Skip to content
AZ2UBFTZZCTlewGg4Vy2lQ-AZ2UBFTZ9lLpOSAqYDBkDw
Quzara LLCAug 20, 20267 min read

NIST SP 800-53 Revision 5: The Complete Controls Guide

NIST SP 800-53 Revision 5: The Complete Controls Guide
11:12

TL;DR

NIST SP 800-53 Revision 5 is the current version of NIST's foundational catalog of security and privacy controls for federal information systems, published in September 2020 with ongoing updates. It organizes controls into 20 families covering everything from access control to supply chain risk management, and it underlies FedRAMP, FISMA, and much of CMMC. Rev 5 significantly expanded the catalog beyond prior revisions to integrate privacy controls directly alongside security controls and to address modern risks like supply chain and software development security. Understanding the control family structure is the starting point for any FedRAMP, FISMA, or CMMC compliance effort.


Table of Contents


What Is NIST SP 800-53?

NIST Special Publication 800-53, formally titled "Security and Privacy Controls for Information Systems and Organizations," is the control catalog that defines the specific security and privacy safeguards federal information systems must implement. It is published and maintained by the National Institute of Standards and Technology as part of the broader NIST Risk Management Framework.

Rather than telling an organization broadly to "be secure," 800-53 defines specific, discrete controls, such as requiring multi-factor authentication, encrypting data at rest, or maintaining an incident response plan, organized into families and mapped to different levels of risk.


What Changed in Revision 5

Revision 5, finalized in September 2020, represented the most significant update to the catalog in years. Key changes included:

Integrated privacy controls. Prior revisions treated privacy as a separate appendix. Rev 5 fully integrates privacy controls alongside security controls throughout the catalog, reflecting the reality that security and privacy risks are often intertwined.

Supply chain risk management. Rev 5 added a dedicated Supply Chain Risk Management (SR) control family, addressing risks introduced through vendors, components, and the broader supply chain, a growing concern given high-profile supply chain compromises in recent years.

Outcome-based control language. Controls were rewritten to be more outcome-focused and less tied to specific technologies, making the catalog more durable as technology changes.

Applicability beyond federal systems. Rev 5 was explicitly designed to be usable by any organization, not just federal agencies, reflecting NIST's recognition that the catalog was already being widely adopted in the private sector.

Control enhancements expansion. The total number of controls and control enhancements grew substantially, giving organizations more granular options for tailoring implementation to their specific risk profile.


The 20 Control Families

NIST SP 800-53 Rev 5 organizes its controls into 20 families, each identified by a two-letter prefix used in control IDs:

  • AC: Access Control
  • AT: Awareness and Training
  • AU: Audit and Accountability
  • CA: Assessment, Authorization, and Monitoring
  • CM: Configuration Management
  • CP: Contingency Planning
  • IA: Identification and Authentication
  • IR: Incident Response
  • MA: Maintenance
  • MP: Media Protection
  • PE: Physical and Environmental Protection
  • PL: Planning
  • PM: Program Management
  • PS: Personnel Security
  • PT: PII Processing and Transparency
  • RA: Risk Assessment
  • SA: System and Services Acquisition
  • SC: System and Communications Protection
  • SI: System and Information Integrity
  • SR: Supply Chain Risk Management

Each family contains a base set of controls plus optional control enhancements that add depth or specificity, referenced with a parenthetical number, for example AC-2(1).


Control Baselines: Low, Moderate, High

Not every system needs every control at full strength. NIST SP 800-53 works together with FIPS 199 impact levels to define three control baselines:

Low baseline: Applies to systems where a security breach would have limited adverse effect. Roughly 125 controls.

Moderate baseline: Applies to systems where a breach would have serious adverse effect. Roughly 325 controls. The majority of federal cloud systems, and the majority of FedRAMP authorizations, fall here.

High baseline: Applies to systems where a breach would have severe or catastrophic effect, such as loss of life or major financial impact. 420 or more controls.

An organization's baseline is determined by categorizing its system's data and mission impact, not by an arbitrary choice. Choosing the wrong baseline is one of the most common and most costly early mistakes in a compliance program.


