Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

NIST 800-37 vs. NIST 800-53: What’s the Difference? (RMF vs. the Control Catalog)

August 11, 2026
hero-nist-800-37-vs-800-53-1.png

NIST 800-37 vs. NIST 800-53 comes down to a simple split. 800-53 is the catalog of security controls. 800-37 is the process, the Risk Management Framework (RMF), that picks and applies them.

The two publications are companion documents, not competitors. [NIST SP 800-53 Rev. It covers everything from access control to incident response. That’s the control catalog, the “what.”

NIST SP 800-37 Rev. 2 is the process side, the “how and when.” It’s the Risk Management Framework, or RMF. RMF tells an organization how to pick controls and put them in place. It also verifies those controls work and keeps the system authorized over time.

This guide breaks down what each publication does. It also walks through RMF’s seven steps. You’ll see exactly where 800-53 controls plug in. If you support a federal system or a client’s Authorization to Operate (ATO) push, this distinction matters for scoping the work.

NIST 800-37 vs. NIST 800-53 at a Glance

Here’s the side-by-side breakdown.

NIST SP 800-37 (RMF)NIST SP 800-53 (Control Catalog)
What it producesA risk-based Authorization to Operate (ATO) decisionThe specific control text an organization implements
Who uses itFederal agencies and system owners running RMFAgencies, FedRAMP cloud vendors, and contractors selecting controls
How they connectPulls control text from 800-53 during its Select and Implement stepsSupplies the controls RMF selects, implements, and later assesses

The short version: 800-37 is inert without a control catalog to draw from, and 800-53 is inert without a process like RMF to apply it. Federal systems run both, together, from start to finish.

The Seven RMF Steps (and Where 800-53 Fits In)

RMF isn’t a single decision. It’s a lifecycle with seven distinct steps, and 800-53 controls only enter the picture partway through.

  1. Prepare. The organization sets up context first. This means roles, priorities, and a risk management strategy, before any system-level work starts. 2. Categorize. The system, and the information it handles, gets categorized by potential impact. 3. Select. This is where 800-53 enters the process. The team picks a control baseline, Low, Moderate, or High, from NIST SP 800-53B, then tailors it to the system’s actual risk. See the NIST 800-53 control families explainer for what’s inside each of the 20 families a baseline can draw from. 4. Implement. The selected controls get put in place. The team documents exactly how each one was implemented. 5. Assess. An assessor checks whether the controls actually work as intended. This isn’t a self-attestation step; it’s a real evaluation. 6. Authorize. A senior official reviews the assessment and makes the ATO call. This is the moment a system is formally approved to operate. 7. Monitor. Authorization isn’t a one-time event. The system’s controls and risk posture get watched on an ongoing basis.

Steps 3 and 4, Select and Implement, are where the two publications actually meet. RMF supplies the process; 800-53 supplies the control text that fills it in. For the full rundown of that catalog, see the complete NIST 800-53 guide.

Why the Confusion Happens

The mix-up makes sense. Both publications live inside the same federal process, and they never operate as alternatives to each other.

A federal system needs an Authorization to Operate (ATO) before it goes into production. That ATO decision comes out of the RMF process in SP 800-37. But RMF’s Select and Implement steps can’t function without a control catalog, and that catalog is SP 800-53. So in practice, nobody “chooses” between them. A system owner runs the full seven-step RMF process, and pulls the actual control language from 800-53 partway through. Ask “which one applies to my system,” and the honest answer is usually both, at different points in the same process.

This is different from genuinely competing standards, where an organization has to pick one path. NIST 800-37 and NIST 800-53 aren’t that. One is the process; the other is the material the process runs on.

What This Means for Your Business

Most businesses reading this aren’t a federal agency running RMF end to end. You’re more likely supporting one from the outside: as a vendor, a subcontractor, or a company chasing a federal or defense contract.

Where you land in that picture depends on your relationship to the government, not on which NIST number you happen to read first.

  • Federal agencies and their systems run the full SP 800-37 RMF process directly, using SP 800-53 controls at the baseline the system’s impact level requires. Cloud vendors selling to the government implement 800-53 controls to earn a FedRAMP Authorization to Operate, which then lets them serve any federal agency without a separate agency-by-agency ATO. Defense contractors and subcontractors usually aren’t scoped to the full 800-53 catalog at all. See how NIST 800-53 relates to CMMC for how that scoping actually works.

If you’re not sure which chain applies to your contracts, contact us and we’ll help you scope it before you build against the wrong document.

Where this does become direct RMF-and-800-53 work is a FedRAMP-adjacent engagement, a system genuinely running its own ATO process, or a client asking you to help assemble the System Security Plan (SSP) and Plan of Action and Milestones (POA&M) that RMF’s Assess and Monitor steps expect. That’s implementation work: unique logins and least privilege for Access Control, centralized logging for Audit and Accountability, hardened baselines for Configuration Management, a tested incident response plan, network segmentation and encryption for System and Communications Protection, and ongoing patching and vulnerability scanning for System and Information Integrity.

See Where You Stand

Not sure how your current setup lines up against the control families RMF’s Select step would draw from? Take the free, no-signup NIST 800-53 Risk-Check. It’s a 2-minute set of plain-English questions that shows you where you stand and which gaps to fix first.

Take the free 2-minute NIST 800-53 Risk-Check

Frequently Asked Questions

No. NIST 800-37 is the Risk Management Framework, a seven-step process for managing security risk. They’re companion documents that work together, not two versions of the same thing.

It depends on your role. A federal agency running its own system typically works with both, since RMF pulls its control text from 800-53.<details> <summary>What is the Risk Management Framework (RMF)?</summary> <p>RMF is the seven-step process defined in NIST SP 800-37 Revision 2: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. It walks a federal system from initial setup through a formal Authorization to Operate, then keeps that authorization current with ongoing monitoring.

NIST 800-53 itself has no fine authority, since it’s a technical standard, not a law. But the consequences show up downstream: a federal system that can’t meet its baseline doesn’t get an Authorization to Operate, and a cloud vendor without FedRAMP authorization can’t sell to federal agencies at all.

CMMC doesn’t plug into the SP 800-37 RMF process directly.## Get Your Federal Compliance Scoping Right the First TimeMixing up 800-37 and 800-53, or assuming they’re interchangeable, wastes time on the wrong document. LeadingIT helps Chicagoland businesses figure out which chain actually applies, then builds the technical controls behind it.See LeadingIT’s NIST 800-53 and federal compliance IT services, or book a call to talk through your specific scope.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.