from the register it feeds. Do that and the
assessment survives review, comparison year on year, and the question an auditor or a customer
eventually asks: how did you arrive at that rating?
References
- NIST SP 800-30 Rev. 1 — Guide for Conducting Risk Assessments, September 2012.
- NIST Cybersecurity Framework — CSF 2.0, published February 2024.
More on NIST risk management
- The NIST risk assessment template — you are here
- The NIST SP 800-30 risk assessment
- The NIST Cybersecurity Framework
- ISO 31000 risk management
- ISO 27001 risk assessment
All of these are covered by the NIST Cyber Risk Management Toolkit, or start with the free ISO templates.