Skip to main content
Category: Standards and Frameworks

NIST SP 800-146

Also known as: SP 800-146, NIST Special Publication 800-146, Cloud Computing Synopsis and Recommendations
Simply put

NIST SP 800-146 is a guidance document published by the U.S. National Institute of Standards and Technology (NIST) in May 2012 that serves as a general guide to cloud computing. It reprises the NIST-established definition of cloud computing and describes the benefits and open issues associated with adopting cloud services. It is advisory in nature rather than a certifiable standard or audit framework.

Formal definition

NIST Special Publication 800-146, titled "Cloud Computing Synopsis and Recommendations" (finalized May 29, 2012), is a NIST guidance publication that reprises the NIST definition of cloud computing, explains the different cloud computing technologies and deployment configurations, describes cloud computing benefits and open issues, and recommends methods and approaches for evaluating and adopting cloud services. It provides terminology used elsewhere in NIST guidance, including the definition of a "cloud provider" as an organization that provides cloud services. As a synopsis-and-recommendations document, it functions as informational reference material and does not itself constitute a control framework, attestation criteria, or certification requirement; organizations using it in a SOC 2 or ISO 27001 context would typically reference it as supporting guidance rather than as an auditable standard.

Why it matters

NIST SP 800-146 provides a common vocabulary and conceptual foundation for discussing cloud computing, which matters because cloud adoption sits at the center of most modern security compliance programs. When compliance managers, auditors, and security engineers need to describe cloud deployment configurations, cloud provider relationships, or the trade-offs of adopting cloud services, referencing a widely cited NIST publication offers a neutral, authoritative touchstone rather than vendor-specific marketing language.

In the context of SOC 2 and ISO 27001 work, the document's value is primarily terminological and educational. It reprises the NIST-established definition of cloud computing and defines terms such as "cloud provider" that appear throughout other NIST guidance, helping teams align on what they mean when scoping cloud environments. Because cloud computing introduces shared-responsibility considerations, its plain-language treatment of benefits and open issues can help organizations reason about the risks they later address through actual controls.

It is important not to overstate its role. SP 800-146 is advisory guidance, not a control framework, attestation criteria, or certification requirement. It does not produce a certificate, does not substitute for the Trust Services Criteria in a SOC 2 examination, and does not map to ISO 27001 clauses or Annex A controls. Organizations would typically cite it as supporting reference material rather than as an auditable standard, and using it does not by itself demonstrate compliance with any framework.

Who it's relevant to

Compliance and GRC managers
Managers scoping cloud environments for a SOC 2 examination or ISO 27001 ISMS can use SP 800-146 as a neutral reference for cloud terminology and deployment concepts. It helps establish a shared understanding of what a cloud provider is and what cloud adoption involves, though it should be treated as supporting guidance rather than as an auditable standard or a substitute for framework criteria.
Security engineers and architects
Engineers evaluating or adopting cloud services may find value in the document's explanation of cloud technologies, deployment configurations, and the benefits and open issues of cloud computing. Its recommended methods and approaches for evaluating cloud services can inform architectural decisions, but the actual security controls are defined and tested through the applicable compliance framework.
Auditors and assessors
Auditors and assessors may encounter SP 800-146 cited as supporting reference material in a service organization's documentation. It is useful to recognize that the publication is advisory and does not constitute attestation criteria or certification requirements, so its presence does not itself evidence that a control is designed or operating effectively under SOC 2 or ISO 27001.

Inside SP 800-146

Cloud Computing Synopsis and Recommendations
NIST SP 800-146 is a NIST Special Publication that provides an overview of cloud computing concepts, service models, and recommendations. It is descriptive and advisory in nature rather than a certifiable standard or an auditable control framework.
Service Model Discussion
The publication typically discusses cloud service models such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), describing their general characteristics and considerations rather than prescribing specific audit criteria.
General Guidance Orientation
It offers guidance and recommendations for organizations evaluating or adopting cloud services, focusing on understanding trade-offs and considerations rather than on issuing certifications or attestation reports.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-146.

