NIST 800-53 tailoring is the step that turns a catalogue of over a thousand controls into a control set an organization can actually implement. You start from a baseline, then justify every change you make to it — and the justification, not the change, is what an assessor reads.
This guide covers where baselines come from, the five tailoring actions, how overlays work, and the documentation that makes a tailored set defensible.

Where the baseline comes from
The control catalogue lives in SP 800-53. The baselines live in SP 800-53B: three security baselines for low, moderate and high impact systems, plus a privacy baseline applied regardless of impact level. Which security baseline applies is decided by the impact level from your FIPS 199 categorisation — the highest of confidentiality, integrity and availability.
The baseline is where NIST 800-53 tailoring starts and explicitly not where it ends. SP 800-53B ships tailoring guidance alongside the baselines precisely because no baseline fits a real system as issued.
The five NIST 800-53 tailoring actions
| Action | What it does | What has to be recorded |
|---|---|---|
| Identify common controls | Inherit controls provided by another system or provider | Who provides it, and what remains your responsibility |
| Apply scoping considerations | Remove or narrow controls that do not apply to the system | Why the technology, mission or environment makes it inapplicable |
| Select compensating controls | Substitute where a baseline control cannot be implemented | The equivalent protection provided, and the residual risk accepted |
| Assign parameter values | Fill in the organization-defined values the controls leave open | The value, and where the number came from |
| Supplement the baseline | Add controls or enhancements the risk assessment demands | The risk that justified the addition |
Of the five NIST 800-53 tailoring actions, the fourth is the quiet one. Controls are written with organization-defined parameters — how often, how long, how many — and an unassigned parameter is an unimplemented control. Filling them in with the smallest defensible number, consistently, is most of what makes a control set testable.
Removing a control is the action that needs the most evidence
Scoping out is legitimate and frequently abused. “Not applicable” has to rest on something structural — the technology is not present, the function does not exist in this system, the control is provided elsewhere — and not on the fact that implementing it would be inconvenient. If the reason you cannot implement it is cost or capability, that is a compensating control or a plan of action, not a scoping decision. Our guide to the plan of action and milestones covers the second route.
Overlays: tailoring somebody else has already done
An overlay is a fully specified set of NIST 800-53 tailoring decisions for a community of interest, a technology or an environment — federal PKI, industrial control systems, privacy, classified systems. Adopting one saves the analysis and, more usefully, aligns you with peers and with the assessors who read those systems every day. NIST maintains a public repository for sharing them.
The live area here is artificial intelligence: NIST’s Control Overlays for Securing AI Systems project is developing overlays that apply the 800-53 catalogue to AI use cases, with material published for comment through 2025 and 2026. If you are securing an AI system today, that work is worth tracking rather than inventing your own tailoring from scratch.
Where NIST 800-53 tailoring goes wrong
The baseline is treated as the deliverable. Implementing a moderate baseline unchanged is not tailoring; it is avoiding a decision, and it produces controls that do not fit alongside controls that were needed and never added.
Parameters left at the example value. Copying a template’s numbers means you are testing against somebody else’s policy, and the mismatch surfaces the first time an assessor compares your parameter to your actual configuration.
Inheritance claimed without a boundary. Inheriting cloud provider controls is normal and correct — claiming inheritance without a shared responsibility analysis is how systems fail assessment. Our guide to the shared responsibility matrix covers the split.
No record of the reasoning. A tailored control set with no rationale column cannot be defended, reviewed, or inherited by whoever holds the system next.
Frequently asked questions
What is NIST 800-53 tailoring?
The process of adjusting a control baseline to a specific system — identifying common controls, scoping, applying compensating controls, assigning parameter values and supplementing — with the reasoning documented.
Where are the baselines published?
In SP 800-53B, separately from the control catalogue in SP 800-53. That split is deliberate: the catalogue is the superset, the baselines are one way of selecting from it.
Can we remove controls from a baseline?
Yes, with justification, through scoping considerations. The justification has to be structural rather than practical, and it is recorded in the system security plan.
What is an overlay?
A pre-built, fully specified set of tailoring decisions for a community, technology or environment — usable as-is or as a starting point, and shareable through NIST’s overlay repository.
Does FedRAMP allow NIST 800-53 tailoring?
FedRAMP baselines are themselves tailored from 800-53, and providers work within them rather than re-tailoring freely. The parameter assignments in particular are largely fixed for you.
Where this leaves you
Categorise honestly, take the matching baseline from SP 800-53B, then tailor with a written reason against every change. Assign every organization-defined parameter yourself, keep scoping decisions structural, and treat inheritance as something you prove with a responsibility split rather than assert. Look for an existing overlay before building your own — and if you are securing AI systems, watch NIST’s overlay work rather than inventing a control set nobody else will recognise.
References
- NIST SP 800-53B — control baselines and the tailoring guidance.
- NIST — Control Overlays for Securing AI Systems — the overlay project for AI use cases.
More on NIST controls
- NIST 800-53 tailoring — you are here
- NIST SP 800-53 and its baselines
- All 20 control families
- The NIST RMF in seven steps
Control selection worksheets, parameter registers and the system security plan are in the NIST SP 800-53 Security Controls Toolkit, or start with the free ISO templates.