NIST SP 800-37
What is NIST SP 800-37?
Risk Management Framework for Information Systems and Organizations: A System Security Engineering Approach for the Federal Government. It comprises 8 controls organised across 8 domains, published by NIST, and applies in the United States.
How NIST SP 800-37 maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains NIST SP 800-37 groups its controls into
Where NIST SP 800-37 overlaps with the standards you already hold
Where to get trained on NIST SP 800-37
One course in the catalogue covers NIST SP 800-37 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What NIST SP 800-37 means in your sector
What NIST SP 800-37 means for your job
Questions people ask about NIST SP 800-37
What is NIST SP 800-37?
How many controls does NIST SP 800-37 have?
Where does NIST SP 800-37 apply?
What frameworks does NIST SP 800-37 map to?
How do I get started with NIST SP 800-37 compliance?
Query NIST SP 800-37 programmatically
NIST SP 800-37, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST SP 800-37 API reference and MCP config →How ready are you for NIST SP 800-37?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.