Is NIST SP 800-146 a compliance framework that I can be certified or audited against like SOC 2 or ISO 27001?
No. NIST SP 800-146 is a descriptive publication that explains cloud computing concepts and characteristics; it is not a certifiable standard or an attestation framework. There is no certificate or audit report issued against it in the way an ISO/IEC 27001 certificate is issued by an accredited certification body or a SOC 2 report is issued by a licensed CPA firm under SSAE 18. It serves as reference and educational material rather than a set of auditable requirements.
Does aligning to NIST SP 800-146 mean my organization satisfies SOC 2 or ISO 27001 requirements?
No. Familiarity with or alignment to the concepts in NIST SP 800-146 does not, on its own, satisfy SOC 2 Trust Services Criteria or the ISMS requirements in ISO/IEC 27001 clauses 4 through 10. Those frameworks have their own evidentiary and control expectations. Any relationship is conceptual context rather than direct equivalence, and satisfying one body of guidance does not automatically satisfy another.
How might NIST SP 800-146 be useful when scoping a SOC 2 or ISO 27001 engagement involving cloud services?
It can help teams establish shared terminology and understanding of cloud service and deployment concepts, which may support conversations about scope boundaries with an auditor or certification body. Depending on scope, that shared vocabulary can assist in describing how cloud-hosted systems are defined, though the actual scope decisions are driven by the applicable Trust Services Criteria or the defined ISMS boundary, not by this publication.
Can I cite NIST SP 800-146 as evidence during a SOC 2 examination or ISO 27001 audit?
Referencing it as background context is generally reasonable, but in most engagements it would not stand as control evidence. A SOC 2 examination evaluates the design and, for a Type II, operating effectiveness of the in-scope controls over the defined period, and an ISO 27001 audit evaluates the ISMS against clauses 4 through 10 with Annex A controls selected via the Statement of Applicability. Evidence typically consists of your own policies, records, and control artifacts rather than external reference documents.
Where does NIST SP 800-146 fit relative to the responsibilities shared between a cloud provider and a customer?
It provides conceptual grounding for understanding different cloud service and deployment approaches, which can inform discussions about where responsibilities may sit. In practice, the allocation of control responsibilities is documented in your own risk assessment, control descriptions, and any provider attestations you rely upon. For a SOC 2, this often surfaces through complementary user entity controls; for ISO 27001, through the scope and Statement of Applicability.
Should our compliance documentation depend on the specific concepts or figures in NIST SP 800-146?
It is prudent to treat the publication as reference material and to verify the current edition and any specific wording before citing it, since guidance documents can be revised or superseded over time. Depending on scope, teams typically anchor their documentation to the applicable framework requirements themselves and use publications like this for context rather than as a source of auditable obligations.

Common misconceptions

NIST SP 800-146 is a compliance framework that organizations can be certified or audited against, similar to SOC 2 or ISO 27001.
It is a NIST Special Publication providing guidance and recommendations. It is not a certifiable standard, and no certification body issues certificates against it, nor does a CPA firm produce an attestation report against it. SOC 2 (an AICPA SSAE 18 attestation examination resulting in a report) and ISO/IEC 27001 (a certification issued by an accredited certification body against an ISMS standard) serve distinct purposes and should not be conflated with this publication.
Following NIST SP 800-146 automatically satisfies SOC 2 or ISO 27001 requirements.
Guidance in a NIST publication does not automatically map to or satisfy the Trust Services Criteria of a SOC 2 examination or the ISMS requirements in ISO/IEC 27001 clauses 4 through 10 and Annex A reference controls. Any alignment is partial and depends on scope, and satisfying one does not automatically satisfy another.
NIST SP 800-146 defines mandatory controls that cloud providers must implement.
It is advisory in nature and offers recommendations rather than mandatory controls. Whether and how any recommendation is applied typically depends on an organization's scope, risk decisions, and applicable requirements.

Best practices

Treat NIST SP 800-146 as advisory guidance to inform cloud decisions, and do not represent adherence to it as a certification or an attestation report.
When pursuing SOC 2, work with a licensed CPA firm to map relevant cloud considerations to the applicable Trust Services Criteria, recognizing that Security (the Common Criteria) is required and other categories are selected based on scope.
When pursuing ISO/IEC 27001, address cloud considerations through your ISMS risk assessment and Statement of Applicability rather than assuming a NIST publication substitutes for the clause 4 through 10 requirements or Annex A control selection.
Document clearly which framework or standard each cloud control supports, since mapping between SOC 2, ISO 27001, and NIST guidance is typically partial and varies by scope.
Define and record the scope of any cloud environment being evaluated, and note the boundaries of what each SOC 2 report or ISO 27001 certificate actually covers.
Consult the specific published edition of the NIST document and describe its recommendations qualitatively where exact figures or citations cannot be confirmed, avoiding reliance on assumed control counts or fixed durations.