Beyond SOC 2
What is NIST 800-53?
What is NIST 800-53?
NIST SP 800-53 is a catalogue of security and privacy controls for information systems, published by the US National Institute of Standards and Technology. Revision 5 organises roughly 1,000 controls and enhancements into 20 families, and companion baselines select which apply at low, moderate, and high impact levels. It is mandatory for federal systems under FISMA and voluntary everywhere else, where it is most valuable as a crosswalk hub.
The 20 control families
| Code | Family | Code | Family |
|---|---|---|---|
| AC | Access Control | PE | Physical and Environmental Protection |
| AT | Awareness and Training | PL | Planning |
| AU | Audit and Accountability | PM | Program Management |
| CA | Assessment, Authorization, Monitoring | PS | Personnel Security |
| CM | Configuration Management | PT | PII Processing and Transparency |
| CP | Contingency Planning | RA | Risk Assessment |
| IA | Identification and Authentication | SA | System and Services Acquisition |
| IR | Incident Response | SC | System and Communications Protection |
| MA | Maintenance | SI | System and Information Integrity |
| MP | Media Protection | SR | Supply Chain Risk Management |
Revision 5 added the PT privacy family and the SR supply chain family, and made the controls outcome-based rather than written specifically for federal systems, which is what made commercial adoption practical.
You do not implement all thousand
The catalogue is deliberately exhaustive. SP 800-53B defines baselines that select a subset by impact level, and a tailoring process narrows further based on your system. A moderate baseline is a few hundred controls, not a thousand.
Why commercial teams care: the crosswalk
This is the reason 800-53 matters to a company with no federal customers. It is the most complete control catalogue in wide use, so other frameworks map onto it rather than onto each other. Map a control to 800-53 once and you inherit its relationships to SOC 2 Common Criteria, ISO 27001 Annex A, and the HIPAA Security Rule.
That turns the second framework into a fraction of the work of the first. One access-control test, evidenced once, satisfies SOC 2 CC6, ISO 27001 A.5.15, and the HIPAA access management standard at the same time.
Screenata uses NIST 800-53 as exactly this hub, which is why an additional framework is 70% of the base rate for your company size rather than full price. The evidence crosswalks; it is not collected twice.
Where 800-53 is actually mandatory
- Federal information systems, under FISMA
- FedRAMP, which builds its baselines from 800-53
- Contractors by flow-down, though CUI obligations usually arrive as NIST SP 800-171 instead
For everyone else it is a reference, not a requirement. There is no such thing as being "NIST 800-53 certified"; there is no certification scheme.