The Authorize step uses the prefix R, not A. A is taken by Assess. It is the most common identifier error in third-party RMF material, and a fair test of whether the checklist you are using was written from the publication or from memory.
This assessment walks all 47 tasks across the seven RMF steps, with Prepare split into its organisation-level and system-level halves the way NIST splits it — so the seven organisation-level answers carry over to every system you assess after the first. It is free, it saves as you go, and you can stop and come back to it.
What this is
SP 800-37 Revision 2 was published on 20 December 2018 and is still current. There is no Revision 3 in draft or announced. One thing worth knowing: the CSRC pages for the Rev 2 drafts carry a withdrawn banner, which NIST does routinely once a final publishes. It is easy to misread as Rev 2 itself being withdrawn. It is not.
The supporting publications have moved, though. SP 800-53 and SP 800-53A are at Release 5.2.0 of August 2025, and SP 800-18 went to Revision 2 on 30 June 2026 — retitled, broadened to cover privacy and supply chain risk planning, and with Revision 1 withdrawn the same day. Any RMF checklist written before July 2026 cites a withdrawn publication for system security plans. There is more on the framework in our RMF guide.
What it covers
53 questions, about 40 minutes.
| Section | Questions |
|---|---|
| Prepare – organisation level | 7 |
| Prepare – system level | 11 |
| Categorize | 4 |
| Select | 7 |
| Implement | 3 |
| Assess | 7 |
| Authorize | 6 |
| Monitor | 8 |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
The distinction this assessment draws between implemented and evidenced maps onto the distinction NIST draws in the Implement step: a control operating in the live environment, demonstrated through configuration and observed behaviour, rather than asserted.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list, and the documents from the NIST Risk Management Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 40 minutes. Prepare is 18 of the 47 tasks and takes roughly half the time, but the seven organisation-level answers are reusable across every system.
What to do with your score
Below 40% — settle the authorisation boundary first. Task P-11 is the one everything after it depends on, and a fuzzy boundary makes every later control assessment provisional.
40–70% — the usual shape. Systems get categorised, controls get selected and implemented; the tailoring rationale, the organisation-defined parameter values and the continuous monitoring cadence are where the evidence thins out.
Above 70% — check the Monitor step honestly. Ongoing authorisation claimed without the authorising official actively receiving and acting on monitoring results is a lapsed authorisation with a better name.
Frequently asked questions
Is this assessment really free?
Yes. All 47 tasks, the breakdown by step and your overall score cost nothing. The $39 report is optional.
Is the RMF only for federal systems?
It was written for federal systems, but the structure works for anyone who needs a repeatable authorisation decision — contractors, cloud providers selling into government, and organisations that want an accountable official formally accepting residual risk.
How does this relate to FedRAMP?
FedRAMP is a specific application of these ideas for cloud services sold to US federal agencies, and it has moved a long way from the RMF vocabulary under the 2026 rules. If you are pursuing FedRAMP, run the FedRAMP assessment instead.
Is Revision 3 coming?
Nothing has been announced. As at September 2026 there is no pre-draft, no concept paper and no call for comments on the NIST site.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.