NFPA 3000 Explained: What the ASHER Standard Actually Requires of Your Facility

Picture a Tuesday night on a mid-sized campus. A camera on a covered walkway records a single figure working his way down the row of doors, testing handles. The footage is sharp, correctly exposed, and retained exactly as designed. Nobody looks at it until Thursday morning, and by then the only useful thing it can do is describe what already happened. That gap between recording and knowing is the exact failure NFPA 3000 was written to close.
That building is not unprepared in the way people usually mean. It has cameras, an access control system, a binder with the words emergency response on the spine, and a line item for security in next year's budget. What it does not have is a program. NFPA 3000 is the national standard that defines what a program actually consists of, and reading it is an uncomfortable exercise for most facility owners, because roughly half of it describes work that no police department, fire service, or alarm vendor can do on your behalf.
Featured image: a real IntelliSee detection of unauthorized access on an institutional building perimeter after hours. It is an actual capture, not an illustration. The model's confidence score was removed and the class label re-rendered for publication.
What is NFPA 3000?
NFPA 3000 is the National Fire Protection Association's Standard for an Active Shooter/Hostile Event Response (ASHER) Program, and the current edition is the 2024 edition, published in January 2024. It is the only consensus standard in the United States that treats an active shooter or hostile event as a whole-program problem rather than a tactical one, covering the entire arc from risk assessment through response to long-term recovery.
The standard's own scope statement is deliberately narrow: "The scope of this standard is limited to the necessary functions and actions related to preparedness, response, and recovery from an active shooter/hostile event (ASHE)." The U.S. Department of Health and Human Services, through its ASPR TRACIE technical resource library, describes the document as identifying "the minimum program elements needed to organize, manage, and sustain an active shooter and/or hostile event response program that helps mitigate the risks, effect, and impact on an organization or community affected by these events."
NFPA developed it on an accelerated schedule after the 2017 Las Vegas shooting and first issued it in 2018 as a provisional standard, which is why a great deal of the material still circulating online refers to "NFPA 3000 (PS)." That designation is obsolete. If a consultant, a training vendor, or a checklist you found in a shared drive still cites the provisional edition, it is at least two revision cycles behind, and the chapter numbering has changed since.
Is NFPA 3000 mandatory, and who enforces it?
NFPA 3000 is a voluntary consensus standard, which means it carries no force of law on its own and becomes enforceable only when something else adopts it. Three mechanisms do that in practice: a state or local authority having jurisdiction writes it into code, a contract or lease requires compliance with it, or an insurer or accrediting body references it as the expected standard of care.
That third mechanism is the one facility owners underestimate. A voluntary standard that is widely published, freely readable, and specific about what a reasonable organization should have done is exactly the kind of document that gets cited after an incident, in the section of a complaint dealing with foreseeability. The question is rarely whether a jurisdiction adopted NFPA 3000. The question is whether a reasonable operator in your sector knew the standard existed and chose to do less than it describes.
Not mandatory is not the same as not enforceable. Treat NFPA 3000 the way you would treat any published standard of care in your industry. Confirm with your authority having jurisdiction whether it has been adopted locally, then assume that your insurer and any opposing counsel will read it regardless of the answer.
The 20 chapters of NFPA 3000, and the 10 that are your job
NFPA 3000 (2024) contains 20 chapters and five annexes, and 10 of those chapters describe work that belongs to the organization that owns the building rather than to the agencies that respond to it. That split is the single most useful thing to understand before you open the document, because it tells you which sections you are reading for information and which sections you are reading as a to-do list.
Chapters 1 through 3 are administration, referenced publications, and definitions. Chapters 7, 8, and 11 through 14 cover resource management, incident management, communications center support, and the competencies and protective equipment that law enforcement and fire and EMS personnel need; those are written for responders. Chapter 19 addresses hospitals receiving patients from an event that happened somewhere else.
Everything else is yours. Here is what the chapters that matter most actually ask for, and where facility programs tend to come apart.
| Chapter | What it asks of you | Where facilities fall short |
|---|---|---|
| 4. ASHER Program Development Process | A defined, documented program with an owner, not a collection of separate plans | Security, facilities, HR, and communications each hold a piece and no one holds the whole |
| 5. Risk Assessment | An assessment of hazards and vulnerabilities specific to this site, refreshed on a schedule | A one-time walkthrough from the year the building opened, never revisited |
| 6. Planning and Coordination | Planning done jointly with the agencies who will actually respond | A plan written internally and emailed to the police department for the file |
| 9. Facility Preparedness | Occupancy characteristics understood, an emergency action plan, and a working notification path | Notification depends on a human noticing first, which is the assumption that fails |
| 18. Continuity of Operation | A plan for operating while the site is a crime scene | Rarely written until the organization has already needed it |
| 20. Recovery | Immediate, early, and continued recovery, including family assistance | Treated as an afterthought, or delegated entirely to an insurer |
Chapter 5: risk assessment is not a walkthrough
Chapter 5 requires a risk assessment that identifies the hazards and vulnerabilities specific to your site, and it is the chapter most often satisfied on paper and failed in substance. A walkthrough that produces a list of broken locks is a maintenance punch list. An assessment that survives scrutiny identifies who can reach what, from where, at which hours, and what would actually detect them.
