Compliance & Regulations/North America/NIST 800-53
Sovereign / National · United States (Federal); adopted globally

NIST SP 800-53

The canonical federal information system controls catalogue — the source for FedRAMP, FISMA, and most US sovereign baselines.

Regulator
National Institute of Standards and Technology
Jurisdiction
United States (Federal); adopted globally
Status
Rev 5 (with patches through Rev 5.1.1).
In force since
September 2020 (Rev 5)
Regulator's source
Who it applies to

All federal information systems and any organisation choosing the catalogue as its security baseline.

Audit / certification status

Used as the underlying control catalogue for Safeguard's own FedRAMP authorisation.

What it requires

What NIST 800-53 actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

1,189 controls across 20 control families — selected and tailored to system impact level.

02

Mandatory Risk Management Framework (NIST SP 800-37) lifecycle: Categorise → Select → Implement → Assess → Authorise → Monitor.

03

Documented control inheritance from cloud providers and shared services.

04

Continuous monitoring with automated evidence wherever feasible (per OMB M-22-09).

05

Specific overlays for privacy (Appendix J), supply chain (800-161), and AI (800-218A draft).

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Pre-mapped to Rev 5 baselines (Low / Moderate / High) with control inheritance documented per cloud provider.

OSCAL-formatted control implementation statements exportable for any inherited control.

Automated evidence harvest for ~70% of technical controls; manual attestation pipeline for the rest.

Drift detection raises any deviation from the documented baseline as a policy-gate finding.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Full OSCAL package (catalog + profile + component + assessment).

Per-control implementation statement with linked evidence artifacts.

Continuous monitoring dashboard exportable monthly.

Control inheritance matrix per shared service.

Ready for NIST 800-53?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing