HomeFrameworksDefense, Supply Chain & NIST CatalogueNIST SP 800-30

Framework  Defense, Supply Chain & NIST Catalogue

NIST SP 800-30

NIST Special Publication 800-30 Revision 1, "Guide for Conducting Risk Assessments", published September 2012, is the US federal method for assessing information security risk.

It breaks an assessment into preparing (purpose, scope, assumptions, sources), conducting (identify threat sources and events, vulnerabilities and predisposing conditions, likelihood, impact, and resulting risk), communicating results, and maintaining the assessment over time, and it supplies the reference tables for likelihood and impact scales that many organizations still copy.

It is one of the Joint Task Force documents that support the Risk Management Framework, so it is used wherever NIST SP 800-37 and 800-53 are used, including FedRAMP and FISMA, and it is a common template for the risk assessment required by HIPAA, NIST SP 800-171, and ISO/IEC 27001 programs. There is no certification against it.

In writing it yields a risk assessment plan, the completed assessment report with its threat, vulnerability, likelihood, and impact tables, and a maintenance schedule.

AI-compiled
Share
Sponsored
NIST
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NIST SP 800-30
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Mandatory in substance for US federal agencies under FISMA; voluntary for others. Contractors and cloud providers use it because FedRAMP, CMMC, and agency assessors expect risk assessments in this shape.

What the assessor asks to see

Risk assessment plan and scope; threat source and event catalog; vulnerability and predisposing condition inventory; likelihood and impact determinations with rationale; risk register or heat map; communication record to decision makers; maintenance and update log.

Assessors

Who assesses NIST SP 800-30

None for the document itself. Risk assessments produced with it are reviewed by whichever assessor governs the parent program (3PAOs, C3PAOs, agency assessors, ISO certification bodies).

No firm has claimed a NIST SP 800-30 assessor listing yet. Claim yours →

Consultants

Who helps with NIST SP 800-30

Every security consultancy offers risk assessments modeled on it; GRC platforms embed its scales. Engagements are typically two to eight weeks.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST SP 800-30 consultant listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for NIST SP 800-30

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NIST SP 800-30

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.