Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST 800-53 Rev 5 vs Rev 4 explained

NIST 800-53 Rev 5 vs Rev 4: The 7 Clear Changes (2026)

NIST 800-53 Rev 5 vs Rev 4 still matters in 2026 because the two revisions are both alive in the regimes built on the catalogue: Revision 5 has been the current publication since September 2020 and Revision 4 was withdrawn on 23 September 2021, yet NIST SP 800-171 Revision 2 — the version CMMC assesses against — was derived from the Rev 4 moderate baseline, FedRAMP only completed its move to Rev 5 baselines in 2023–2024, and thousands of system security plans still carry Rev 4 control text.

Rev 5 changed the catalogue in seven ways NIST lists in its own preface: outcome-based control statements with the responsible entity removed; security and privacy integrated in one catalogue; a new Supply Chain Risk Management family; control selection separated from the controls; baselines and tailoring moved out to SP 800-53B; the relationship between requirements and controls clarified; and new state-of-the-practice controls for resiliency, secure design and governance. This guide sets the two revisions side by side, lists what was added, withdrawn and renamed, explains what the change means for a system security plan, and gives a migration path for a control set still written to Rev 4.

NIST 800-53 Rev 5 vs Rev 4: the seven changes
Outcome-based statements · security + privacy in one catalogue · new SR family (and PT) · selection separated from controls · baselines moved to 800-53B · requirements vs controls clarified · new resiliency, design and governance controls · Rev 4 withdrawn 23 Sept 2021; Rev 5 maintained by release (5.1.1, 5.2.0).

NIST 800-53 Rev 5 vs Rev 4 at a glance

SP 800-53 Rev 4 SP 800-53 Rev 5
Published April 2013, updated January 2015 September 2020, updated 10 December 2020; Release 5.1.1 (2023) and Release 5.2.0 (27 August 2025)
Status Withdrawn 23 September 2021 Current
Families 18 (privacy in Appendix J, not a family) 20 — PT and SR added
Control statement form “The organization…” / “The information system…” Outcome-based; no entity named
Baselines Inside the publication, Appendix D SP 800-53B: low, moderate, high and a privacy baseline
Tailoring guidance Inside the publication SP 800-53B
Privacy Appendix J privacy controls, separate from security Integrated: PT family plus privacy attributes across families; privacy baseline
Supply chain SA-12 and enhancements SR family, SR-1 to SR-12, plus SA controls
Assessment companion SP 800-53A Rev 4 (December 2014) SP 800-53A Rev 5 (January 2022)
Machine-readable Spreadsheet OSCAL and spreadsheet

Our guide to NIST SP 800-53 covers what Release 5.2.0 changed inside Rev 5.

NIST 800-53 Rev 5 vs Rev 4: the seven changes in practice

Change (NIST’s list) What it means for a control set
1. Outcome-based statements Controls no longer say who does what; the SSP must state whether the organisation, the system, a provider or a hybrid implements each — the responsibility column is now yours to write
2. Security and privacy in one catalogue Privacy is no longer an appendix a security team can skip; controls carry privacy attributes and the PT family applies wherever PII is processed
3. New SR family Twelve supply chain controls (SR-1 to SR-12): policy, the supply chain risk management plan, controls and processes, provenance, acquisition strategies, supplier assessments, operations security, notification agreements, tamper resistance, inspection, component authenticity, component disposal — absorbing the Rev 4 SA-12 cluster
4. Selection separated from controls The catalogue no longer tells you which controls apply; 800-53B does. A Rev 5 control set has to cite its baseline source
5. Baselines and tailoring moved to 800-53B The moderate baseline, tailoring actions and overlay guidance are in a different document with its own release history
6. Requirements vs controls clarified A requirement is what a law or policy demands; a control is a safeguard that satisfies it. The SSP traces controls to requirements rather than treating the catalogue as the requirement
7. New controls Cyber resiliency, secure system design and governance controls — for example in SA, SC, SI and PM — and the PT family; plus Rev 5’s practice of withdrawing controls into others rather than renumbering

NIST 800-53 Rev 5 vs Rev 4: what was added, withdrawn and renamed

Category Rev 5 treatment Examples
New families PT (PII Processing and Transparency, 8 controls) and SR (Supply Chain Risk Management, 12 controls) PT-2 Authority to Process PII, PT-4 Consent; SR-3 Supply Chain Controls and Processes, SR-11 Component Authenticity
Withdrawn controls and enhancements Kept in the catalogue marked “[Withdrawn: Incorporated into …]” so numbering is stable An AC-2 enhancement incorporated into AC-2k; another AC item into MP-4 and SC-28; SA-12 and its enhancements into the SR family
Renamed families CA became Assessment, Authorization, and Monitoring; PT and SR named CA was Security Assessment and Authorization in Rev 4
Privacy appendix Appendix J controls redistributed into PT and privacy-relevant controls elsewhere (e.g. PM-18 to PM-27 series, RA-8, SI-18, SI-19) AP, AR, DI, DM, IP, SE, TR, UL families of Appendix J no longer exist
Parameters More organization-defined parameters, and 800-53A Rev 5 tests them on their own determination statements Frequencies, lists of roles, retention periods

Our guide to the NIST 800-53 control families lists all twenty as Rev 5 names them.

