NIST 800-53 Rev 5 vs Rev 4 still matters in 2026 because the two revisions are both alive in the regimes built on the catalogue: Revision 5 has been the current publication since September 2020 and Revision 4 was withdrawn on 23 September 2021, yet NIST SP 800-171 Revision 2 — the version CMMC assesses against — was derived from the Rev 4 moderate baseline, FedRAMP only completed its move to Rev 5 baselines in 2023–2024, and thousands of system security plans still carry Rev 4 control text.
Rev 5 changed the catalogue in seven ways NIST lists in its own preface: outcome-based control statements with the responsible entity removed; security and privacy integrated in one catalogue; a new Supply Chain Risk Management family; control selection separated from the controls; baselines and tailoring moved out to SP 800-53B; the relationship between requirements and controls clarified; and new state-of-the-practice controls for resiliency, secure design and governance. This guide sets the two revisions side by side, lists what was added, withdrawn and renamed, explains what the change means for a system security plan, and gives a migration path for a control set still written to Rev 4.

NIST 800-53 Rev 5 vs Rev 4 at a glance
| SP 800-53 Rev 4 | SP 800-53 Rev 5 | |
|---|---|---|
| Published | April 2013, updated January 2015 | September 2020, updated 10 December 2020; Release 5.1.1 (2023) and Release 5.2.0 (27 August 2025) |
| Status | Withdrawn 23 September 2021 | Current |
| Families | 18 (privacy in Appendix J, not a family) | 20 — PT and SR added |
| Control statement form | “The organization…” / “The information system…” | Outcome-based; no entity named |
| Baselines | Inside the publication, Appendix D | SP 800-53B: low, moderate, high and a privacy baseline |
| Tailoring guidance | Inside the publication | SP 800-53B |
| Privacy | Appendix J privacy controls, separate from security | Integrated: PT family plus privacy attributes across families; privacy baseline |
| Supply chain | SA-12 and enhancements | SR family, SR-1 to SR-12, plus SA controls |
| Assessment companion | SP 800-53A Rev 4 (December 2014) | SP 800-53A Rev 5 (January 2022) |
| Machine-readable | Spreadsheet | OSCAL and spreadsheet |
Our guide to NIST SP 800-53 covers what Release 5.2.0 changed inside Rev 5.
NIST 800-53 Rev 5 vs Rev 4: the seven changes in practice
| Change (NIST’s list) | What it means for a control set |
|---|---|
| 1. Outcome-based statements | Controls no longer say who does what; the SSP must state whether the organisation, the system, a provider or a hybrid implements each — the responsibility column is now yours to write |
| 2. Security and privacy in one catalogue | Privacy is no longer an appendix a security team can skip; controls carry privacy attributes and the PT family applies wherever PII is processed |
| 3. New SR family | Twelve supply chain controls (SR-1 to SR-12): policy, the supply chain risk management plan, controls and processes, provenance, acquisition strategies, supplier assessments, operations security, notification agreements, tamper resistance, inspection, component authenticity, component disposal — absorbing the Rev 4 SA-12 cluster |
| 4. Selection separated from controls | The catalogue no longer tells you which controls apply; 800-53B does. A Rev 5 control set has to cite its baseline source |
| 5. Baselines and tailoring moved to 800-53B | The moderate baseline, tailoring actions and overlay guidance are in a different document with its own release history |
| 6. Requirements vs controls clarified | A requirement is what a law or policy demands; a control is a safeguard that satisfies it. The SSP traces controls to requirements rather than treating the catalogue as the requirement |
| 7. New controls | Cyber resiliency, secure system design and governance controls — for example in SA, SC, SI and PM — and the PT family; plus Rev 5’s practice of withdrawing controls into others rather than renumbering |
NIST 800-53 Rev 5 vs Rev 4: what was added, withdrawn and renamed
| Category | Rev 5 treatment | Examples |
|---|---|---|
| New families | PT (PII Processing and Transparency, 8 controls) and SR (Supply Chain Risk Management, 12 controls) | PT-2 Authority to Process PII, PT-4 Consent; SR-3 Supply Chain Controls and Processes, SR-11 Component Authenticity |
| Withdrawn controls and enhancements | Kept in the catalogue marked “[Withdrawn: Incorporated into …]” so numbering is stable | An AC-2 enhancement incorporated into AC-2k; another AC item into MP-4 and SC-28; SA-12 and its enhancements into the SR family |
| Renamed families | CA became Assessment, Authorization, and Monitoring; PT and SR named | CA was Security Assessment and Authorization in Rev 4 |
| Privacy appendix | Appendix J controls redistributed into PT and privacy-relevant controls elsewhere (e.g. PM-18 to PM-27 series, RA-8, SI-18, SI-19) | AP, AR, DI, DM, IP, SE, TR, UL families of Appendix J no longer exist |
| Parameters | More organization-defined parameters, and 800-53A Rev 5 tests them on their own determination statements | Frequencies, lists of roles, retention periods |
Our guide to the NIST 800-53 control families lists all twenty as Rev 5 names them.
