Fundamentals

What Is NIST 800-53?

Updated

NIST SP 800-53 is the catalog of security and privacy controls that the National Institute of Standards and Technology publishes for federal information systems and organizations, and it is the control foundation for FedRAMP and much of U.S. government cybersecurity. This guide covers the 20 control families, the baselines in SP 800-53B, who uses the catalog, and how engineers automate it.

Key Takeaways

  • NIST SP 800-53 is the U.S. government catalog of security and privacy controls. Revision 5 is current, and release 5.2.0 was issued August 27, 2025.
  • Controls are grouped into 20 families, each identified by a two-letter code such as AC (Access Control) or SR (Supply Chain Risk Management).
  • SP 800-53B defines Low, Moderate, and High security baselines plus a privacy baseline. Systems pick a baseline from their FIPS 199 impact level, then tailor it.
  • Federal agencies apply 800-53 under FISMA, and FedRAMP builds its cloud baselines on it.
  • NIST publishes the catalog in OSCAL, which makes 800-53 one of the most automation-friendly frameworks available.

Who uses NIST 800-53?

Federal agencies are the primary users. Under the Federal Information Security Modernization Act (FISMA) and FIPS 200, agencies select and implement 800-53 controls for their systems as part of the NIST Risk Management Framework (SP 800-37), which walks each system through categorization, control selection, implementation, assessment, authorization, and continuous monitoring.

Cloud service providers meet 800-53 through FedRAMP, which builds its Low, Moderate, and High authorization baselines on the 800-53 catalog. State governments, defense and civilian contractors, and regulated private companies also adopt it because it is detailed, free, and widely mapped to other frameworks.

Revision 5 made the catalog outcome-based and removed the word "federal" from the title, so the controls apply to any organization. It also merged privacy controls into the main catalog and moved baselines into the separate SP 800-53B.

What are the NIST 800-53 control families?

Revision 5 organizes controls into 20 families. Each control has an identifier made of the family code and a number, such as AC-2 (Account Management). Control enhancements add rigor and appear in parentheses, such as AC-2(1) for automated account management.

IDFamily
ACAccess Control
ATAwareness and Training
AUAudit and Accountability
CAAssessment, Authorization, and Monitoring
CMConfiguration Management
CPContingency Planning
IAIdentification and Authentication
IRIncident Response
MAMaintenance
MPMedia Protection
PEPhysical and Environmental Protection
PLPlanning
PMProgram Management
PSPersonnel Security
PTPII Processing and Transparency
RARisk Assessment
SASystem and Services Acquisition
SCSystem and Communications Protection
SISystem and Information Integrity
SRSupply Chain Risk Management

Release 5.2.0 (August 2025) added controls focused on secure software updates and resilience, including SA-24 (Design for Cyber Resiliency) and SI-2(7) (Root Cause Analysis). For a primer on what a control is and how it is tested, see what is a security control.

How do NIST 800-53 baselines work?

A baseline is a starting set of controls. First, the system owner categorizes the system using FIPS 199 by rating the potential impact (low, moderate, or high) of a loss of confidentiality, integrity, or availability. The highest rating across the three usually sets the system's overall impact level, which selects the Low, Moderate, or High security baseline in SP 800-53B.

Higher baselines include more controls and more enhancements. The privacy baseline is separate and applies based on whether the system processes personally identifiable information, not on the security impact level.

Baselines are then tailored: controls can be scoped out with justification, compensating controls can be substituted, and organization-defined parameters (such as how often to review accounts) are filled in. Overlays, such as those published for specific communities, apply a predefined set of tailoring decisions.

How GRC engineers automate NIST 800-53

800-53 is large, which is exactly why automation pays off. Typical patterns:

  • Controls as OSCAL data: Load NIST's published OSCAL catalog and baseline profiles, then write the system security plan as an OSCAL SSP so implementation statements are versioned and machine-validated.
  • AC-2 account management: A scheduled job pulls users and roles from AWS IAM and the identity provider, flags inactive or orphaned accounts, and stores the output as evidence of the review.
  • CM-2 and CM-6 configuration: Terraform defines the baseline configuration, and AWS Config rules or Azure Policy detect settings that drift from it.
  • AU-2 and AU-12 logging: Checks confirm CloudTrail or equivalent audit logging is enabled in every account and region, and alert when it is not.
  • Findings mapped to controls: AWS Security Hub includes a NIST SP 800-53 Rev. 5 standard, so failed checks arrive already tagged with the control they affect.
  • CA-7 continuous monitoring: Pipelines aggregate these results daily, which supports the RMF monitoring step and FedRAMP continuous monitoring reporting.

Related: what is OSCAL, the FedRAMP compliance guide, and IaC compliance scanning.

Frequently Asked Questions

What is NIST 800-53?

NIST Special Publication 800-53 is a catalog of security and privacy controls for information systems and organizations, published by the National Institute of Standards and Technology. Federal agencies use it to protect federal systems, and it is the control basis for FedRAMP. The current version is Revision 5, with release 5.2.0 issued on August 27, 2025.

How many control families are in NIST 800-53 Rev 5?

Revision 5 has 20 control families, from Access Control (AC) to Supply Chain Risk Management (SR). Revision 5 added the PII Processing and Transparency (PT) and Supply Chain Risk Management (SR) families. Each family contains base controls and optional control enhancements.

What are the NIST 800-53 baselines?

NIST SP 800-53B defines three security control baselines (Low, Moderate, and High) and a separate privacy baseline. A system's security baseline is chosen from its FIPS 199 impact categorization, then tailored to the system's risks and environment.

Who has to comply with NIST 800-53?

Federal agencies must apply it to federal information systems under FISMA and FIPS 200. Cloud providers selling to federal agencies meet it through FedRAMP, and some contractors inherit it through contract terms. Private organizations can adopt it voluntarily as a comprehensive control catalog.

What is the difference between NIST 800-53 and NIST 800-171?

NIST SP 800-53 is the full control catalog for federal systems. NIST SP 800-171 is a smaller set of requirements for protecting Controlled Unclassified Information in nonfederal systems, such as those run by defense contractors, and its requirements are derived from 800-53. CMMC Level 2 is based on 800-171.

Is NIST 800-53 available in machine-readable form?

Yes. NIST publishes the 800-53 catalog and the 800-53B baselines in OSCAL formats (JSON, XML, and YAML), and the Cybersecurity and Privacy Reference Tool offers additional downloads. This lets teams load controls directly into tooling instead of copying them from a PDF.

Automate Federal Controls, Hands-On

The GRC Engineering Club teaches you to express controls as code, collect evidence from cloud APIs, and run continuous monitoring in real labs with a community of practitioners. Membership is $70 a year.