The practical test is simple. For every approach to your building, name the thing that would notice a person who should not be there, and name how long it would take. If the honest answer for the loading dock at 2 a.m. is "the morning shift," that is a documented vulnerability, and it is now written down in a document your own program required you to produce. That is not a reason to skip the assessment. It is the reason to do it, and our guide to running a physical security risk assessment walks through the same exercise in more detail.
Chapter 9: facility preparedness is where most programs quietly fail
Chapter 9 covers facility and occupancy characteristics, emergency action plans, and notification, and notification is where the whole standard meets physical reality. Every downstream chapter assumes a clock starts. Incident management, unified command, responder competencies, and recovery all measure from the moment someone knows. Chapter 9 is the chapter that decides when that moment happens.
In most buildings, the moment happens when a person sees something and decides to act. That is a genuine detection method and it has a genuine failure rate. It depends on someone being present, being oriented the right way, correctly interpreting what they are seeing, and choosing to escalate rather than assume it is nothing. Camera coverage does not change that equation on its own, because a recorded frame nobody is looking at is evidence rather than warning. We covered the same gap from the notification side in our analysis of the trigger gap in mass notification systems: the alerting infrastructure is usually fine, and the thing that is missing is whatever is supposed to pull the trigger.
What NFPA 3000 asks for that passive cameras cannot deliver
NFPA 3000 does not name any technology, and it does not have to, because the requirements it does state have technical consequences. A program that must produce timely notification needs something capable of noticing. A risk assessment that must document how each approach is covered needs an honest answer for the hours when nobody is watching a monitor.
This is the layer where AI video analytics belongs in an ASHER program, and it is worth being precise about what that means. Computer vision applied to the cameras you already own can detect a visible weapon, a person in an area that should be empty, a fall, a crowd forming, loitering, or smoke and fire, and can push an alert to the people named in your emergency action plan within seconds rather than at the next shift change. It runs on existing camera infrastructure, so the Chapter 5 assessment does not have to be answered with a capital request to replace hardware. Our breakdown of running AI video analytics on existing cameras covers what that migration actually involves, and a separate piece explains how AI detects weapons in real time.
Two things it does not do, and should not be sold as doing. It is not facial recognition, and IntelliSee does not perform facial recognition or identify individuals; for a Chapter 5 assessment that has to survive a privacy review, that is a feature rather than a limitation. And it is not a replacement for Chapters 6, 15, and 20. Detection shortens the interval between an event starting and a human knowing about it. Coordination, training, and recovery are still work that people have to do.
Chapter 10 and paying for the program
Chapter 10 is Financial Management, and the fact that a standards body wrote a funding chapter into a life safety standard tells you how often programs stall for budget reasons. The chapter asks organizations to document program costs, identify revenue sources, and plan for cost recovery, which in practice means knowing what your ASHER program costs before someone asks you to justify it.
For schools, houses of worship, nonprofits, and public agencies, a meaningful share of that cost is fundable through federal and state programs rather than the operating budget. Our security grant funding hub tracks the open programs and eligibility rules, which is a faster starting point than a general search when the deadline calendar matters more than the total dollar figure.
How to read NFPA 3000 without buying it
NFPA publishes read-only access to its codes and standards at no cost, so you can read NFPA 3000 in full before deciding whether to purchase it. Create a free account at nfpa.org, find the standard in the list of codes and standards, and choose the free access view. The document opens in a paginated reader.
Two limits are worth knowing before you plan around it. The free view is read-only, so you cannot download or print it, and free access covers the most recent edition, which means an older edition still enforced in a particular jurisdiction may not be available that way. As of August 2026 the current edition is 2024. If your authority having jurisdiction enforces an earlier one, confirm which before you build a checklist from the version on your screen.
Frequently asked questions about NFPA 3000
What does ASHER stand for?
ASHER stands for Active Shooter/Hostile Event Response. NFPA uses the related term ASHE, an active shooter or hostile event, for the incident itself, and ASHER for the response program built around it.
What is the current edition of NFPA 3000?
The 2024 edition is current as of August 2026. It supersedes the 2021 edition and the 2018 provisional standard, often written as NFPA 3000 (PS), which is no longer the version to work from.
Does NFPA 3000 apply to my organization?
NFPA 3000 is written to apply broadly to organizations and communities rather than to a single occupancy type, so schools, hospitals, campuses, houses of worship, venues, and employers all fall within its intent. Whether it applies as an enforceable requirement depends on adoption by your authority having jurisdiction or by contract.
How many chapters does NFPA 3000 have?
The 2024 edition has 20 chapters and five annexes. Ten of the 20 describe program work owned by the organization rather than by responding agencies.
Does NFPA 3000 require specific security technology?
No. NFPA 3000 states program requirements rather than specifying products, so it does not require cameras, analytics, or any particular vendor. It does require outcomes such as a documented risk assessment and a functioning notification path, and those outcomes have to be achieved by something.
Where to start
Read Chapter 5 and Chapter 9 first. They are short, they are unambiguous, and together they will tell you within an afternoon whether you have an ASHER program or a set of documents that resemble one. If the honest answer to "what notices, and how fast" is a person who may or may not be looking, that is the gap the rest of the standard is built on top of, and closing it is the highest-leverage thing you can do before the next assessment cycle.
IntelliSee exists to turn cameras that record into cameras that notice, using the infrastructure a facility already owns. If you are working through NFPA 3000 and want a straight answer about what your existing camera coverage could detect and how quickly it could alert the people in your emergency action plan, talk with our team.