NIST Special Publication 800-53 Revision 5 guide.

Overview

NIST 800-53 is a catalog of security and privacy controls for federal information systems.

Who needs it: Federal contractors, FedRAMP Cloud Service Providers
Certification: Not a certification itself (used by FedRAMP, FISMA)
Total controls: 1,196 controls
AuditKit coverage: 149 automated technical controls, reached through the SOC 2 / PCI / CMMC crosswalk
What's not covered: the remaining 1,047 organizational and policy controls

How AuditKit Uses 800-53

Framework crosswalk: AuditKit maps existing SOC2, PCI-DSS, and CMMC controls to NIST 800-53 control families.

Example:

Your SOC2 control: CC6.6 - MFA enforcement

Maps to NIST 800-53:
- IA-2: Identification and Authentication
- IA-2(1): Multi-Factor Authentication
- IA-5: Authenticator Management

Benefit: Run one scan, see compliance across all frameworks

Control Families

NIST 800-53 has 20 control families. AuditKit reaches controls in 18 of them; PT (Personally Identifiable Information Processing) and SR (Supply Chain Risk Management) have no automated coverage:

AC - Access Control

AuditKit checks: IAM policies, MFA, least privilege, access key rotation

Example controls:

  • AC-2: Account Management
  • AC-3: Access Enforcement
  • AC-17: Remote Access

AU - Audit and Accountability

AuditKit checks: CloudTrail, logging, log retention, audit trails

Example controls:

  • AU-2: Event Logging
  • AU-3: Content of Audit Records
  • AU-12: Audit Record Generation

CA - Assessment, Authorization, & Monitoring

AuditKit checks: Security Hub, Config, compliance monitoring

Example controls:

  • CA-7: Continuous Monitoring

CM - Configuration Management

AuditKit checks: Config baselines, change tracking, patch management

Example controls:

  • CM-2: Baseline Configuration
  • CM-6: Configuration Settings

IA - Identification and Authentication

AuditKit checks: MFA, password policies, authenticator management

Example controls:

  • IA-2: Identification and Authentication
  • IA-5: Authenticator Management

IR - Incident Response

AuditKit checks: GuardDuty, Defender, Security Command Center, alerting

Example controls:

  • IR-4: Incident Handling
  • IR-6: Incident Reporting

MA - Maintenance

AuditKit checks: Systems Manager, Update Management, maintenance windows

Example controls:

  • MA-2: Controlled Maintenance

MP - Media Protection

AuditKit checks: Storage encryption, secure deletion policies

Example controls:

  • MP-5: Media Transport

PE - Physical and Environmental Protection

What AuditKit checks: Limited - mostly manual verification

PL - Planning

What AuditKit checks: Limited - mostly organizational policies

PM - Program Management

What AuditKit checks: Limited - mostly organizational policies

PS - Personnel Security

What AuditKit checks: Limited - mostly organizational policies

RA - Risk Assessment

AuditKit checks: Vulnerability scanning, threat detection

Example controls:

  • RA-5: Vulnerability Monitoring and Scanning

SA - System and Services Acquisition

What AuditKit checks: Limited - mostly organizational policies

SC - System and Communications Protection

AuditKit checks: Encryption, network segmentation, firewalls, TLS

Example controls:

  • SC-7: Boundary Protection
  • SC-8: Transmission Confidentiality
  • SC-13: Cryptographic Protection

SI - System and Information Integrity

AuditKit checks: Malware protection, patch management, flaw remediation

Example controls:

  • SI-2: Flaw Remediation
  • SI-3: Malicious Code Protection

SR - Supply Chain Risk Management

What AuditKit checks: Limited - mostly organizational policies

What AuditKit Automates

Technical controls (149):

  • Access controls and authentication
  • Logging and monitoring
  • Encryption and key management
  • Network security
  • Vulnerability management
  • Configuration management
  • Incident detection
  • Backup and recovery

What AuditKit doesn't cover (about 1,050 controls):

