NIST 800-53A — SP 800-53A Revision 5, Assessing Security and Privacy Controls in Information Systems and Organizations, published in January 2022 — is the publication an assessor works from, and therefore the best guide to what evidence a control owner will be asked for. For every control and enhancement in SP 800-53 Rev 5 it provides an assessment procedure: a set of assessment objectives broken into numbered determination statements, each with potential assessment methods — examine, interview, test — and the assessment objects those methods are applied to.
Findings are recorded as satisfied or other than satisfied, per determination statement, and the depth and coverage of each method are set at basic, focused or comprehensive. This guide explains the anatomy of a procedure, the three methods and four object types, how depth and coverage are chosen, the five-step assessment process, what goes in the assessment report, and how a control owner uses 800-53A to prepare evidence before the assessor arrives.

What NIST 800-53A is for
SP 800-53 states controls; SP 800-53B selects them; SP 800-53A tests them. The assessment procedures are what a FedRAMP 3PAO, an agency assessor, a StateRAMP assessor or an internal assessment team applies to produce the security and privacy assessment reports that go into the authorisation package with the system security plan, privacy plan and plan of action and milestones. Rev 5 of 800-53A was aligned to the Rev 5 catalogue, decomposed the objectives into more granular determination statements, and separated the determination statements for organization-defined parameters from those for the control items — so that an unassigned parameter now fails on its own line. Our guide to NIST SP 800-53 covers the publication set.
The anatomy of an assessment procedure
| Element | What it is | Example (AC-17 Remote Access) |
|---|---|---|
| Assessment objective | What the assessor is trying to determine for the control, derived from the control statement | Determine if the remote access control is implemented as stated |
| Determination statements | The objective decomposed into granular, individually answerable items; further granularised where the control text bundles several requirements | AC-17a.[01] usage restrictions are established and documented for each type of remote access; AC-17a.[02] configuration/connection requirements; AC-17a.[03] implementation guidance; AC-17b. each type of remote access is authorized prior to allowing such connections |
| Potential assessment methods | Examine, interview and test — not every procedure uses all three | AC-17-Examine, AC-17-Interview, AC-17-Test |
| Assessment objects | What each method is applied to: specifications, mechanisms, activities, individuals | Examine: access control policy, remote access procedures, configuration settings, authorisations, audit records, SSP; Interview: personnel managing remote access, administrators; Test: the remote access management capability |
| Finding | Satisfied or other than satisfied, per determination statement | AC-17a.[02] other than satisfied: no connection requirements documented for vendor VPN |
The granularity is the point. A control owner who can answer each determination statement with a named artefact, a named person and a demonstrable mechanism has already done the assessor’s work; one who can only say “we have a remote access policy” will fail the statements the policy does not reach.
The three methods and four object types
| Method | 800-53A definition | Applied to | What it produces |
|---|---|---|---|
| Examine | Reviewing, inspecting, observing, studying or analysing assessment objects to facilitate understanding, achieve clarification or obtain evidence | Specifications, mechanisms, activities | Document and configuration evidence |
| Interview | Holding discussions with individuals or groups to facilitate understanding, achieve clarification or obtain evidence | Individuals | Corroboration that people know and do what the documents say |
| Test | Exercising assessment objects under specified conditions to compare actual state to desired state or expected behaviour | Activities, mechanisms | Proof the control operates |
| Object type | Definition | Examples |
|---|---|---|
| Specifications | Document-based artefacts associated with a system or common control | Policies, procedures, plans, requirements, functional specifications, architectural designs |
| Mechanisms | Hardware, software or firmware safeguards employed within a system, including physical protection devices | Access control lists, encryption modules, locks, cameras, fire protection |
| Activities | Protection-related actions involving people | Running backups, monitoring network traffic, exercising a contingency plan |
| Individuals | People applying the specifications, mechanisms or activities | Administrators, security officers, users |
Depth and coverage
Each method carries two attributes. Depth is the rigour and level of detail of the examination, interview or test; coverage is its scope and breadth — how many and which objects. Both take the values basic, focused and comprehensive, and Appendix C of 800-53A describes what each value means per method.
The organisation chooses the values in the assessment plan according to the assurance it needs: a low-impact system may be examined at basic depth on a sample of objects; a high-impact system or a FedRAMP High authorisation expects comprehensive depth and coverage on the controls that matter. Depth and coverage are also where reuse of prior assessment evidence is decided — an earlier comprehensive test can support a later focused one if the object has not changed.
