Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The seven steps of the NIST RMF

NIST RMF: A Clear Guide to the 7 Steps of SP 800-37

The NIST RMF is the seven-step process a federal system goes through to be authorized to operate — and it is a different thing from the Cybersecurity Framework, which is where most of the confusion around “the NIST risk framework” starts. The RMF is a lifecycle process defined in SP 800-37 Revision 2; the CSF is a set of outcomes. You can run both, and large organizations do.

This guide walks the seven steps as NIST states their purpose, shows which publication does the work at each one, and sets out plainly when the RMF applies to you and when the CSF is the better instrument.

NIST RMF: the seven steps of SP 800-37 Revision 2 and the publication behind each
Seven steps, each with a companion publication that does the detailed work.

The seven steps of the NIST RMF

Step Purpose Companion
Prepare Carry out essential activities at organization, mission and system level so the rest can be executed consistently SP 800-37, SP 800-39
Categorize Determine the adverse impact of a loss of confidentiality, integrity or availability FIPS 199, FIPS 200
Select Select, tailor and document the controls needed, commensurate with risk SP 800-53, SP 800-53B
Implement Implement the controls and document the specifics in a baseline configuration SP 800-53
Assess Determine whether controls are implemented correctly, operating as intended and producing the desired outcome SP 800-53A
Authorize Provide accountability by requiring a senior official to determine whether the risk is acceptable SP 800-37
Monitor Maintain ongoing situational awareness of the security and privacy posture to support risk decisions SP 800-137

Revision 2, published in December 2018, is where Prepare arrived. It exists because organizations kept starting at Categorize with no risk strategy, no defined roles and no common controls identified — and then rebuilt the same foundations on every system. NIST’s framing is that Prepare leverages activities already running in security, privacy and supply chain programmes, and it splits into organization-level and system-level preparation.

Where the effort actually goes

Two steps of the NIST RMF consume most of a first authorization. Select is where tailoring happens — starting from a control baseline and justifying every addition, removal and parameter value. Teams that treat the baseline as a checklist end up implementing controls their system does not need and cannot evidence.

Authorize is where the process becomes a decision rather than an exercise. The purpose NIST states is accountability: a senior official determines whether the risk, including supply chain risk, is acceptable. That official is signing their name to a residual risk position, which is why a package full of unresolved findings does not get signed — and why the Assess step’s honesty determines how the Authorize step goes.

NIST RMF vs the Cybersecurity Framework

They answer different questions and they are not alternatives.

  • The RMF is a process applied to a system, ending in an authorization decision, with mandatory force for US federal information systems under FISMA. Its outputs are a categorization, a tailored control set, an assessment and an authorization.
  • The CSF is a voluntary set of cybersecurity outcomes usable by any organization, tailored through profiles. Its output is a prioritized picture of current and target posture. Our guide to the NIST CSF organizational profile covers that mechanism.

In practice the two interlock. CSF outcomes map to SP 800-53 controls through informative references, so a target profile can drive control selection, while the RMF supplies the assessment and authorization discipline the CSF deliberately leaves open. If your obligation is a federal ATO, the RMF is the process; if your obligation is to show a board where you stand, the CSF is the language.

Who has to use the NIST RMF

Federal agencies and their systems, by law. Contractors inherit it indirectly: a system operated on an agency’s behalf goes through the same process, and FedRAMP is the RMF applied to cloud services with a shared evidence package on top — the reason its vocabulary of categorization, control baselines and authorization is identical. Our guide to the FedRAMP ATO covers how that agency decision now works.

For a private-sector organization with no federal customers, the RMF is optional and often heavier than needed. What travels well is its sequence: decide impact before selecting controls, tailor deliberately, assess before you claim, make somebody senior accept the residual risk, and monitor continuously rather than annually.

Five NIST RMF mistakes that cost an authorization

  1. Skipping Prepare. No risk strategy, no common controls identified, no roles — and every system team rebuilds the same foundations.
  2. Categorizing low to reduce work. The impact level drives the baseline; a categorization set for convenience produces a control set that will not survive assessment.
  3. Tailoring without justification. Every deviation from the baseline needs a recorded rationale. Silent removals are what assessors find first.
  4. Treating Assess as a formality. The purpose is to determine whether controls work, not to confirm they exist. Findings raised honestly at Assess are cheaper than findings raised at Authorize.
  5. Monitoring on an annual cycle. Continuous monitoring is a step of the framework, not a report. If the authorizing official learns about drift a year later, the authorization has been fictional for eleven months.

Frequently asked questions

What does RMF stand for?
Risk Management Framework. NIST defines it in SP 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy.

How many steps does the NIST RMF have?
Seven: Prepare, Categorize, Select, Implement, Assess, Authorize and Monitor. Prepare was added in Revision 2 in December 2018.

Is the RMF the same as the Cybersecurity Framework?
No. The RMF is a lifecycle process ending in an authorization decision; the CSF is a voluntary set of outcomes used to describe and prioritize posture.

Do private companies have to follow the RMF?
No, unless they operate a system for a federal agency or are contractually required to. The sequence is still a sound model for any system authorization process.

Which publication supports each step?
FIPS 199 and 200 for Categorize, SP 800-53 and 800-53B for Select and Implement, SP 800-53A for Assess, SP 800-37 for Authorize, and SP 800-137 for continuous monitoring under Monitor.

Where this leaves you

Run the NIST RMF in order and it is a coherent lifecycle; run it as seven deliverables and it becomes documentation nobody trusts. Do the Prepare work once at organization level so system teams inherit it, categorize honestly because everything downstream depends on it, justify every tailoring decision at the time you make it, and treat the authorization as a real risk acceptance by a named official. If you are not federal, borrow the sequence and pair it with the CSF for the language your board actually wants.

References

More on NIST cyber risk

Categorization, control selection and assessment templates are in the NIST Cyber Risk Management Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.