Screenata

Beyond SOC 2

What is NIST 800-53?

August 18, 20262 min read

What is NIST 800-53?

NIST SP 800-53 is a catalogue of security and privacy controls for information systems, published by the US National Institute of Standards and Technology. Revision 5 organises roughly 1,000 controls and enhancements into 20 families, and companion baselines select which apply at low, moderate, and high impact levels. It is mandatory for federal systems under FISMA and voluntary everywhere else, where it is most valuable as a crosswalk hub.

The 20 control families

CodeFamilyCodeFamily
ACAccess ControlPEPhysical and Environmental Protection
ATAwareness and TrainingPLPlanning
AUAudit and AccountabilityPMProgram Management
CAAssessment, Authorization, MonitoringPSPersonnel Security
CMConfiguration ManagementPTPII Processing and Transparency
CPContingency PlanningRARisk Assessment
IAIdentification and AuthenticationSASystem and Services Acquisition
IRIncident ResponseSCSystem and Communications Protection
MAMaintenanceSISystem and Information Integrity
MPMedia ProtectionSRSupply Chain Risk Management

Revision 5 added the PT privacy family and the SR supply chain family, and made the controls outcome-based rather than written specifically for federal systems, which is what made commercial adoption practical.

You do not implement all thousand

The catalogue is deliberately exhaustive. SP 800-53B defines baselines that select a subset by impact level, and a tailoring process narrows further based on your system. A moderate baseline is a few hundred controls, not a thousand.

Why commercial teams care: the crosswalk

This is the reason 800-53 matters to a company with no federal customers. It is the most complete control catalogue in wide use, so other frameworks map onto it rather than onto each other. Map a control to 800-53 once and you inherit its relationships to SOC 2 Common Criteria, ISO 27001 Annex A, and the HIPAA Security Rule.

That turns the second framework into a fraction of the work of the first. One access-control test, evidenced once, satisfies SOC 2 CC6, ISO 27001 A.5.15, and the HIPAA access management standard at the same time.

Screenata uses NIST 800-53 as exactly this hub, which is why an additional framework is 70% of the base rate for your company size rather than full price. The evidence crosswalks; it is not collected twice.

Where 800-53 is actually mandatory

  • Federal information systems, under FISMA
  • FedRAMP, which builds its baselines from 800-53
  • Contractors by flow-down, though CUI obligations usually arrive as NIST SP 800-171 instead

For everyone else it is a reference, not a requirement. There is no such thing as being "NIST 800-53 certified"; there is no certification scheme.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.