What is NIST SP 800-53?
NIST SP 800-53 is the catalog of security and privacy controls that U.S. federal agencies use to protect their information systems, from account management and logging to backups and supply chain risk. Revision 5, published in September 2020 and most recently updated in Release 5.2.0 in August 2025, groups the controls into 20 families.
NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations, is a catalog of safeguards against threats that range from hostile attacks and human error to natural disasters and structural failures. The controls are mandatory for federal information systems, NIST encourages state, local and tribal governments and private companies to consider them, and nongovernmental organizations may use the publication voluntarily. Revision 5 runs to 492 pages. It was published in September 2020 with updates as of December 10, 2020, and NIST now issues smaller releases of the same catalog. The most recent, Release 5.2.0 on August 27, 2025, added SA-15(13), SA-24 and SI-02(07) and updated several existing controls.
Revision 5 groups its controls into 20 families, each with a two-letter identifier: Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Assessment, Authorization, and Monitoring (CA), Configuration Management (CM), Contingency Planning (CP), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Physical and Environmental Protection (PE), Planning (PL), Program Management (PM), Personnel Security (PS), PII Processing and Transparency (PT), Risk Assessment (RA), System and Services Acquisition (SA), System and Communications Protection (SC), System and Information Integrity (SI) and Supply Chain Risk Management (SR). Each family holds base controls, such as IA-2, Identification and Authentication (Organizational Users), and enhancements that strengthen them, such as IA-2(1), which requires multi-factor authentication for privileged accounts.
Revision 5 moved control selection into a companion publication, SP 800-53B. It defines three security baselines, one each for low-, moderate- and high-impact systems, plus a privacy baseline applied whatever the impact level, along with tailoring guidance and overlays for particular communities. Federal agencies select a baseline for each system, tailor it and assess it with SP 800-53A under NIST's Risk Management Framework. Cloud providers seeking FedRAMP authorization have worked to FedRAMP baselines built on the Revision 5 catalog; FedRAMP's legacy documentation carries a June 24, 2026 notice that it is moving to new consolidated rules for 2026, so check fedramp.gov for the current process.
Two other NIST publications lean on it. NIST SP 800-171, the standard for Controlled Unclassified Information in contractor systems, takes its derived requirements from SP 800-53 controls, and Revision 3 of 800-171 starts directly from the SP 800-53B moderate baseline, keeping what protects confidentiality and is the contractor's job. The NIST Cybersecurity Framework describes outcomes rather than controls, and NIST publishes mappings between it and SP 800-53 Revision 5. NetSys uses the CSF as the outline for the security programs it runs for managed clients, so when a customer asks about SP 800-53 controls, the answer starts from NIST's published mapping rather than from a blank page.
The 20 NIST SP 800-53 control families
| ID | Family | Example control |
|---|---|---|
| AC | Access Control | AC-2 Account Management |
| AT | Awareness and Training | AT-2 Literacy Training and Awareness |
| AU | Audit and Accountability | AU-2 Event Logging |
| CA | Assessment, Authorization, and Monitoring | CA-7 Continuous Monitoring |
| CM | Configuration Management | CM-8 System Component Inventory |
| CP | Contingency Planning | CP-9 System Backup |
| IA | Identification and Authentication | IA-2 Identification and Authentication (Organizational Users) |
| IR | Incident Response | IR-4 Incident Handling |
| MA | Maintenance | MA-4 Nonlocal Maintenance |
| MP | Media Protection | MP-6 Media Sanitization |
| PE | Physical and Environmental Protection | PE-3 Physical Access Control |
| PL | Planning | PL-2 System Security and Privacy Plans |
| PM | Program Management | PM-9 Risk Management Strategy |
| PS | Personnel Security | PS-4 Personnel Termination |
| PT | PII Processing and Transparency | PT-2 Authority to Process Personally Identifiable Information |
| RA | Risk Assessment | RA-5 Vulnerability Monitoring and Scanning |
| SA | System and Services Acquisition | SA-9 External System Services |
| SC | System and Communications Protection | SC-7 Boundary Protection |
| SI | System and Information Integrity | SI-2 Flaw Remediation |
| SR | Supply Chain Risk Management | SR-3 Supply Chain Controls and Processes |
Why it matters for a small business
Most small businesses never implement SP 800-53 in full: it is written for federal systems, and Revision 5 alone runs to 492 pages. It matters to you when a contract or customer names it, for example a cloud service you sell to federal agencies, a state or agency contract that writes 800-53 controls into its security terms, or a large customer's questionnaire organized by 800-53 control families. In those cases, ask which baseline or which controls apply rather than promising compliance with the whole catalog. For everyone else, the NIST Cybersecurity Framework, or NIST SP 800-171 if you handle CUI, is the right-sized starting point, and both trace back to the same controls.
Where NetSys handles this
NIST SP 800-53: FAQs
What is NIST SP 800-53 used for?
Federal agencies use NIST SP 800-53 to select, implement and assess the security and privacy controls on their information systems, where the controls are mandatory. Cloud providers seeking FedRAMP authorization have worked to baselines built from it, and NIST SP 800-171 for contractors draws its requirements from it. Private companies may use it voluntarily, usually when a contract or a large customer asks for it.
How many control families are in NIST 800-53 Rev 5?
Twenty: AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI and SR, from Access Control to Supply Chain Risk Management. Each family holds base controls and enhancements. Revision 5 added the Supply Chain Risk Management family and merged the privacy controls, which Revision 4 kept in a separate appendix, into one catalog with the security controls.
What is the difference between NIST 800-53 and 800-171?
NIST SP 800-53 is the full control catalog for federal information systems, while NIST SP 800-171 is a much shorter set of requirements for protecting the confidentiality of CUI in a contractor's systems. 800-171 is derived from 800-53, and its Revision 3 is tailored from the 800-53B moderate baseline. Revision 2 of 800-171, with 110 requirements, is the version Defense Department assessments use today.
What are the NIST 800-53 baselines?
The baselines are starting sets of controls published in SP 800-53B: one each for low-, moderate- and high-impact systems, plus a privacy baseline applied regardless of impact level. An agency picks the baseline that matches a system's impact level, then tailors it with the guidance in the same publication. SP 800-53B Release 5.2.0, issued August 27, 2025, made no changes to the baselines.
Do small businesses need to comply with NIST 800-53?
Usually not. The controls are mandatory for federal information systems, and NIST says nongovernmental organizations may use them voluntarily. A small business needs them when a contract or customer requires it, such as a cloud service sold to federal agencies or a contract that writes 800-53 controls into its security terms. Otherwise the NIST Cybersecurity Framework, or NIST SP 800-171 for CUI, is the usual starting point.
What changed between NIST 800-53 Rev 4 and Rev 5?
Revision 5 made controls outcome-based by removing the responsible entity from each control statement, merged security and privacy controls into one catalog, added the Supply Chain Risk Management family and moved the control baselines into SP 800-53B. NIST withdrew Revision 4 on September 23, 2021, one year after Revision 5 was published, so new work should use Revision 5 and its later releases.
More terms
Find out which controls the request really covers.
Send us the contract clause or questionnaire that names NIST SP 800-53. A NetSys engineer will identify the baseline or controls it points to, compare them with what you run today and outline the gaps. Month to month, no long-term contract.
