NIST 800-53 overlays are the mechanism that lets a whole community reuse one set of tailoring decisions instead of every system owner making them alone. SP 800-53B defines an overlay as a specification of controls, control enhancements, supplemental guidance and other supporting information — parameter values above all — employed during tailoring to complement and refine a baseline; it may be more or less stringent than the baseline it refines, and it applies to multiple systems.
Appendix C of 800-53B lists seven categories overlays are built for, from communities of interest and technologies to environments, system types, missions, threats and statutes, and gives an eight-section outline for writing one. Published overlays include the industrial control system overlay in SP 800-82, the CNSS overlays for national security systems, and the AI-system overlays NIST is developing under the COSAiS project from 2025. This guide explains what an overlay is and is not, the seven categories, how an overlay differs from tailoring and from a baseline, which published overlays matter, how to adopt one and how to write one for your own community.

What an overlay is, and is not
| Baseline | Overlay | Tailoring | |
|---|---|---|---|
| What it is | The starting control set for an impact level: low, moderate, high, plus the privacy baseline | A reusable set of tailoring decisions for a community, technology, environment or circumstance | The adaptation of a baseline (with or without an overlay) to one system |
| Who produces it | NIST, in SP 800-53B | A community of interest, sector body, agency, CNSS, NIST | The system owner |
| Applies to | All federal systems at that impact level | Multiple systems sharing the characteristic the overlay addresses | One system |
| Can add or remove controls | n/a | Yes — more or less stringent than the baseline | Yes, with recorded justification |
| Sets parameter values | Some, as minimums | Yes, values the community agrees on | Yes, the final values |
NIST 800-53 overlays are not for an individual system — that is what tailoring is for. An overlay exists because a group of systems diverge from the baseline’s assumptions in the same way, and it is cheaper and more consistent for the group to decide once. Our guide to NIST 800-53 tailoring covers the five tailoring actions an overlay packages.
The seven categories of NIST 800-53 overlays
| Category (800-53B Appendix C) | NIST’s examples | What the overlay typically changes |
|---|---|---|
| Communities of interest, industry sectors, coalitions or partnerships | Healthcare, law enforcement, intelligence, finance, manufacturing, transportation, energy, allied collaboration | Statutory controls added, sector parameter values, shared interpretations |
| Information technologies and computing paradigms | Virtualised systems, cloud, mobile, smart grid, cross-domain solutions | Controls interpreted for the technology; inapplicable controls removed |
| Environments of operation | Space, tactical, sea | Physical and contingency controls adapted to the environment |
| Types of systems and operating modes | Industrial or process control systems, weapons systems, single-user and stand-alone systems, IoT devices and sensors | Controls that assume general-purpose IT scoped or replaced with compensating measures |
| Types of missions or operations | Counterterrorism, first responders, research, development, test and evaluation | Availability and integrity emphasis; operational tempo reflected in parameters |
| Types of threats | Advanced persistent threats, insider threats | Enhancements added for detection, segregation and monitoring |
| Statutory or regulatory requirements | FISA, HIPAA, FISMA, Privacy Act | Controls and parameters that implement the statute’s specific obligations |
Published NIST 800-53 overlays worth knowing
| Overlay | Publisher | Category | Note |
|---|---|---|---|
| Industrial control systems overlay | NIST SP 800-82 | System type | 800-53B cites it as the example of a fully specified overlay |
| CNSSI 1253 overlays for national security systems | Committee on National Security Systems | Community and statute | Classified, space, cross-domain, privacy overlays applied to CNSS baselines |
| Privacy overlay | CNSS / federal privacy community | Statute | Predates the Rev 5 PT family; still used for NSS |
| FedRAMP baselines | FedRAMP PMO | Community and technology (cloud) | Functionally overlays on the 800-53B baselines with FedRAMP parameter values and additional controls |
| Control Overlays for Securing AI Systems (COSAiS) | NIST | Technology | Concept paper 14 August 2025; use cases: generative AI assistants and LLMs, using and fine-tuning predictive AI, single- and multi-agent systems, security controls for AI developers; annotated outline for the predictive AI overlay released 8 January 2026 |
| Security Control Overlay Repository (SCOR) | NIST | All | The public platform for voluntarily sharing overlays and finding published ones |
The live one is COSAiS. NIST is building the AI overlays on the 800-53 catalogue together with SP 800-218A (secure software development for generative AI), draft AI 800-1 and AI 100-2e2025 (adversarial machine learning), and they are the first overlays most commercial organisations will have a reason to adopt. Our guide to the NIST SP 800-53 publication set covers where the overlays sit among 800-53, 53A and 53B.