The NIST 800-53A assessment process
| Step (800-53A Chapter 3) | Purpose | Output |
|---|---|---|
| 3.1 Prepare | Establish objectives, scope and the assessor’s independence; assemble the SSP, prior results and the control set as tailored | Assessment scope and schedule |
| 3.2 Develop the assessment plans | Select procedures for every in-scope control, tailor methods and objects, set depth and coverage, handle common and hybrid controls, decide reuse of evidence | Security and privacy assessment plans, approved by the organisation |
| 3.3 Conduct the assessments | Apply the methods to the objects; record findings per determination statement | Assessment findings |
| 3.4 Analyse the report results | Findings of other than satisfied are analysed for risk; the organisation decides to accept, reject or mitigate; updates the SSP and POA&M | Security and privacy assessment reports; POA&M entries |
| 3.5 Assess capabilities | Optionally assess groups of controls as a security or privacy capability rather than one by one | Capability-level findings |
The assessment report — Appendix E gives its recommended content — carries, for each other-than-satisfied finding, which parts of the control are affected, how the actual state differs from the planned state, and the potential for compromise to confidentiality, integrity, availability or privacy. Organisations may add severity subcategories to prioritise remediation. Our guide to NIST 800-53 tailoring covers the tailored control set the plan is built against.
Using NIST 800-53A before the assessor arrives
- Build the evidence matrix from the determination statements, not from the controls. One row per determination statement, with the specification, mechanism, activity and individual that answer it. A control with six statements needs six answers.
- Assign every organization-defined parameter first. Rev 5 of 800-53A tests parameters on separate determination statements; an unassigned frequency or list fails before the control is examined.
- Prepare for all three methods. A document proves the specification exists; the interview proves people follow it; the test proves the mechanism works. Assessors triangulate, and a policy nobody can describe in interview is a finding.
- Run the procedures internally at the depth the plan will use. An internal assessment at focused depth that produces zero findings means the internal assessment was too shallow, not that the system is clean.
- Record the 800-53 release. Release 5.2.0 of the catalogue added SA-15(13), SA-24 and SI-02(07); 800-53A procedures for new controls follow, and an assessment against the wrong release is a scoping error before it is a finding.
- Mark inapplicable determination statements with a reason. 800-53A allows an assessor to disregard a non-applicable requirement — a privacy statement on a system with no PII — and still find the control satisfied, but only if the inapplicability is recorded.
Our guide to the NIST 800-53 control families is the checklist for making sure the matrix covers every family.
Frequently asked questions
What is NIST 800-53A?
SP 800-53A Revision 5 (January 2022), the companion to SP 800-53 that provides an assessment procedure for every control and enhancement: assessment objectives decomposed into determination statements, with examine, interview and test methods applied to specifications, mechanisms, activities and individuals, producing findings of satisfied or other than satisfied.
What are the three assessment methods?
Examine (review, inspect, observe, study or analyse objects), interview (discuss with individuals or groups) and test (exercise mechanisms or activities under specified conditions and compare actual to expected state). Not every procedure uses all three.
What do depth and coverage mean?
Depth is the rigour and level of detail of a method; coverage is its scope and breadth across assessment objects. Both are set to basic, focused or comprehensive in the assessment plan, according to the assurance required.
What is a determination statement?
A granular, individually answerable item derived from the control statement — AC-17a.[01], AC-17a.[02] and so on — against which the assessor records satisfied or other than satisfied. Rev 5 separates the statements for organization-defined parameters from those for the control items.
Who uses NIST 800-53A?
FedRAMP 3PAOs, agency and StateRAMP assessors, and internal assessment teams performing CA-2 control assessments and CA-7 continuous monitoring — and control owners preparing evidence, because the procedures tell them exactly what will be asked.
Where this leaves you
Read NIST 800-53A as the answer key: build the evidence matrix by determination statement, assign every parameter, prepare a document, a person and a working mechanism for each, run the procedures internally at real depth, and record the 800-53 release and every inapplicability — because the assessor’s report will be written in exactly those terms, and satisfied is the only finding that does not become a POA&M entry.
References
- NIST SP 800-53A Rev. 5 — Assessing Security and Privacy Controls in Information Systems and Organizations — Chapters 2–3, the AC-17 example, Appendices C and E.
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls — The controls the procedures assess; Release 5.2.0.
More on NIST 800-53
- NIST 800-53A — you are here
- NIST SP 800-53: the baselines and Release 5.2.0
- NIST 800-53 control families: all 20
- NIST 800-53 tailoring: the 5 actions
- NIST 800-53 overlays
- NIST 800-53 vs ISO 27001
The control assessment plan template, the evidence matrix keyed to determination statements, the assessment report template on the Appendix E outline and the POA&M register are in the NIST SP 800-53 Security Controls Toolkit, or start with the free templates.