<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is NIST 800-53?"
title: "What Is NIST 800-53"
seoTitle: "What Is NIST 800-53? Controls, Families, Baselines"
summary: "NIST SP 800-53 is a catalogue of security and privacy controls for information systems, published by the US National Institute of Standards and Technology. Revision 5 organises roughly 1,000 controls into 20 families and defines low, moderate, and high baselines. It is mandatory for US federal systems and voluntary elsewhere, where it is most often used as the crosswalk hub that maps SOC 2, ISO 27001, and HIPAA onto a single control set."
publishedAt: "2026-08-18"
keywords:
  - "NIST 800-53"
  - "NIST 800 53"
  - "what is NIST 800 53"
  - "NIST SP 800-53 controls"
  - "NIST 800-53 control families"
pillar: "Beyond SOC 2"
faqs:
  - question: "What is NIST 800-53 used for?"
    answer: "It is the control catalogue for US federal information systems under FISMA, and the basis for FedRAMP. Outside government it is used voluntarily as a comprehensive reference and, most usefully for commercial teams, as a crosswalk hub: map your controls to 800-53 once and the mappings to SOC 2, ISO 27001, and HIPAA follow."
  - question: "How many controls are in NIST 800-53?"
    answer: "Revision 5 contains roughly 1,000 controls and control enhancements across 20 families. You are never expected to implement all of them. The baselines in SP 800-53B select a subset for low, moderate, or high impact systems, and a tailoring process narrows it further."
  - question: "What is the difference between NIST 800-53 and 800-171?"
    answer: "800-53 is the full catalogue for federal systems. 800-171 is a 110-requirement subset for protecting Controlled Unclassified Information on nonfederal systems, derived from the 800-53 moderate baseline. If you are a contractor handling CUI, 800-171 is your obligation, not 800-53."
---

## What is NIST 800-53?

NIST SP 800-53 is a **catalogue of security and privacy controls** for information systems, published by the US National Institute of Standards and Technology. Revision 5 organises roughly 1,000 controls and enhancements into **20 families**, and companion baselines select which apply at low, moderate, and high impact levels. It is mandatory for federal systems under FISMA and voluntary everywhere else, where it is most valuable as a crosswalk hub.

### The 20 control families

| Code | Family | Code | Family |
|---|---|---|---|
| AC | Access Control | PE | Physical and Environmental Protection |
| AT | Awareness and Training | PL | Planning |
| AU | Audit and Accountability | PM | Program Management |
| CA | Assessment, Authorization, Monitoring | PS | Personnel Security |
| CM | Configuration Management | PT | PII Processing and Transparency |
| CP | Contingency Planning | RA | Risk Assessment |
| IA | Identification and Authentication | SA | System and Services Acquisition |
| IR | Incident Response | SC | System and Communications Protection |
| MA | Maintenance | SI | System and Information Integrity |
| MP | Media Protection | SR | Supply Chain Risk Management |

Revision 5 added the PT privacy family and the SR supply chain family, and made the controls outcome-based rather than written specifically for federal systems, which is what made commercial adoption practical.

## You do not implement all thousand

The catalogue is deliberately exhaustive. **SP 800-53B** defines baselines that select a subset by impact level, and a tailoring process narrows further based on your system. A moderate baseline is a few hundred controls, not a thousand.

## Why commercial teams care: the crosswalk

This is the reason 800-53 matters to a company with no federal customers. It is the most complete control catalogue in wide use, so **other frameworks map onto it** rather than onto each other. Map a control to 800-53 once and you inherit its relationships to SOC 2 Common Criteria, ISO 27001 Annex A, and the HIPAA Security Rule.

That turns the second framework into a fraction of the work of the first. One access-control test, evidenced once, satisfies SOC 2 CC6, ISO 27001 A.5.15, and the HIPAA access management standard at the same time.

Screenata uses NIST 800-53 as exactly this hub, which is why an additional framework is **70% of the base rate for your company size** rather than full price. The evidence crosswalks; it is not collected twice.

## Where 800-53 is actually mandatory

- **Federal information systems**, under FISMA
- **FedRAMP**, which builds its baselines from 800-53
- **Contractors** by flow-down, though CUI obligations usually arrive as [NIST SP 800-171](/resources/answers/what-is-nist-sp-800-171) instead

For everyone else it is a reference, not a requirement. There is no such thing as being "NIST 800-53 certified"; there is no certification scheme.
