There are 1,014 active controls and enhancements in Revision 5, so no web assessment can work control by control. This one works at family level, anchored on the two or three controls in each family that carry the most weight, plus the scoping decisions that come before any of them.

This assessment scores 66 questions across all twenty control families, starting with the categorisation, baseline selection and organisation-defined parameter decisions that everything below them depends on. It is free, it saves as you go, and you can stop and come back to it.

What this is

The current release is Revision 5, Release 5.2.0, issued 27 August 2025. NIST moved off the five-yearly reissue model onto a versioned release model: major releases every two years, up to two minor releases a year. Release 5.2.0 added SA-15(13), SA-24 and SI-2(7) in response to Executive Order 14306, and broadened SI-7(12). SP 800-53B was reissued at the same version with no baseline changes, so those three new items are not in the Low, Moderate, High or Privacy baselines yet.

One citation trap worth knowing: the CSRC page at /pubs/sp/800/53/r5/final carries a withdrawn banner. That is the original September 2020 print. The live page is /r5/upd1/final. Rev 5 superseded itself when the December 2020 errata update replaced the first printing.

The background is elsewhere — the catalogue explained, the twenty families, tailoring, overlays, the assessment procedures, the privacy controls and Rev 5 against Rev 4. Come here when you want a score.

What it covers

66 questions, about 45 minutes.

SectionQuestions
Scoping, programme and planning7
People and physical6
Risk, assessment and authorisation7
Access and identity9
Configuration and maintenance6
Audit and integrity8
Protection, media and continuity10
Acquisition, supply chain, incident and privacy13

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicable—A justified exclusion, removed from the score

A control can be fully implemented and still be a gap if nobody has set the organisation-defined parameter it depends on. That is the quietest common failure in the whole catalogue, and it has a question of its own at the start.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list — as a PDF and a working Excel file.

How long does it take?

About 45 minutes. Access control, system and communications protection, system and services acquisition and system and information integrity carry the most weight — between them they are 480 of the 1,014 active controls and enhancements.

What to do with your score

Below 40% — settle the categorisation and the baseline first. Without them you have no yardstick, and a gap assessment against a catalogue you have not scoped to is a list of everything.

40–70% — the usual shape. The technical families score well and the programme management, supply chain and privacy families do not, because they are organisation-level and usually owned by nobody in particular.

Above 70% — look at the parameter values. Set, recorded and reviewed is a different answer from set once at build and never revisited, and an assessor reads the review date.

Frequently asked questions

Is this assessment really free?

Yes. All 66 questions, the breakdown by family and your overall score cost nothing. The $39 report is optional.

Why family level rather than control by control?

Because 1,014 controls is a consulting engagement, not a web form. Family level plus the highest-weight controls gets you a defensible picture in under an hour, and tells you which families need the full control-by-control treatment.

Where do PM and PT fit?

Both appear only in the Privacy baseline, never in Low, Moderate or High. Programme management controls are organisation-level, assessed once and inherited, which is exactly the level this assessment works at.

Is Revision 6 coming?

Nothing has been announced. As at September 2026 the current release is still 5.2.0, and NIST publishes no forward timeline beyond its stated release cadence.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.