How NIST 800-53 overlays are structured
800-53B offers an eight-section outline — an example, not a mandate — that published overlays generally follow.
| Section | Content |
|---|---|
| Identification | Unique name, version and date, the 800-53 version used, other source documents, author and point of contact, type of approval, duration and update triggers |
| Overlay characteristics | Physical environment, types of information processed, users and their clearances or roles, threats, and the system types and technologies targeted |
| Applicability | How a system owner decides whether the overlay applies, and how to handle systems that only partly match |
| Overlay summary | A table of every control and enhancement: added, removed, modified, with parameter values |
| Overlay control specifications | Per control: the tailoring decision, the rationale, supplemental guidance, and the parameter values |
| Tailoring considerations | What system owners may still tailor after applying the overlay, and what they may not |
| Terms and definitions | Overlay-specific vocabulary |
| Additional information or instructions | Assessment guidance, references, mappings |
Adopting NIST 800-53 overlays
- Confirm the baseline first. Categorise the system under FIPS 199 and take the 800-53B baseline; the overlay refines it and cannot substitute for it unless it is one of the baseline-independent overlays 800-53B describes for very specific circumstances.
- Test applicability honestly. Read the overlay’s characteristics section against the system. A cloud overlay applied to an on-premises system, or an ICS overlay applied to a business network, removes controls for reasons that do not exist.
- Apply, then tailor what remains. The overlay decides the community-level questions; the system owner still assigns any parameters the overlay leaves open, identifies common controls, and records the system-specific decisions.
- Record the overlay by name and version. The system security plan states which overlay and which release of 800-53 it was built on; an overlay written for Release 5.1.1 does not know about the controls Release 5.2.0 added.
- Assess against the overlay’s control set. The 800-53A procedures apply to the controls as tailored, including the overlay’s parameter values; the assessor needs the overlay to know what “satisfied” means.
Writing an overlay for your own community
Organisations with many like systems — a hospital group, a utility, a manufacturer with dozens of plants — build internal overlays for the same reason the sector bodies do. The discipline is the same: state the characteristics that make the systems alike, decide every control once with a written rationale, agree parameter values that every site can meet, and say what site-level tailoring is still allowed. 800-53B warns against widely divergent overlays on the same topic; where a published overlay exists for your category, refine it rather than compete with it, and consider submitting yours to SCOR. Our guide to the NIST 800-53 control families is the checklist for making sure the overlay visits every family, including PM and PT.
Frequently asked questions
What is a NIST 800-53 overlay?
A specification of controls, enhancements, supplemental guidance and parameter values used during tailoring to refine a baseline for a community of interest, technology, environment, system type, mission, threat or statute. It can be more or less stringent than the baseline and applies to multiple systems.
How is an overlay different from tailoring?
Tailoring adapts a baseline to one system; an overlay packages tailoring decisions for many systems that share a characteristic. 800-53B says the overlay concept is not appropriate for an individual system.
What are the categories of overlays?
800-53B Appendix C lists seven: communities of interest and sectors; information technologies and computing paradigms; environments of operation; types of systems and operating modes; types of missions or operations; types of threats; and statutory or regulatory requirements.
Which overlays are published?
The industrial control system overlay in SP 800-82, the CNSSI 1253 overlays for national security systems, FedRAMP’s baselines in effect, and NIST’s Control Overlays for Securing AI Systems (COSAiS), in development since the August 2025 concept paper. The Security Control Overlay Repository lists shared overlays.
Do private-sector organisations use overlays?
Yes — any organisation using 800-53 as its catalogue can adopt a published overlay or write an internal one for a class of like systems, and the AI overlays are aimed at exactly that audience.
Where this leaves you
Use NIST 800-53 overlays for what 800-53B designed them for: decisions that a whole class of systems shares. Take the baseline, apply the overlay that matches the system’s characteristics, tailor only what the overlay leaves open, record the overlay and the 800-53 release by name, and — if you own many like systems — write your own with the eight-section outline, because the alternative is every system owner re-deciding the same controls with less consistency and more assessor findings.
References
- NIST SP 800-53B — Control Baselines for Information Systems and Organizations — Appendix C, Overlays; the overlay definition and the example outline.
- NIST — Control Overlays for Securing AI Systems (COSAiS) — Concept paper of 14 August 2025 and the use cases.
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls — The catalogue the overlays refine.
More on NIST 800-53
- NIST 800-53 overlays — you are here
- NIST SP 800-53: the baselines and Release 5.2.0
- NIST 800-53 tailoring: the 5 actions
- NIST 800-53 control families: all 20
- NIST 800-53A: assessment procedures
- NIST 800-53 Rev 5 vs Rev 4
The overlay template on the 800-53B outline, the tailoring record, the control implementation matrix with parameter values and the system security plan template are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.