The NIST 800-53 control families are the organizing layer that makes a 1,000-page control catalog usable. There are twenty of them, each with a two-letter identifier, and once you know which family a requirement lives in you can find the control, the enhancements beneath it and the policy that ought to exist for it.
This guide lists all twenty as NIST names them, explains the difference between a base control and an enhancement, and covers the three families that behave differently from the rest.

All twenty NIST 800-53 control families
| ID | Family | ID | Family |
|---|---|---|---|
| AC | Access Control | PE | Physical and Environmental Protection |
| AT | Awareness and Training | PL | Planning |
| AU | Audit and Accountability | PM | Program Management |
| CA | Assessment, Authorization, and Monitoring | PS | Personnel Security |
| CM | Configuration Management | PT | PII Processing and Transparency |
| CP | Contingency Planning | RA | Risk Assessment |
| IA | Identification and Authentication | SA | System and Services Acquisition |
| IR | Incident Response | SC | System and Communications Protection |
| MA | Maintenance | SI | System and Information Integrity |
| MP | Media Protection | SR | Supply Chain Risk Management |
NIST 800-53 control families: base controls and enhancements
Each family holds base controls and control enhancements. NIST’s distinction is precise: enhancements either add functionality or specificity to a base control, or increase its strength. They are used where greater protection is needed than the base control provides, and they are selected because of potential adverse impact or because assurance requirements demand it.
Two practical consequences follow. First, an enhancement is never freestanding — implementing AC-2(1) without AC-2 is incoherent, and an assessor will treat it that way. Second, enhancements are where control sets quietly inflate: a baseline that pulls in enhancements nobody scoped is the usual reason a first implementation runs long.
The three families that are not like the others
Of the twenty NIST 800-53 control families, seventeen align with the minimum security requirements in FIPS 200. Three do not, because they address matters that emerged after FIPS 200 was written:
- PM — Program Management. Enterprise-level controls that belong to the security programme rather than to any single system. They are not selected per system in the way other families are, which is why they are so often missing entirely from a first control set.
- PT — PII Processing and Transparency. The privacy family. Its presence is why Revision 5 can serve as both a security and a privacy control catalog rather than treating privacy as an appendix.
- SR — Supply Chain Risk Management. Added because supply chain became a control problem in its own right, not a procurement footnote.
If your control matrix has no PM entries, the likely reason is that somebody scoped the exercise at system level and never asked who owns the organization-wide controls.
Using the NIST 800-53 control families to structure documentation
The most useful thing about the NIST 800-53 control families is that they map cleanly onto a policy set. Most organizations end up with one policy and one procedure per family — an access control policy covering AC, a configuration management policy covering CM, and so on — which gives you twenty documents rather than an argument about how to slice the catalog.
Three conventions make that work:
- Name the family in the document. A policy that states which family and which controls it addresses is auditable; one that describes good practice in general is not.
- Keep the -1 controls honest. Every family has a policy and procedures control at position 1, and it asks for a document that is reviewed and updated at a defined frequency. Those review dates are the cheapest finding an assessor can raise.
- Record inheritance per family. When a control is provided by a hosting environment or an enterprise service, say which family entries are inherited and from where — otherwise every assessment starts by re-deriving it.
Which controls in each family actually apply comes from the baseline, and that is a separate publication: SP 800-53B holds the low, moderate, high and privacy baselines. Our guide to NIST SP 800-53 and its baselines covers that side, and the NIST RMF is the process that decides which baseline you start from.
Frequently asked questions
How many NIST 800-53 control families are there?
Twenty in Revision 5, each with a two-letter identifier that prefixes every control in the family.
What is the difference between a control and an enhancement?
An enhancement adds functionality or specificity to a base control, or increases its strength. It is always attached to a base control rather than standing alone.
Which families are not in FIPS 200?
Program Management, PII Processing and Transparency, and Supply Chain Risk Management — the three added for enterprise-level programme management, privacy and supply chain considerations that emerged after FIPS 200.
Do we need a policy for every family?
Every family contains a policy and procedures control, so in practice yes for the families in your baseline. One document per family is the structure most organizations settle on.
Are the families the same in Revision 4?
No. Revision 5 consolidated security and privacy in one catalog and added families, so a Revision 4 mapping cannot be carried across without checking.
Where this leaves you
Treat the twenty NIST 800-53 control families as the skeleton of both your control matrix and your document set. Build one policy per family, keep the -1 policy-and-procedures control genuinely reviewed, record what you inherit, and check that Program Management has an owner — it is the family that belongs to nobody by default and is missing from most first attempts. Then let the baseline decide which controls inside each family you actually implement.
References
- NIST SP 800-53 Revision 5 — the control catalog, the family table and the definition of control enhancements.
- NIST SP 800-53B — the low, moderate, high and privacy control baselines.
More on NIST controls
- The NIST 800-53 control families — you are here
- NIST SP 800-53: the baselines and release 5.2.0
- The NIST RMF and its seven steps
- NIST SP 800-171 and CUI protection
Policies and procedures mapped family by family are in the NIST SP 800-53 Security Controls Toolkit, or start with the free ISO templates.