Where each revision still applies in 2026
| Regime | Revision in effect | Note |
|---|---|---|
| FISMA agency systems | Rev 5 via 800-53B baselines | OMB expects current NIST publications; Rev 4 SSPs are legacy |
| FedRAMP | Rev 5 baselines | Transition from Rev 4 ran 2023–2024; new authorisations are Rev 5 |
| NIST SP 800-171 Rev 2 / CMMC | Derived from Rev 4 moderate | CMMC assesses 800-171 Rev 2; 800-171 Rev 3 (May 2024) is derived from Rev 5 but DoD has not adopted it for CMMC |
| StateRAMP | Rev 5 baselines | Aligned to FedRAMP |
| CNSS national security systems | CNSSI 1253 on Rev 5 | With CNSS overlays |
| Private-sector adopters | Whichever their contracts cite | Most have moved; mapping tools such as NIST’s OLIR are Rev 5 |
Our guide to NIST 800-171 vs 800-53 explains why the CMMC world is frozen at the Rev 4-derived 800-171 Rev 2 even while the catalogue has moved on — the NIST 800-53 Rev 5 vs Rev 4 question is settled for the catalogue and unsettled for its derivatives.
Migrating a control set from Rev 4 to Rev 5
A NIST 800-53 Rev 5 vs Rev 4 migration has seven moves.
- Get the mapping, not the diff. NIST published a Rev 4-to-Rev 5 comparison workbook; use it to map every control in the current SSP to its Rev 5 identifier, its withdrawn-into target, or its new home in PT or SR.
- Re-select from 800-53B. The moderate baseline is not the same set of controls it was in Rev 4 Appendix D; re-derive the baseline and re-run the tailoring record. Our guide to NIST 800-53 tailoring covers the five actions.
- Rewrite the responsibility column. Outcome-based statements need an explicit implementation owner per control — organisation, system, provider, hybrid.
- Add the SR and PT families. Supply chain is a full family now; PT applies if the system processes PII, and the privacy baseline applies regardless of impact level.
- Assign the new parameters. Every organization-defined value Rev 5 added is a determination statement in 800-53A Rev 5.
- Update to the current release. Migrate to Release 5.2.0, not to Rev 5 as published in 2020; record the release in the SSP.
- Re-plan the assessment. 800-53A Rev 5 procedures, with depth and coverage set for the new controls.
Frequently asked questions
What changed between NIST 800-53 Rev 4 and Rev 5?
NIST’s own list: outcome-based control statements; security and privacy integrated in one catalogue; a new Supply Chain Risk Management family; control selection separated from the controls; baselines and tailoring moved to SP 800-53B; the requirements-versus-controls relationship clarified; and new controls for resiliency, secure design and governance. Rev 5 also added the PT privacy family, taking the family count from 18 to 20.
Is Rev 4 still valid?
It was withdrawn on 23 September 2021. It survives indirectly because NIST SP 800-171 Rev 2, which CMMC assesses, was derived from the Rev 4 moderate baseline.
Did Rev 5 renumber the controls?
No. Withdrawn controls are kept in the catalogue marked as incorporated into another control, so identifiers are stable; new controls were appended and two new families were added.
Where did the Rev 4 privacy appendix go?
Appendix J’s privacy controls were integrated into Rev 5 — the PT family and privacy-relevant controls in PM, RA, SI and elsewhere — and 800-53B added a privacy baseline that applies regardless of impact level.
Is Rev 5 finished?
It is maintained by release rather than by revision: Release 5.1.1 and, from 27 August 2025, Release 5.2.0, which added SA-15(13), SA-24 and SI-02(07). Record the release, not just the revision.
Where this leaves you
Treat NIST 800-53 Rev 5 vs Rev 4 as a migration with seven known moves: map every control, re-select the baseline from 800-53B, write the responsibility column the outcome-based statements now require, add the SR and PT families, assign the new parameters, land on Release 5.2.0 and re-plan the assessment under 800-53A Rev 5 — while remembering that a CMMC programme stays on the Rev 4-derived 800-171 Rev 2 until DoD says otherwise.
References
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems and Organizations — Preface list of significant changes; Release 5.2.0.
- NIST SP 800-53B — Control Baselines for Information Systems and Organizations — Where the baselines and tailoring moved.
- NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls — The Rev 5 assessment procedures.
More on NIST 800-53
- NIST 800-53 Rev 5 vs Rev 4 — you are here
- NIST SP 800-53: the baselines and Release 5.2.0
- NIST 800-53 control families: all 20
- NIST 800-53 tailoring: the 5 actions
- NIST 800-171 vs 800-53
- NIST 800-53A: assessment procedures
The Rev 4-to-Rev 5 migration workbook, the family-by-family policy set including SR and PT, the control implementation matrix with responsibility and parameter columns and the tailoring record are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.