HomeFrameworksDefense, Supply Chain & NIST CatalogueNIST SP 800-34

Framework  Defense, Supply Chain & NIST Catalogue

NIST SP 800-34

NIST Special Publication 800-34 Revision 1, "Contingency Planning Guide for Federal Information Systems", published May 2010 with updates through November 2010, tells organizations how to plan for recovering information systems after a disruption.

It sets out a seven-step process: develop the contingency planning policy, conduct a business impact analysis, identify preventive controls, create recovery strategies, develop the plan, test and train, and maintain the plan.

It also explains how an information system contingency plan relates to business continuity, disaster recovery, crisis communications, and incident response plans, and provides templates by system impact level.

The NIST CSRC listing marks the publication as withdrawn from active maintenance, but it remains the reference behind the CP control family in NIST SP 800-53 and is still cited in FedRAMP and CMMC work (verify current status on the NIST page).

In writing it yields the contingency planning policy, BIA, recovery strategies, the plan itself with roles and call trees, test records, and a maintenance log.

AI-compiled
Share
Sponsored
NIST
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NIST SP 800-34
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Written for US federal agencies under FISMA; voluntary for others, but widely used by contractors and cloud providers to satisfy the CP controls in NIST SP 800-53 baselines.

What the assessor asks to see

Contingency planning policy; business impact analysis with recovery time and point objectives; preventive controls list; recovery strategies and alternate site or backup arrangements; the contingency plan with roles, notification procedures, and recovery steps; training records; test and exercise reports with lessons learned; plan maintenance and distribution records.

Assessors

Who assesses NIST SP 800-34

None for the document itself; contingency plans built on it are reviewed by the assessor of the parent program (3PAOs, agency assessors, C3PAOs).

No firm has claimed a NIST SP 800-34 assessor listing yet. Claim yours →

Consultants

Who helps with NIST SP 800-34

Business continuity and disaster recovery consultancies use it as a template. Typical engagement is a BIA and plan build of one to three months, followed by annual test facilitation.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST SP 800-34 consultant listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for NIST SP 800-34

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NIST SP 800-34

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.