Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST SP 800-53 security and privacy controls catalog

NIST SP 800-53: The Baselines, and Release 5.2.0

NIST SP 800-53 is the control catalog nearly every US federal security regime is built on — and saying “we’re on Rev 5” no longer tells anyone which controls you mean.

Revision 5 has not become Revision 6. Instead it now receives patch releases, in the way software does, and the most recent one added controls. If your control set was baselined before August 2025, it is missing some.

What NIST SP 800-53 actually is

Security and Privacy Controls for Information Systems and Organizations is a catalog, not a standard you comply with. It provides controls to protect operations, assets, individuals, other organisations and the nation from a wide range of threats — hostile attacks, human error, natural disasters, structural failures, foreign intelligence entities and privacy risks.

Three design decisions distinguish it from most control sets.

Security and privacy live in one catalog. Revision 5 consolidated them rather than treating privacy as an appendix — which is why the same document underpins both security programmes and privacy programmes in federal agencies.

It is deliberately not federal-only in its language. The controls are written as outcomes for any information system, which is why private-sector organisations with no federal obligation adopt it.

It addresses functionality and assurance separately — the strength of the mechanism, and the confidence you have in it. Those are different questions and most frameworks conflate them.

The parts of NIST SP 800-53 you actually need

The parts of NIST SP 800-53 and its patch releases

The single most common mistake is treating the NIST SP 800-53 catalog as the whole publication. It is not, and the other parts are where the work happens.

SP 800-53B holds the control baselines — low, moderate, high and privacy. The catalog tells you what a control is; 800-53B tells you which controls apply at your impact level. An organisation that has read the catalog but not the baselines has no basis for selecting anything.

SP 800-53A Rev. 5 holds the assessment procedures. This is what an assessor works from, so it is also the best guide to what evidence you will be asked for.

Two supporting resources are worth knowing about because they save real time. Rev. 5 controls are published in OSCAL, machine-readable, so a GRC platform can ingest them rather than have someone retype them. And NIST publishes an OLIR mapping from SP 800-53 Rev. 5 to ISO/IEC 27001:2022 — which is the fastest honest answer to “we already have ISO 27001, what else do we need?”

Release 5.2.0, and why patch releases matter

On 27 August 2025 NIST issued a minor release of NIST SP 800-53, Release 5.2.0. It was not a cosmetic update:

  • New controls and enhancements: SA-15(13), SA-24, SI-02(07).
  • Revised: SI-07(12).
  • Updated discussion: SA-04, SA-05, SA-08, SA-08(14), SI-02, SI-02(05).
  • Updated related controls: every -01 control, plus AU-02, AU-03, CA-07, IR-04, IR-06, IR-08, SA-15, SI-02 and SI-07.

The weight of this NIST SP 800-53 update sits in the SA (system and services acquisition) and SI (system and information integrity) families — supply chain and software integrity, which is where federal attention has been concentrated.

The practical consequence: record the release you baselined against, not just the revision. “Rev 5” was a sufficient answer in 2021. It is not now, and an assessor comparing your control set against the current catalog will find gaps you did not know you had.

Where NIST SP 800-53 shows up

Regime How it uses the catalog
FedRAMP Built directly on the baselines, selected by impact level. If you are pursuing federal cloud authorisation, this catalog is the substance of it
GovRAMP Built on Rev. 5, with Core Verification using 60 prioritised controls aligned to the Moderate baseline
SP 800-171 A different publication for a different job — protecting CUI in nonfederal systems, derived from but not equal to the 800-53 catalog
ISO 27001 NIST publishes an OLIR mapping between Rev. 5 and the 2022 edition. Substantial overlap, but ISO 27001 certifies a management system and 800-53 does not certify anything

That last distinction is the one to hold onto. Nobody certifies you to SP 800-53. You are authorised, assessed or contracted against a baseline drawn from it. The catalog is an input to those processes, never the output.

Where NIST SP 800-53 implementations go wrong

  • Implementing the catalog instead of a baseline. There are over a thousand controls and enhancements; nobody applies them all. Select from 800-53B.
  • Ignoring tailoring. The controls are explicitly flexible and customisable. Tailoring decisions have to be recorded, with reasons, or they read as omissions.
  • Treating privacy controls as optional. They are in the same catalog for a reason.
  • Baselining once. Patch releases mean the catalog moves under you.
  • Retyping controls. The OSCAL version exists precisely so you do not have to.

Where to start with NIST SP 800-53

  1. Fix your impact level first — low, moderate or high — because the baseline follows from it.
  2. Take the baseline from SP 800-53B, not the catalog.
  3. Read SP 800-53A for the control you are implementing, so you build the evidence the assessor will ask for.
  4. Record the release, e.g. Rev. 5 Release 5.2.0, in your system security plan.
  5. Ingest the OSCAL files rather than rekeying.
  6. Use the OLIR mapping if you hold ISO 27001, to find the genuine delta rather than starting again.

This guide reflects csrc.nist.gov at 15 August 2026, on which SP 800-53 Rev. 5 with Release 5.2.0 is current. Check the planning notes before baselining — that is where NIST announces patch releases.

The NIST SP 800-53 Security Controls Toolkit provides editable templates covering the system security plan, the control implementation and tailoring records, the assessment evidence and the continuous monitoring artefacts.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.