Framework · Last verified

Security and Privacy Controls for Information Systems and Organizations

NIST SP 800-53 is a catalog of security and privacy controls; FIPS 200 requires U.S. federal agencies to meet minimum requirements using it. Revision 5 was published in September 2020 and Release 5.2.0 was issued on 27 August 2025; FIPS 200 directs agencies to its low, moderate and high control baselines.

Class
Framework
Owner
National Institute of Standards and Technology (NIST), U.S. Department of Commerce
Last verified

What it is

NIST SP 800-53 is a control catalog, not a certification. Its abstract states that the publication "provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks," and that "The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk."

Revision 5's publication record reads "Date Published: September 2020 (includes updates as of Dec. 10, 2020)". NIST notes on the same page that "On August 27, 2025, NIST issued a minor release of SP 800-53 (Release 5.2.0)"; NIST's announcement describes that release as focusing "on improving the security and reliability of software updates and patches in response to [Executive Order 14306] on strengthening the Nation's cybersecurity."

Who owns it

SP 800-53 is published by the National Institute of Standards and Technology (NIST), an agency of the U.S. Department of Commerce.

Control baselines (as required by FIPS 200)

  • Low baseline — For low-impact information systems, organizations must, as a minimum, employ appropriately tailored security controls from the low baseline of security controls defined in NIST Special Publication 800-53 and must ensure that the minimum assurance requirements associated with the low baseline are satisfied. (FIPS PUB 200 §4)
  • Moderate baseline — For moderate-impact information systems, organizations must, as a minimum, employ appropriately tailored security controls from the moderate baseline of security controls defined in NIST Special Publication 800-53 and must ensure that the minimum assurance requirements associated with the moderate baseline are satisfied. (FIPS PUB 200 §4)
  • High baseline — For high-impact information systems, organizations must, as a minimum, employ appropriately tailored security controls from the high baseline of security controls defined in NIST Special Publication 800-53 and must ensure that the minimum assurance requirements associated with the high baseline are satisfied. (FIPS PUB 200 §4)

Who asks for it

Statutory (scoped). Statutory in one defined scope: U.S. federal agencies under FIPS 200, which requires them to meet its minimum security requirements through the controls in NIST SP 800-53. National security systems are outside FIPS 200's scope. Outside U.S. federal information systems this record documents no verified legal obligation.

In the United States the catalog carries statutory weight through FIPS 200, Minimum Security Requirements for Federal Information and Information Systems (9 March 2006), which states: "Federal agencies must meet the minimum security requirements as defined herein through the use of the security controls in accordance with NIST Special Publication 800-53 … as amended." (FIPS 200 refers to the publication under its earlier title, Recommended Security Controls for Federal Information Systems.) FIPS 200 applies to "all federal information systems other than those information systems designated as national security systems as defined in 44 United States Code Section 3542(b)(2)", and it records that "No provision is provided under FISMA for waivers to FIPS made mandatory by the Secretary of Commerce." Outside U.S. federal information systems, no obligation was identified in the sources reviewed as of 29 August 2026 — confirm against the relevant regulator or contracting authority.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Security and Privacy Controls for Information Systems and Organizations." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/nist-800-53

All frameworks & audits →