NIST SP 800-146
NIST SP 800-146 is a guidance document published by the U.S. National Institute of Standards and Technology (NIST) in May 2012 that serves as a general guide to cloud computing. It reprises the NIST-established definition of cloud computing and describes the benefits and open issues associated with adopting cloud services. It is advisory in nature rather than a certifiable standard or audit framework.
NIST Special Publication 800-146, titled "Cloud Computing Synopsis and Recommendations" (finalized May 29, 2012), is a NIST guidance publication that reprises the NIST definition of cloud computing, explains the different cloud computing technologies and deployment configurations, describes cloud computing benefits and open issues, and recommends methods and approaches for evaluating and adopting cloud services. It provides terminology used elsewhere in NIST guidance, including the definition of a "cloud provider" as an organization that provides cloud services. As a synopsis-and-recommendations document, it functions as informational reference material and does not itself constitute a control framework, attestation criteria, or certification requirement; organizations using it in a SOC 2 or ISO 27001 context would typically reference it as supporting guidance rather than as an auditable standard.
Why it matters
NIST SP 800-146 provides a common vocabulary and conceptual foundation for discussing cloud computing, which matters because cloud adoption sits at the center of most modern security compliance programs. When compliance managers, auditors, and security engineers need to describe cloud deployment configurations, cloud provider relationships, or the trade-offs of adopting cloud services, referencing a widely cited NIST publication offers a neutral, authoritative touchstone rather than vendor-specific marketing language.
In the context of SOC 2 and ISO 27001 work, the document's value is primarily terminological and educational. It reprises the NIST-established definition of cloud computing and defines terms such as "cloud provider" that appear throughout other NIST guidance, helping teams align on what they mean when scoping cloud environments. Because cloud computing introduces shared-responsibility considerations, its plain-language treatment of benefits and open issues can help organizations reason about the risks they later address through actual controls.
It is important not to overstate its role. SP 800-146 is advisory guidance, not a control framework, attestation criteria, or certification requirement. It does not produce a certificate, does not substitute for the Trust Services Criteria in a SOC 2 examination, and does not map to ISO 27001 clauses or Annex A controls. Organizations would typically cite it as supporting reference material rather than as an auditable standard, and using it does not by itself demonstrate compliance with any framework.
Who it's relevant to
Inside SP 800-146
Common questions
Answers to the questions practitioners most commonly ask about SP 800-146.