What category of publication this is
NIST Special Publication 800-53 Revision 5 is Security and Privacy Controls for Information Systems and Organizations. It is a catalog of security and privacy controls. Organizations select controls from it and tailor them to the system, the mission, and the risk. It is a vocabulary to choose from, not one list that every control applies to every system.
Federal agencies use the catalog inside their risk management programs, and many contracts and programs point to it. A private company is not automatically obligated to use it, and it is not a single mandatory list for every private company. Whether a real organization has an obligation depends on law, contract, or program terms that this page does not decide.
Edition pin
SP 800-53 Revision 5, current minor release Release 5.2.0, issued 27 August 2025. DOI 10.6028/NIST.SP.800-53r5. The CSRC Final page is csrc.nist.gov/pubs/sp/800/53/r5/upd1/final, and NIST announced the release in the CSRC news item NIST Releases Revision to SP 800-53 Controls. The Reference card uses the same pin: Revision 5, Release 5.2.0 (27 August 2025), shown as SP 800-53 Rev.5 Rel 5.2.0.
Release 5.2.0 theme, one sentence only: NIST issued it in response to Executive Order 14306, with updates focused on software update and patch reliability. Re-open the CSRC page at publish. If a newer release or revision appears, update this pin and treat the older claim as UNKNOWN.
Catalog, baseline, and assessment are three documents
Three names, three jobs. SP 800-53 is the catalog: the controls you can choose from. SP 800-53B holds the control baselines: starting selections that an organization then tailors. SP 800-53A holds the assessment procedures: how someone checks whether selected controls are in place and working as intended. Catalog is not baseline, and baseline is not assessment.
This page names the companions only. It does not copy their baselines or procedures. For where selection and assessment sit in the Risk Management Framework, see the Select and Assess steps on the SP 800-37 explainer (/learn/explainers/sp-800-37/).
Obligation or borrowed language
When someone says "we use 800-53," ask which of two things they mean. Obligation: a law, contract, or program requires the organization to select, implement, and assess controls from the catalog, with an owner who decides tailoring. Borrowing: the team uses 800-53 control language as a vocabulary to describe its own practices, with no external obligation behind it. Both are legitimate. They are not the same claim.
In either case, record the exact revision and release in every mapping, for example Revision 5, Release 5.2.0, so nobody cites an older set by accident. A mapping to a vendor feature list is a starting note, not a finished selection. Selection, tailoring, and evidence are the work.
Why this page does not reprint control families
The controls live in the official catalog. NIST publishes SP 800-53 Release 5.2.0 through the CSRC publication page and the Cybersecurity and Privacy Reference Tool (CPRT). Read the controls there, from the source, at the pinned release.
This page does not list control families, does not assign control identifiers as homework, and does not hand out an implement-every-policy worksheet. The Reference card (/reference/frameworks/nist-sp-800-53-r5/) stays the framework summary, with purpose, getting-started steps, and evidence examples. This explainer complements that card. It does not replace it.
Rewrite the one-line claim
Replace "we are NIST, FedRAMP, CMMC, and 171 compliant" with separate objects. For example: we borrow SP 800-53 Revision 5, Release 5.2.0 control language to describe our practices. Our cloud offering has, or does not have, a FedRAMP Authorization. Our contract does, or does not, require SP 800-171 for CUI and a CMMC assessment. Each clause names its own owner and evidence.
At work, privately ask which revision and release your team's mappings cite, and whether the team has an obligation or is borrowing language. Do not paste internal control mappings or sensitive system details into Atlas.
The catalog is not a sticker, not FedRAMP, not FISMA done, and not SP 800-171 or CMMC
Teaching table only. It does not assign an obligation, a baseline, an Authorization, an assessment result, or a finding that a publication has been met.
| Phrase people say | Literacy correction |
|---|---|
| We implemented NIST, or 800-53, so we are NIST compliant | SP 800-53 is a catalog to select and tailor from. A "NIST compliant" sticker is folklore. Whether there is an obligation, and how controls were tailored, is what matters. Reference card: /reference/frameworks/nist-sp-800-53-r5/. |
| 800-53 equals FedRAMP | FedRAMP is the federal cloud product and service Authorization program. It draws on the catalog, and it is a different object. Atlas card: /learn/explainers/fedramp/. |
| 800-53 means FISMA is done | FISMA is the statutory and program backdrop for federal agency information security management. Reading the catalog is not an Authorization and not a finished program. Atlas cards: /learn/explainers/fisma/ and /learn/explainers/sp-800-37/. |
| 800-53 equals SP 800-171 equals CMMC | SP 800-171 protects CUI on nonfederal systems. CMMC is the DoD/DoW contractor assessment program for the Defense Industrial Base. Different publications and programs. Atlas cards: /learn/explainers/sp-800-171/ and /learn/explainers/cmmc/. |
| Map every control ID to a vendor feature and you are done | Selection, tailoring, and evidence beat feature bingo. A mapping is a starting note, and it should cite the exact revision and release. |
Claims to retire
We implemented NIST, or 800-53, so we are NIST certified or NIST compliant.
SP 800-53 is a catalog to select and tailor from. There is no "NIST compliant" sticker from the catalog itself. Obligation, tailoring, and evidence decide what a claim means.
800-53, FedRAMP, FISMA, SP 800-171, and CMMC are interchangeable badges.
The catalog is a publication. FedRAMP is a cloud Authorization program. FISMA is the statutory and program backdrop for federal agencies. SP 800-171 covers CUI on nonfederal systems. CMMC is a contractor assessment program. Related vocabulary, different objects.
The baselines and the assessment procedures are in the same document as the catalog.
Baselines live in SP 800-53B. Assessment procedures live in SP 800-53A. The catalog is SP 800-53. Three companion documents, three jobs.
Mapping every control ID to a vendor feature finishes control selection.
A feature list is not a selection. Selection and tailoring are owner decisions tied to the system and its risk, and a claim still needs evidence.
This explainer replaces the SP 800-53 Reference card.
The Reference card at /reference/frameworks/nist-sp-800-53-r5/ stays. This page complements it with catalog literacy and the inequalities table.
Finishing this Atlas lesson is an Authorization or an assessment.
Atlas issues no Authorizations and performs no SP 800-53A assessments. Completing a lesson is not a finding that any control is in place.
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- NIST SP 800-53 Reference card (framework summary, complement to this page)
- SP 800-37 explainer (RMF Select and Assess steps)
- FISMA explainer (statutory backdrop, not FISMA done)
- FedRAMP explainer (cloud Authorization, different lane)
- SP 800-171 explainer (CUI on nonfederal systems, different publication)
- CMMC explainer (contractor assessment program, different lane)
- SP 800-82 explainer (OT guidance with an SP 800-53 overlay, related)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.