Categorize Step
The Categorize Step is the stage in the NIST Risk Management Framework (RMF) where an organization determines how serious the harm would be if an information system and the information it holds were compromised. Its purpose is to size up the potential adverse impact so that later risk management decisions are informed by how important the system is. This categorization then guides the choices made in subsequent RMF activities.
Within the NIST Risk Management Framework (RMF), the Categorize Step (often referred to as RMF Step 1) is intended to inform and guide subsequent organizational risk management processes and tasks by determining the adverse impact associated with the loss of confidentiality, integrity, and availability of a system and the information it processes, stores, and transmits. In practice, this step establishes the impact-level characterization of the system that shapes downstream RMF activities. In some implementations the associated tasks are labeled (for example, C-1, C-2, and C-3), though task labeling and specific procedures can vary across RMF editions and across implementing organizations (such as DoD or CMS). This definition addresses the RMF context specifically; categorization approaches under other frameworks, and jurisdiction- or agency-specific requirements, fall outside its scope and should be verified against the applicable primary source.
Why it matters
The Categorize Step sits at the front of the NIST Risk Management Framework because the decisions made here ripple through every activity that follows. By determining the adverse impact that would result from a loss of confidentiality, integrity, or availability of a system and the information it processes, stores, and transmits, this step effectively sizes the system's importance to the organization. Getting this characterization right helps ensure that later RMF activities are proportionate: a system whose compromise would cause severe harm warrants a different level of attention than one whose compromise would be a minor inconvenience.
Because categorization informs and guides subsequent risk management processes and tasks, an error at this stage can propagate. If a system's potential impact is understated, downstream decisions may be calibrated too loosely relative to the actual stakes; if overstated, effort may be directed disproportionately. In this sense the Categorize Step is less a standalone deliverable than a foundational input that shapes how the rest of the framework is applied to a given system.
It is worth noting that this definition addresses the RMF context specifically. Categorization approaches under other frameworks, and jurisdiction- or agency-specific requirements, fall outside its scope and should be verified against the applicable primary source. Task labeling and specific procedures can also vary across RMF editions and across implementing organizations, so practitioners should confirm details against the guidance that governs their environment.
Who it's relevant to
Inside Categorize Step
Common questions
Answers to the questions practitioners most commonly ask about Categorize Step.

