NIST 800-53
NIST Special Publication 800-53 is the U.S. government's master catalog of security and privacy controls for information systems — the control library that sits behind FISMA and FedRAMP, and that countless private-sector security programs borrow from. If a federal contract, a cloud authorization, or an enterprise customer is pushing you toward "800-53 controls," here's the plain-language version: what it is, who needs it, how the catalog is organized, what the Low/Moderate/High baselines mean, and how to get ready.
NIST 800-53 checklist
A family-by-family implementation checklist.
Free readiness assessment
See your 800-53 gaps in minutes.
Map to other frameworks
How 800-53 lines up with NIST CSF 2.0, ISO 27001 & SOC 2.
Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.
What is NIST 800-53?
NIST 800-53 is a controls catalog, not a certification. It defines a large, carefully maintained library of security and privacy controls that organizations select from to protect their systems and the data they hold. It's produced by the U.S. National Institute of Standards and Technology and is the control backbone of the federal Risk Management Framework (RMF): agencies categorize a system's impact, select an appropriate baseline of 800-53 controls, implement them, assess them, and then authorize the system to operate. Because the catalog is comprehensive and public-domain, it's also widely used as a reference by private companies building a serious security program.
Who needs NIST 800-53?
It applies most directly to organizations in or adjacent to the U.S. federal space, but its reach is much wider. Teams typically engage with 800-53 when: - they operate federal information systems and must meet FISMA requirements; - they're a cloud service provider pursuing a FedRAMP authorization (FedRAMP baselines are built on 800-53); - a federal or enterprise customer contractually requires 800-53-aligned controls; - they want a thorough, authoritative control set to structure a private-sector security program, often alongside SOC 2 or ISO 27001.
How NIST 800-53 is structured
Revision 5 organizes controls into 20 families, each identified by a two-letter code. Every family groups related controls, and many controls have optional control enhancements that add rigor. The families are: Revision 5 made the controls outcome-based (written to be technology- and sector-neutral) and fully integrated privacy controls alongside security ones — which is why the PT (PII Processing and Transparency) family and privacy considerations run throughout.
Low, Moderate, and High baselines
Low — Systems where a breach would have limited adverse impact on operations, assets, or individuals. Moderate — Systems where a breach would have a serious adverse impact — the most common baseline for cloud/SaaS and FedRAMP Moderate. High — Systems where a breach would have a severe or catastrophic impact (e.g., critical or life-safety systems). You don't implement all 1,000+ controls. Instead you pick a baseline sized to your system's impact level, then tailor it. The baselines come from the companion publication SP 800-53B: There's also a dedicated privacy baseline for systems that process personally identifiable information. Standpoint's 800-53 content focuses on the controls most teams actually work through, so you can assess readiness without wading through the entire catalog at once. NIST publications are in the public domain. We summarize the catalog here; consult the official SP 800-53 Rev 5 and SP 800-53B for authoritative control text and baselines.
How NIST 800-53 relates to FISMA, FedRAMP & the RMF
FISMA is the law that requires federal agencies to secure their systems; 800-53 supplies the controls they use to do it; the Risk Management Framework (RMF, SP 800-37) is the process that ties it together — categorize, select, implement, assess, authorize, monitor. FedRAMP applies that same machinery to cloud services, with authorization baselines drawn directly from 800-53. So when a customer asks for "800-53 controls," they usually mean: show that you've selected an appropriate baseline, implemented the controls, and can evidence them.
NIST 800-53 vs. NIST CSF 2.0 vs. ISO 27001 vs. SOC 2
They work together. NIST CSF 2.0 is a higher-level framework of outcomes (Govern, Identify, Protect, Detect, Respond, Recover) — great for organizing a program; 800-53 is the detailed control catalog you implement underneath it. ISO 27001 is a certifiable management-system standard, and SOC 2 is an attestation against the AICPA Trust Services Criteria — both cover much of the same ground with heavy overlap. Because the controls map to each other, evidence you gather for one framework advances the others. See the NIST 800-53 crosswalk for the detail.
NIST 800-53 work counts elsewhere too
The crosswalk maps your NIST 800-53 evidence onto the frameworks it overlaps — so you move forward on several at once.