  • Organizational policies
  • Training programs
  • HR procedures
  • Physical security
  • Risk assessments
  • Contingency planning
  • System acquisition
  • Privacy controls

Running 800-53 Scan

# AWS
auditkit scan -provider aws -framework 800-53

# Azure
auditkit scan -provider azure -framework 800-53

# GCP
auditkit scan -provider gcp -framework 800-53

# Generate report
auditkit scan -provider aws -framework 800-53 -format pdf -output nist-report.pdf

Output shows:

[FAIL] IA-2, IA-2(1), IA-5 - Authentication Controls (via CC6.6)
  Issue: 12 users without MFA enabled
  Source: SOC2 CC6.6 maps to NIST IA-2

[PASS] AU-2, AU-3, AU-12 - Audit Logging (via CC7.1)
  Source: SOC2 CC7.1 maps to NIST AU-2

FedRAMP Baselines

NIST 800-53 is used by FedRAMP (Federal Risk and Authorization Management Program) for cloud services.

FedRAMP LOW

  • 149 controls
  • Low-impact data
  • Public information

FedRAMP MODERATE

  • 287 controls
  • Moderate-impact data
  • Most common baseline

FedRAMP HIGH

  • 370 controls
  • High-impact data
  • National security systems

Note: AuditKit helps with technical controls, but FedRAMP requires full 800-53 implementation including all organizational controls.

800-53 vs Other Frameworks

Framework Total Controls Automated by AuditKit
NIST 800-53 1,196 149 (12%)
SOC2 43 criteria 38 on AWS (88%)
PCI-DSS 312 requirements 71 (23%)
CMMC Level 2 110 practices 13 in Community, 42 cloud-queried in Pro

Key insight: SOC2/PCI-DSS/CMMC are subsets of 800-53. Pass those, you're partway to 800-53 compliance.

Common Use Cases

Federal Contractor

Need: NIST 800-53 compliance for FISMA

AuditKit approach: 1. Scan for automated technical controls (~150) 2. Document organizational controls manually (about 1,050) 3. Use scan results as evidence for technical controls 4. Complete remaining documentation

FedRAMP Applicant

Need: FedRAMP authorization

AuditKit approach: 1. Start with SOC2 or CMMC (smaller scope) 2. Use 800-53 scan to see gaps 3. Work with FedRAMP 3PAO for full assessment 4. AuditKit provides technical control evidence

CMMC + Federal Work

Need: CMMC Level 2 + NIST 800-53

AuditKit approach: 1. Use Pro for CMMC Level 2 (110 practices) 2. Run 800-53 scan to see additional gaps 3. CMMC Level 2 covers ~30% of 800-53 technical controls 4. Document remaining controls

Cost Estimate

NIST 800-53 compliance costs vary widely:

Item Cost (Estimate)
AuditKit Free $0
Gap assessment $10,000 - $50,000
Implementation $50,000 - $500,000
Consulting $100,000 - $1,000,000
FedRAMP 3PAO (if applicable) $250,000 - $1,500,000

Timeline: 12-24 months for full implementation

Note: These are estimates. Actual costs depend on organization size and current security posture.

FAQ

Q: Is NIST 800-53 a certification?
A: No. It's a control catalog used by FedRAMP, FISMA, and other compliance programs.

Q: Do I need all 1,000 controls?
A: No. Tailor based on your system's impact level (LOW/MODERATE/HIGH).

Q: Can AuditKit help with FedRAMP?
A: Yes, for technical controls. You'll still need organizational documentation and 3PAO assessment.

Q: What's the difference between Rev 4 and Rev 5?
A: Rev 5 (2020) added supply chain, privacy controls, and reorganized families. AuditKit uses Rev 5.

Q: Should I start with 800-53 or SOC2?
A: Start with SOC2. It's faster, cheaper, and maps to 800-53 technical controls.

Next Steps

Scan your environment

Point AuditKit at AWS, Azure or GCP with read-only credentials and get every finding with the command to fix it. Full results in about thirty minutes.

Start 14-Day Free Trial

$297/month after the trial. Cancel any time. The Community Edition is free and open source.