There are 1,014 active controls and enhancements in Revision 5, so no web assessment can work control by control. This one works at family level, anchored on the two or three controls in each family that carry the most weight, plus the scoping decisions that come before any of them.
This assessment scores 66 questions across all twenty control families, starting with the categorisation, baseline selection and organisation-defined parameter decisions that everything below them depends on. It is free, it saves as you go, and you can stop and come back to it.
What this is
The current release is Revision 5, Release 5.2.0, issued 27 August 2025. NIST moved off the five-yearly reissue model onto a versioned release model: major releases every two years, up to two minor releases a year. Release 5.2.0 added SA-15(13), SA-24 and SI-2(7) in response to Executive Order 14306, and broadened SI-7(12). SP 800-53B was reissued at the same version with no baseline changes, so those three new items are not in the Low, Moderate, High or Privacy baselines yet.
One citation trap worth knowing: the CSRC page at /pubs/sp/800/53/r5/final carries a withdrawn banner. That is the original September 2020 print. The live page is /r5/upd1/final. Rev 5 superseded itself when the December 2020 errata update replaced the first printing.
The background is elsewhere — the catalogue explained, the twenty families, tailoring, overlays, the assessment procedures, the privacy controls and Rev 5 against Rev 4. Come here when you want a score.
What it covers
66 questions, about 45 minutes.
| Section | Questions |
|---|---|
| Scoping, programme and planning | 7 |
| People and physical | 6 |
| Risk, assessment and authorisation | 7 |
| Access and identity | 9 |
| Configuration and maintenance | 6 |
| Audit and integrity | 8 |
| Protection, media and continuity | 10 |
| Acquisition, supply chain, incident and privacy | 13 |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
A control can be fully implemented and still be a gap if nobody has set the organisation-defined parameter it depends on. That is the quietest common failure in the whole catalogue, and it has a question of its own at the start.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list — as a PDF and a working Excel file.
How long does it take?
About 45 minutes. Access control, system and communications protection, system and services acquisition and system and information integrity carry the most weight — between them they are 480 of the 1,014 active controls and enhancements.
What to do with your score
Below 40% — settle the categorisation and the baseline first. Without them you have no yardstick, and a gap assessment against a catalogue you have not scoped to is a list of everything.
40–70% — the usual shape. The technical families score well and the programme management, supply chain and privacy families do not, because they are organisation-level and usually owned by nobody in particular.
Above 70% — look at the parameter values. Set, recorded and reviewed is a different answer from set once at build and never revisited, and an assessor reads the review date.
Frequently asked questions
Is this assessment really free?
Yes. All 66 questions, the breakdown by family and your overall score cost nothing. The $39 report is optional.
Why family level rather than control by control?
Because 1,014 controls is a consulting engagement, not a web form. Family level plus the highest-weight controls gets you a defensible picture in under an hour, and tells you which families need the full control-by-control treatment.
Where do PM and PT fit?
Both appear only in the Privacy baseline, never in Low, Moderate or High. Programme management controls are organisation-level, assessed once and inherited, which is exactly the level this assessment works at.
Is Revision 6 coming?
Nothing has been announced. As at September 2026 the current release is still 5.2.0, and NIST publishes no forward timeline beyond its stated release cadence.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.
NIST SP 800-53: The Baselines, and Release 5.2.0
NIST SP 800-53 is the control catalog nearly every US federal security regime is built on — and saying “we’re on Rev 5” no longer tells anyone which controls you mean.
Revision 5 has not become Revision 6. Instead it now receives patch releases, in the way software does, and the most recent one added controls. If your control set was baselined before August 2025, it is missing some.
What NIST SP 800-53 actually is
Security and Privacy Controls for Information Systems and Organizations is a catalog, not a standard you comply with. It provides controls to protect operations, assets, individuals, other organisations and the nation from a wide range of threats — hostile attacks, human error, natural disasters, structural failures, foreign intelligence entities and privacy risks.
Three design decisions distinguish it from most control sets.
Security and privacy live in one catalog. Revision 5 consolidated them rather than treating privacy as an appendix — which is why the same document underpins both security programmes and privacy programmes in federal agencies.
It is deliberately not federal-only in its language. The controls are written as outcomes for any information system, which is why private-sector organisations with no federal obligation adopt it.