How 800-53 Relates to FedRAMP

FedRAMP's Rev5 authorization path is built directly on NIST SP 800-53 Rev 5 control baselines. A cloud service pursuing FedRAMP authorization under Rev5 is, at its core, being assessed against the Low, Moderate, or High 800-53 baseline that matches its intended use case, with additional FedRAMP-specific parameters and requirements layered on top.

FedRAMP 20x, the newer authorization model, restructures how authorization works procedurally (moving toward Certification Classes and continuous automated validation) but the underlying control substance for most systems still traces back to the 800-53 catalog.


How 800-53 Relates to CMMC

CMMC Level 2 is built primarily on NIST SP 800-171, which itself is derived from a subset of NIST SP 800-53 Moderate baseline controls, tailored specifically for protecting Controlled Unclassified Information (CUI) in non-federal systems. CMMC Level 3 layers in additional enhanced requirements drawn from NIST SP 800-172, which adds controls beyond the standard 800-171 set to defend against advanced persistent threats.

Organizations that understand the 800-53 control family structure have an easier time understanding both 800-171 and 800-172, since the underlying control logic and numbering conventions carry through across all three publications.


Reading a Control: Structure and Enhancements

A typical 800-53 control follows a consistent structure:

  • Control identifier: A family prefix plus a number, such as AC-2
  • Control title: A short descriptive name, such as "Account Management"
  • Control statement: The specific requirement, written to be assessable
  • Discussion: Supplementary guidance explaining intent and context
  • Related controls: Cross-references to other controls that interact with this one
  • Control enhancements: Optional add-ons that increase the control's rigor, numbered in parentheses, such as AC-2(1) for automated account management

Understanding this structure matters because assessors evaluate implementation against the specific control statement and any applicable enhancements required by the system's baseline, not against a general impression of the control's intent.


How Organizations Manage 800-53 Compliance at Scale

For a Moderate baseline system with roughly 325 controls, and a High baseline system with 420 or more, manually tracking implementation status, evidence, and continuous monitoring data across every control quickly becomes unmanageable with spreadsheets alone. Organizations typically need:

  • Control mapping tooling that maps existing policies and technical configurations to specific 800-53 controls automatically
  • Evidence automation that pulls evidence directly from cloud environments and security tools rather than relying on manual screenshots and exports
  • Continuous monitoring that tracks control status on an ongoing basis rather than only at annual assessment time
  • Cross-framework mapping so work done to satisfy 800-53 also maps automatically to FedRAMP, FISMA, or CMMC requirements built on the same underlying controls

AI-powered, OSCAL-native platforms handle this at scale by treating the control catalog as structured data that can be queried, cross-referenced, and monitored programmatically instead of read manually document by document.


FAQ

Is NIST SP 800-53 only for the federal government?
No. While it was originally developed for federal information systems, Rev 5 was explicitly written to be usable by any organization, and it is widely adopted in the private sector, particularly by organizations that do business with the federal government or operate in regulated industries.

How many controls are in NIST SP 800-53 Rev 5?
The full catalog contains over 1,000 controls and control enhancements across all 20 families, though any individual system only needs to implement the subset defined by its applicable baseline (Low, Moderate, or High).

What is the difference between NIST SP 800-53 and NIST SP 800-171?
NIST SP 800-53 is the full federal control catalog. NIST SP 800-171 is a tailored subset of 800-53 Moderate baseline controls, specifically scoped for protecting Controlled Unclassified Information in non-federal systems, and it forms the technical basis for CMMC Level 2.

Is there a Revision 6 of NIST SP 800-53 planned?
NIST periodically updates 800-53 through both formal revisions and interim patches. Organizations should monitor NIST's official publication channels directly for the current status of any future revision, since compliance programs are typically built around whichever revision is currently in effect for their applicable framework.

Do I need to implement every control in my baseline exactly as written?
Organizations can tailor controls within the bounds their framework allows, including documenting compensating controls where a standard control cannot be implemented as written. Tailoring decisions and their justifications become part of the System Security Plan and are reviewed by assessors.


Quzara's NISTcompliance.ai automates control mapping, evidence collection, and continuous monitoring across all 20 NIST SP 800-53 Rev 5 control families, built on OSCAL-native architecture to support FedRAMP, FISMA, and CMMC programs simultaneously. Talk to a Quzara advisor to see how control mapping automation works for your environment.

Discover More Topics