Where each revision still applies in 2026

Regime Revision in effect Note
FISMA agency systems Rev 5 via 800-53B baselines OMB expects current NIST publications; Rev 4 SSPs are legacy
FedRAMP Rev 5 baselines Transition from Rev 4 ran 2023–2024; new authorisations are Rev 5
NIST SP 800-171 Rev 2 / CMMC Derived from Rev 4 moderate CMMC assesses 800-171 Rev 2; 800-171 Rev 3 (May 2024) is derived from Rev 5 but DoD has not adopted it for CMMC
StateRAMP Rev 5 baselines Aligned to FedRAMP
CNSS national security systems CNSSI 1253 on Rev 5 With CNSS overlays
Private-sector adopters Whichever their contracts cite Most have moved; mapping tools such as NIST’s OLIR are Rev 5

Our guide to NIST 800-171 vs 800-53 explains why the CMMC world is frozen at the Rev 4-derived 800-171 Rev 2 even while the catalogue has moved on — the NIST 800-53 Rev 5 vs Rev 4 question is settled for the catalogue and unsettled for its derivatives.

Migrating a control set from Rev 4 to Rev 5

A NIST 800-53 Rev 5 vs Rev 4 migration has seven moves.

  1. Get the mapping, not the diff. NIST published a Rev 4-to-Rev 5 comparison workbook; use it to map every control in the current SSP to its Rev 5 identifier, its withdrawn-into target, or its new home in PT or SR.
  2. Re-select from 800-53B. The moderate baseline is not the same set of controls it was in Rev 4 Appendix D; re-derive the baseline and re-run the tailoring record. Our guide to NIST 800-53 tailoring covers the five actions.
  3. Rewrite the responsibility column. Outcome-based statements need an explicit implementation owner per control — organisation, system, provider, hybrid.
  4. Add the SR and PT families. Supply chain is a full family now; PT applies if the system processes PII, and the privacy baseline applies regardless of impact level.
  5. Assign the new parameters. Every organization-defined value Rev 5 added is a determination statement in 800-53A Rev 5.
  6. Update to the current release. Migrate to Release 5.2.0, not to Rev 5 as published in 2020; record the release in the SSP.
  7. Re-plan the assessment. 800-53A Rev 5 procedures, with depth and coverage set for the new controls.

Frequently asked questions

What changed between NIST 800-53 Rev 4 and Rev 5?
NIST’s own list: outcome-based control statements; security and privacy integrated in one catalogue; a new Supply Chain Risk Management family; control selection separated from the controls; baselines and tailoring moved to SP 800-53B; the requirements-versus-controls relationship clarified; and new controls for resiliency, secure design and governance. Rev 5 also added the PT privacy family, taking the family count from 18 to 20.

Is Rev 4 still valid?
It was withdrawn on 23 September 2021. It survives indirectly because NIST SP 800-171 Rev 2, which CMMC assesses, was derived from the Rev 4 moderate baseline.

Did Rev 5 renumber the controls?
No. Withdrawn controls are kept in the catalogue marked as incorporated into another control, so identifiers are stable; new controls were appended and two new families were added.

Where did the Rev 4 privacy appendix go?
Appendix J’s privacy controls were integrated into Rev 5 — the PT family and privacy-relevant controls in PM, RA, SI and elsewhere — and 800-53B added a privacy baseline that applies regardless of impact level.

Is Rev 5 finished?
It is maintained by release rather than by revision: Release 5.1.1 and, from 27 August 2025, Release 5.2.0, which added SA-15(13), SA-24 and SI-02(07). Record the release, not just the revision.

Where this leaves you

Treat NIST 800-53 Rev 5 vs Rev 4 as a migration with seven known moves: map every control, re-select the baseline from 800-53B, write the responsibility column the outcome-based statements now require, add the SR and PT families, assign the new parameters, land on Release 5.2.0 and re-plan the assessment under 800-53A Rev 5 — while remembering that a CMMC programme stays on the Rev 4-derived 800-171 Rev 2 until DoD says otherwise.

References

More on NIST 800-53

The Rev 4-to-Rev 5 migration workbook, the family-by-family policy set including SR and PT, the control implementation matrix with responsibility and parameter columns and the tailoring record are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.