It addresses functionality and assurance separately — the strength of the mechanism, and the confidence you have in it. Those are different questions and most frameworks conflate them.
The parts of NIST SP 800-53 you actually need

The single most common mistake is treating the NIST SP 800-53 catalog as the whole publication. It is not, and the other parts are where the work happens.
SP 800-53B holds the control baselines — low, moderate, high and privacy. The catalog tells you what a control is; 800-53B tells you which controls apply at your impact level. An organisation that has read the catalog but not the baselines has no basis for selecting anything.
SP 800-53A Rev. 5 holds the assessment procedures. This is what an assessor works from, so it is also the best guide to what evidence you will be asked for.
Two supporting resources are worth knowing about because they save real time. Rev. 5 controls are published in OSCAL, machine-readable, so a GRC platform can ingest them rather than have someone retype them. And NIST publishes an OLIR mapping from SP 800-53 Rev. 5 to ISO/IEC 27001:2022 — which is the fastest honest answer to “we already have ISO 27001, what else do we need?”
Release 5.2.0, and why patch releases matter
On 27 August 2025 NIST issued a minor release of NIST SP 800-53, Release 5.2.0. It was not a cosmetic update:
- New controls and enhancements: SA-15(13), SA-24, SI-02(07).
- Revised: SI-07(12).
- Updated discussion: SA-04, SA-05, SA-08, SA-08(14), SI-02, SI-02(05).
- Updated related controls: every -01 control, plus AU-02, AU-03, CA-07, IR-04, IR-06, IR-08, SA-15, SI-02 and SI-07.
The weight of this NIST SP 800-53 update sits in the SA (system and services acquisition) and SI (system and information integrity) families — supply chain and software integrity, which is where federal attention has been concentrated.
The practical consequence: record the release you baselined against, not just the revision. “Rev 5” was a sufficient answer in 2021. It is not now, and an assessor comparing your control set against the current catalog will find gaps you did not know you had.
Where NIST SP 800-53 shows up
| Regime | How it uses the catalog |
|---|---|
| FedRAMP | Built directly on the baselines, selected by impact level. If you are pursuing federal cloud authorisation, this catalog is the substance of it |
| GovRAMP | Built on Rev. 5, with Core Verification using 60 prioritised controls aligned to the Moderate baseline |
| SP 800-171 | A different publication for a different job — protecting CUI in nonfederal systems, derived from but not equal to the 800-53 catalog |
| ISO 27001 | NIST publishes an OLIR mapping between Rev. 5 and the 2022 edition. Substantial overlap, but ISO 27001 certifies a management system and 800-53 does not certify anything |
That last distinction is the one to hold onto. Nobody certifies you to SP 800-53. You are authorised, assessed or contracted against a baseline drawn from it. The catalog is an input to those processes, never the output.
Where NIST SP 800-53 implementations go wrong
- Implementing the catalog instead of a baseline. There are over a thousand controls and enhancements; nobody applies them all. Select from 800-53B.
- Ignoring tailoring. The controls are explicitly flexible and customisable. Tailoring decisions have to be recorded, with reasons, or they read as omissions.
- Treating privacy controls as optional. They are in the same catalog for a reason.
- Baselining once. Patch releases mean the catalog moves under you.
- Retyping controls. The OSCAL version exists precisely so you do not have to.
Where to start with NIST SP 800-53
- Fix your impact level first — low, moderate or high — because the baseline follows from it.
- Take the baseline from SP 800-53B, not the catalog.
- Read SP 800-53A for the control you are implementing, so you build the evidence the assessor will ask for.
- Record the release, e.g. Rev. 5 Release 5.2.0, in your system security plan.
- Ingest the OSCAL files rather than rekeying.
- Use the OLIR mapping if you hold ISO 27001, to find the genuine delta rather than starting again.
This guide reflects csrc.nist.gov at 15 August 2026, on which SP 800-53 Rev. 5 with Release 5.2.0 is current. Check the planning notes before baselining — that is where NIST announces patch releases.
The NIST SP 800-53 Security Controls Toolkit provides editable templates covering the system security plan, the control implementation and tailoring records, the assessment evidence and the continuous monitoring artefacts.