NIST 800-53
Definition
NIST 800-53
NIST 800-53 is the United States catalogue of security and privacy controls for federal information systems and the organisations running them. It is a catalogue, not a checklist, and selecting the applicable baseline is the work that actually matters.
That distinction defeats a lot of procurement conversations.
Nobody implements all of NIST 800-53 — the catalogue is deliberately comprehensive so that different systems, at different sensitivity levels, can draw different subsets from it.
A provider claiming to be “800-53 compliant” without naming a baseline has said very little. The meaningful question is which controls apply to your system and who operates each one.
Key takeaways
- The full title is Security and Privacy Controls for Information Systems and Organizations.
- Revision 5 was published in September 2020, with updates through December 2020.
- Supply Chain Risk Management is one of the named control families.
- Controls are selected into baselines by system impact level, not applied wholesale.
How it works
The publication is Security and Privacy Controls for Information Systems and Organizations, Revision 5, published in September 2020 with updates issued through December of that year. It organises controls into families.
Security and privacy were merged in Revision 5. Earlier revisions treated privacy controls as a separate appendix, and consolidating them reflected how the two disciplines had converged in practice.
Supply Chain Risk Management is among the named families, which is the part that speaks directly to outsourcing. Controls in that family address the risk that a supplier introduces into a system you are accountable for.
Baselines are how the catalogue becomes usable. A system is categorised by impact, and a corresponding set of controls is selected — which is why two organisations can both claim alignment and be doing quite different things.
FedRAMP is the clearest working example of that selection. The programme draws its cloud baselines from this catalogue rather than writing separate requirements, and publishes authorised services on its marketplace.
| Question | Why it matters in outsourcing |
|---|---|
| Which baseline applies? | Determines how many controls are in scope |
| Who operates each control? | The provider, you, or both |
| Are privacy controls included? | Revision 5 merged them into the catalogue |
| Is supply chain risk addressed? | It is a named family, often skipped |
| Which revision is referenced? | Contracts sometimes cite superseded ones |
Ask for the control implementation summary rather than a compliance statement — the summary shows the allocation, the statement shows the marketing.
Examples
Control catalogues become real at the moment someone has to say which party operates which control, and outsourcing forces that conversation. Each example here is drawn from work that is running under contract right now.
A cloud provider inherits most infrastructure controls while the customer retains application and access controls. That allocation is the substance of the relationship.
A buyer asks a provider for its control implementation summary and finds forty controls marked customer responsibility. Those had never been assigned internally, a common compliance outsourcing gap.
An agency programme references an older revision in its contract. The provider is compliant with the cited revision and behind the current one, which is a contractual rather than technical problem.
A commercial firm adopts the catalogue voluntarily for its government outsourcing pipeline. Adopting federal controls before winning federal work is a reasonable investment.
Related terms
Control catalogues, frameworks, programmes and certifications occupy different layers that buyers routinely flatten. Every entry here defines a single thing and stops before it starts overlapping.
- NIST AI risk management framework: a voluntary framework, not a control catalogue.
- Cybersecurity outsourcing: buying security capability to operate controls like these.
- Government outsourcing: the contracting context in which this catalogue is mandatory.
- Compliance outsourcing: delegating regulatory work, distinct from implementing controls.
- Information security analyst: the role implementing and evidencing individual controls.
- ISO 27001: a certifiable management system, where this is an uncertified catalogue.
- Risk outsourcing: transferring exposure, which control allocation does not accomplish.
FAQ
What is NIST 800-53?
The United States catalogue of security and privacy controls for information systems and organisations, maintained by the National Institute of Standards and Technology.
Which revision is current?
Revision 5, published in September 2020 with updates issued through December 2020. Contracts sometimes still reference earlier revisions.
Do organisations implement every control?
No. Controls are selected into baselines according to a system’s impact level, so the applicable set varies considerably.
Can you be certified against it?
No. There is no certification scheme. Federal systems are authorised, and programmes such as FedRAMP assess against baselines drawn from it.
Does it cover supply chain risk?
Yes. Supply Chain Risk Management is a named control family, which is the part most relevant to outsourced arrangements.
How does it relate to FedRAMP?
FedRAMP draws its cloud security baselines from this catalogue rather than maintaining a separate set of control requirements.
Begin at Outsource Accelerator and map the baseline to the systems you actually run.







Independent




