Federal control catalog · Rev 5

NIST SP 800-53

Security and privacy controls, mapped and made actionable.

01 Overview

What is NIST SP 800-53?

NIST Special Publication 800-53 is the authoritative catalog of security and privacy controls for federal information systems and any organization that processes, stores, or transmits federal data. It tells organizations what to implement — specific, auditable controls — rather than describing high-level outcomes.

Controls are grouped into 20 families spanning access control, audit, incident response, supply chain risk, and more. Each control is assigned to one or more baselines (Low, Moderate, High, Privacy). Organizations select the baseline that matches their system's impact level — not every control applies to every system.

02 Audience

Who uses it, and why it matters

NIST SP 800-53 governs far more than internal IT. Many of its controls dictate how organizations select, assess, and monitor the vendors and external services in their supply chain.

Federal agencies & contractors

Required under FISMA and foundational to FedRAMP authorization packages.

Defense industrial base

CMMC and DFARS flows reference 800-53 control language; supply chain programs inherit SA and SR family requirements.

Enterprises with federal data

Organizations handling CUI, FCI, or federal contract data align vendor and internal posture to 800-53 baselines.

Third-party risk teams

Vendor assessments, security questionnaires, and continuous monitoring map directly to SA, SR, PS, and RA controls.

Many 800-53 controls govern how organizations select, assess, and monitor vendors and external services — not just internal IT. UpGuard helps teams operationalize those requirements through automated questionnaires, continuous external monitoring, and risk-mapped reporting.

03 Baselines

Control baselines explained

NIST SP 800-53 Rev 5 defines four baseline profiles. Each baseline is a curated subset of controls appropriate for a given impact level.

Low

Minimal impact systems

For systems where loss of confidentiality, integrity, or availability would have a limited adverse effect.

Moderate

Most federal & enterprise systems

The default for many federal systems and the baseline most organizations reference for vendor assessments.

High

Critical infrastructure

For systems where a breach could cause severe or catastrophic harm to operations, assets, or individuals.

Privacy

Privacy overlay controls

Additional controls to manage privacy risk beyond the security baseline — often combined with Low, Moderate, or High.

04 Control library

Browse control families

NIST SP 800-53 organizes controls into 20 families. Select a family to browse its controls, implementation guidance, and cross-framework mappings.

ac
23 controls

Access Control

Govern who can access systems and data, and under what conditions.

at
5 controls

Awareness and Training

Ensure personnel understand security risks and their responsibilities.

au
15 controls

Audit and Accountability

Record, review, and protect audit logs of system activity.

ca
8 controls

Assessment, Authorization, and Monitoring

Assess control effectiveness and maintain ongoing system authorization.

cm
14 controls

Configuration Management

Establish and maintain secure baseline configurations for systems.

cp
12 controls

Contingency Planning

Prepare for and recover from disruptions to system operations.

ia
13 controls

Identification and Authentication

Verify user and device identity before granting system access.

ir
9 controls

Incident Response

Detect, respond to, and recover from security incidents.

ma
7 controls

Maintenance

Perform system maintenance securely and with appropriate oversight.

mp
8 controls

Media Protection

Protect and sanitize system media containing sensitive data.

pe
22 controls

Physical and Environmental Protection

Restrict physical access to systems, facilities, and equipment.

pl
8 controls

Planning

Develop and maintain security and privacy plans for systems.

pm
32 controls

Program Management

Govern the organization-wide security and privacy program.

ps
9 controls

Personnel Security

Screen personnel and manage access through the employment lifecycle.

pt
8 controls

PII Processing and Transparency

Manage how personally identifiable information is processed and disclosed.

ra
9 controls

Risk Assessment

Identify, assess, and respond to organizational and system risk.

sa
17 controls

System and Services Acquisition

Manage security in system development and external service acquisition.

sc
47 controls

System and Communications Protection

Protect communications and boundaries between systems and networks.

si
22 controls

System and Information Integrity

Detect flaws, malware, and unauthorized changes to systems.

sr
12 controls

Supply Chain Risk Management

Manage risks from suppliers, developers, and service providers.

05 Featured

Frequently referenced controls

Looking for a specific control? Start with these frequently referenced requirements.

AC-2
Access Control

Account Management

Orphaned accounts, over-provisioned vendor access, and lifecycle gaps.

IA-5
Identification

Authenticator Management

Password policy, MFA, and credential hygiene failures.

PS-4
Personnel

Personnel Termination

Offboarding failures and insider access after termination.

SA-9
Acquisition

External System Services

Vendor and cloud service security requirements.

SR-2
Supply Chain

Supply Chain Risk Management Plan

Supply chain risk program foundations.

RA-5
Risk

Vulnerability Monitoring & Scanning

Continuous vulnerability management and scanning.

AU-2
Audit

Event Logging

Audit log requirements and monitoring foundations.

SC-7
Comms

Boundary Protection

Network segmentation and perimeter controls.

