Requirements browser
Every control NIST publishes, rendered from NIST's own OSCAL, the same files the catalogs are distributed as. Nothing is summarised or rewritten: what you read here is what is in the source, including the parameters you have to decide and the objectives an assessor will test.
SP 800-53 Rev 5
Security and Privacy Controls
The federal control catalog. Everything else on this list either profiles it or maps to it.
- Controls
- 324
- Families
- 20
- Params
- 1,458
SP 800-53 Rev 4
Security and Privacy Controls
The superseded revision, still in scope for systems that have not moved to Rev 5.
- Controls
- 256
- Families
- 18
- Params
- 853
SP 800-171 Rev 3
Protecting CUI
What CMMC Level 2 is assessed against. One flat layer of requirements, no baselines.
- Requirements
- 130
- Families
- 17
- Params
- 88
SP 800-172 Rev 3
Enhanced Requirements for CUI
The advanced-persistent-threat overlay on 800-171, and the basis for CMMC Level 3.
- Requirements
- 115
- Families
- 17
- Params
- 164
SP 800-218 v1.1
Secure Software Development Framework
Practices and tasks for the build pipeline rather than the running system.
- Practices
- 19
- Families
- 4
CSF v2.0
Cybersecurity Framework
Outcomes rather than controls, in the language executives already read.
- Categories
- 34
- Families
- 6
Served from NIST's OSCAL content, which is released into the worldwide public domain under CC0 1.0. Counts are generated from those same files.