Who uses NIST 800-53?
Federal agencies are the primary users. Under the Federal Information Security Modernization Act (FISMA) and FIPS 200, agencies select and implement 800-53 controls for their systems as part of the NIST Risk Management Framework (SP 800-37), which walks each system through categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
Cloud service providers meet 800-53 through FedRAMP, which builds its Low, Moderate, and High authorization baselines on the 800-53 catalog. State governments, defense and civilian contractors, and regulated private companies also adopt it because it is detailed, free, and widely mapped to other frameworks.
Revision 5 made the catalog outcome-based and removed the word "federal" from the title, so the controls apply to any organization. It also merged privacy controls into the main catalog and moved baselines into the separate SP 800-53B.
What are the NIST 800-53 control families?
Revision 5 organizes controls into 20 families. Each control has an identifier made of the family code and a number, such as AC-2 (Account Management). Control enhancements add rigor and appear in parentheses, such as AC-2(1) for automated account management.
| ID | Family |
|---|---|
| AC | Access Control |
| AT | Awareness and Training |
| AU | Audit and Accountability |
| CA | Assessment, Authorization, and Monitoring |
| CM | Configuration Management |
| CP | Contingency Planning |
| IA | Identification and Authentication |
| IR | Incident Response |
| MA | Maintenance |
| MP | Media Protection |
| PE | Physical and Environmental Protection |
| PL | Planning |
| PM | Program Management |
| PS | Personnel Security |
| PT | PII Processing and Transparency |
| RA | Risk Assessment |
| SA | System and Services Acquisition |
| SC | System and Communications Protection |
| SI | System and Information Integrity |
| SR | Supply Chain Risk Management |
Release 5.2.0 (August 2025) added controls focused on secure software updates and resilience, including SA-24 (Design for Cyber Resiliency) and SI-2(7) (Root Cause Analysis). For a primer on what a control is and how it is tested, see what is a security control.
How do NIST 800-53 baselines work?
A baseline is a starting set of controls. First, the system owner categorizes the system using FIPS 199 by rating the potential impact (low, moderate, or high) of a loss of confidentiality, integrity, or availability. The highest rating across the three usually sets the system's overall impact level, which selects the Low, Moderate, or High security baseline in SP 800-53B.
Higher baselines include more controls and more enhancements. The privacy baseline is separate and applies based on whether the system processes personally identifiable information, not on the security impact level.
Baselines are then tailored: controls can be scoped out with justification, compensating controls can be substituted, and organization-defined parameters (such as how often to review accounts) are filled in. Overlays, such as those published for specific communities, apply a predefined set of tailoring decisions.
How GRC engineers automate NIST 800-53
800-53 is large, which is exactly why automation pays off. Typical patterns:
- Controls as OSCAL data: Load NIST's published OSCAL catalog and baseline profiles, then write the system security plan as an OSCAL SSP so implementation statements are versioned and machine-validated.
- AC-2 account management: A scheduled job pulls users and roles from AWS IAM and the identity provider, flags inactive or orphaned accounts, and stores the output as evidence of the review.
- CM-2 and CM-6 configuration: Terraform defines the baseline configuration, and AWS Config rules or Azure Policy detect settings that drift from it.
- AU-2 and AU-12 logging: Checks confirm CloudTrail or equivalent audit logging is enabled in every account and region, and alert when it is not.
- Findings mapped to controls: AWS Security Hub includes a NIST SP 800-53 Rev. 5 standard, so failed checks arrive already tagged with the control they affect.
- CA-7 continuous monitoring: Pipelines aggregate these results daily, which supports the RMF monitoring step and FedRAMP continuous monitoring reporting.
Related: what is OSCAL, the FedRAMP compliance guide, and IaC compliance scanning.
Frequently Asked Questions
What is NIST 800-53?
NIST Special Publication 800-53 is a catalog of security and privacy controls for information systems and organizations, published by the National Institute of Standards and Technology. Federal agencies use it to protect federal systems, and it is the control basis for FedRAMP. The current version is Revision 5, with release 5.2.0 issued on August 27, 2025.
How many control families are in NIST 800-53 Rev 5?
Revision 5 has 20 control families, from Access Control (AC) to Supply Chain Risk Management (SR). Revision 5 added the PII Processing and Transparency (PT) and Supply Chain Risk Management (SR) families. Each family contains base controls and optional control enhancements.
What are the NIST 800-53 baselines?
NIST SP 800-53B defines three security control baselines (Low, Moderate, and High) and a separate privacy baseline. A system's security baseline is chosen from its FIPS 199 impact categorization, then tailored to the system's risks and environment.
Who has to comply with NIST 800-53?
Federal agencies must apply it to federal information systems under FISMA and FIPS 200. Cloud providers selling to federal agencies meet it through FedRAMP, and some contractors inherit it through contract terms. Private organizations can adopt it voluntarily as a comprehensive control catalog.
What is the difference between NIST 800-53 and NIST 800-171?
NIST SP 800-53 is the full control catalog for federal systems. NIST SP 800-171 is a smaller set of requirements for protecting Controlled Unclassified Information in nonfederal systems, such as those run by defense contractors, and its requirements are derived from 800-53. CMMC Level 2 is based on 800-171.
Is NIST 800-53 available in machine-readable form?
Yes. NIST publishes the 800-53 catalog and the 800-53B baselines in OSCAL formats (JSON, XML, and YAML), and the Cybersecurity and Privacy Reference Tool offers additional downloads. This lets teams load controls directly into tooling instead of copying them from a PDF.