06 Compare

NIST SP 800-53 vs related frameworks

Not sure which NIST resource you need? Here's how 800-53 differs from the frameworks it's most often confused with.

Framework What it is UpGuard page
NIST CSF Outcomes-based cybersecurity framework — Identify, Protect, Detect, Respond, Recover. View hub →
NIST SP 800-53 (this page) Control catalog — specific, auditable security and privacy controls. You're here
NIST SP 800-171 CUI protection requirements for non-federal organizations — an 800-53 subset. Read guide →
ISO 27001:2022 International ISMS standard with Annex A controls. View hub →

Every NIST SP 800-53 control page in this hub includes mapped equivalents in ISO 27001:2022 and NIST SP 800-171 — so teams can trace requirements across frameworks without maintaining separate spreadsheets.

UpGuard vendor risk assessment dashboard mapped to NIST 800-53 controls
Vendor & Third-party risk

Assess vendors against 800-53 control language

Better assess vendor security, adherence to cybersecurity standards, and data protection capabilities.

  • Ensure vendors meet your NIST-aligned cybersecurity standards

  • Automate vendor risk assessments to detect threats across your supply chain

  • Map SA, SR, PS, and RA controls to onboarding, monitoring, and offboarding

  • Use risk-mapped questionnaires to evaluate third parties against 800-53

Know your vendor risks
07 Free resources

Tools, templates & guides

Free resources to help you implement and assess NIST SP 800-53 controls — use alongside the control library above.

Guide
NIST 800-53 Compliance Checklist & Security Controls Guide

NIST 800-53 Compliance Checklist & Security Controls Guide

A practical, control-by-control checklist for planning and tracking your 800-53 implementation.

Template
NIST 800-53 Risk Assessment Template

NIST 800-53 Risk Assessment Template

A ready-to-use template to document, score, and prioritize risk against 800-53 controls.

Resource
NIST 800-53 Checklist (downloadable)

NIST 800-53 Checklist (downloadable)

Download the full checklist as a working resource for your security and audit teams.

08 FAQ

Frequently asked questions

Free resources to help you implement and assess NIST SP 800-53 controls — use alongside the control library above.

NIST SP 800-53 is a catalog of security and privacy controls published by the National Institute of Standards and Technology. It defines specific, auditable requirements that federal agencies and their contractors use to protect information systems. Organizations select controls based on their system's impact level (Low, Moderate, High, or Privacy baseline). Browse all control families on this page ↑
NIST SP 800-53 Revision 5 contains approximately 300 active controls organized into 20 families. The exact count varies slightly by revision — Rev 5.2.0 added controls and withdrew others. Not every organization implements every control; baseline profiles (Low, Moderate, High, Privacy) define which controls apply.
Control families are thematic groupings that organize related controls — for example, Access Control (AC), Identification and Authentication (IA), and Supply Chain Risk Management (SR). NIST SP 800-53 Rev 5 defines 20 families spanning AC through SR. Each family has its own index page in this hub where you can browse individual controls.
NIST CSF is an outcomes-based framework organized around five core functions (Identify, Protect, Detect, Respond, Recover). NIST SP 800-53 is a control catalog with specific, auditable requirements. CSF helps organizations prioritize cybersecurity outcomes; 800-53 tells them exactly what to implement. Many organizations use both — CSF for strategic planning and 800-53 for detailed control selection. See our NIST Cybersecurity Framework page for CSF-specific guidance.
Baselines are pre-defined subsets of controls matched to a system's impact level. Low baseline applies to systems with limited adverse impact if compromised. Moderate is the most common reference for federal systems and vendor assessments. High baseline applies to systems where a breach could cause severe harm. A separate Privacy baseline adds controls for managing privacy risk. Organizations inherit their baseline from their system's FIPS 199 categorization.
Federal agencies must comply under FISMA. Federal contractors and cloud service providers typically align to 800-53 controls through FedRAMP authorization or agency-specific requirements. Non-federal organizations that handle Controlled Unclassified Information (CUI) often work from NIST SP 800-171, which maps to a subset of 800-53 controls. Enterprises also use 800-53 voluntarily to structure security programs and vendor assessments.
FedRAMP authorization packages are built on NIST SP 800-53 controls at the Moderate or High baseline. Cloud service providers seeking FedRAMP authorization must demonstrate implementation of the applicable 800-53 controls and provide evidence for assessment. UpGuard helps CSPs and their customers assess whether vendors meet the control requirements relevant to their authorization boundary.
Start by identifying which 800-53 controls apply to your vendor relationships — typically controls from the SA, SR, PS, and RA families. Use a NIST-aligned security questionnaire to collect vendor attestations, then validate responses with continuous external monitoring. UpGuard provides a risk-mapped NIST questionnaire and automated vendor assessment workflows. See our NIST 800-53 questionnaire template to get started.

Experience superior visibility and a simpler approach to cyber risk management