Skip to content

    CMMC Level 2 to NIST SP 800-53 Rev 5 control mapping

    CMMC Level 2 maps to 218 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the CMMC Level 2 controls that map to it.

    Shared NIST 800-53 controls
    218
    CMMC Level 2 controls involved
    110
    NIST 800-53 families touched
    20

    How this pairing is derived

    NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored CMMC Level 2 to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls that CMMC Level 2 maps to, with the CMMC Level 2 controls that map to each one.
    NIST 800-53 controlFamilyCMMC Level 2 controls
    AC-1Policy and ProceduresACAccess ControlAC.L1-3.1.1
    AC-2Account ManagementACAccess ControlAC.L1-3.1.2
    AC-2(1)Automated System Account ManagementACAccess ControlAC.L1-3.1.1, IA.L1-3.5.1, IA.L1-3.5.2
    AC-2(3)Disable AccountsACAccess ControlIA.L2-3.5.6
    AC-2(5)Inactivity LogoutACAccess ControlAC.L2-3.1.10
    AC-2(7)Privileged User AccountsACAccess ControlAC.L1-3.1.1, AC.L1-3.1.2, AC.L2-3.1.3
    AC-2(12)Account Monitoring for Atypical UsageACAccess ControlSI.L2-3.14.7
    AC-3Access EnforcementACAccess ControlAC.L1-3.1.1
    AC-4Information Flow EnforcementACAccess ControlAC.L2-3.1.3
    AC-4(21)Physical or Logical Separation of Information FlowsACAccess ControlSC.L1-3.13.5
    AC-5Separation of DutiesACAccess ControlAC.L2-3.1.4
    AC-6Least PrivilegeACAccess ControlAC.L1-3.1.1, AC.L2-3.1.5
    AC-6(1)Authorize Access to Security FunctionsACAccess ControlAC.L2-3.1.5
    AC-6(2)Non-privileged Access for Nonsecurity FunctionsACAccess ControlAC.L2-3.1.6
    AC-6(5)Privileged AccountsACAccess ControlAC.L2-3.1.5
    AC-6(9)Log Use of Privileged FunctionsACAccess ControlAC.L2-3.1.7
    AC-6(10)Prohibit Non-privileged Users from Executing Privileged FunctionsACAccess ControlAC.L2-3.1.7
    AC-7Unsuccessful Logon AttemptsACAccess ControlAC.L2-3.1.8
    AC-8System Use NotificationACAccess ControlAC.L2-3.1.9
    AC-11Device LockACAccess ControlAC.L2-3.1.10
    AC-11(1)Pattern-hiding DisplaysACAccess ControlAC.L2-3.1.10
    AC-12Session TerminationACAccess ControlAC.L2-3.1.11
    AC-17Remote AccessACAccess ControlAC.L2-3.1.12
    AC-17(1)Monitoring and ControlACAccess ControlAC.L2-3.1.12
    AC-17(2)Protection of Confidentiality and Integrity Using EncryptionACAccess ControlAC.L2-3.1.13
    AC-17(3)Managed Access Control PointsACAccess ControlAC.L2-3.1.14
    AC-17(4)Privileged Commands and AccessACAccess ControlAC.L2-3.1.15
    AC-17(6)Protection of Mechanism InformationACAccess ControlAC.L2-3.1.12
    AC-18Wireless AccessACAccess ControlAC.L2-3.1.16
    AC-18(1)Authentication and EncryptionACAccess ControlAC.L2-3.1.17
    AC-19Access Control for Mobile DevicesACAccess ControlAC.L2-3.1.18
    AC-19(5)Full Device or Container-based EncryptionACAccess ControlAC.L2-3.1.19
    AC-20Use of External SystemsACAccess ControlAC.L1-3.1.20
    AC-20(1)Limits on Authorized UseACAccess ControlAC.L1-3.1.20
    AC-20(2)Portable Storage Devices — Restricted UseACAccess ControlAC.L2-3.1.21
    AC-20(5)Portable Storage Devices — Prohibited UseACAccess ControlAC.L2-3.1.21
    AC-22Publicly Accessible ContentACAccess ControlAC.L1-3.1.22
    AT-2Literacy Training and AwarenessATAwareness and TrainingAT.L2-3.2.1
    AT-2(2)Insider ThreatATAwareness and TrainingAT.L2-3.2.3
    AT-2(6)Cyber Threat EnvironmentATAwareness and TrainingAT.L2-3.2.3
    AT-3Role-based TrainingATAwareness and TrainingAT.L2-3.2.2
    AT-3(2)Physical Security ControlsATAwareness and TrainingAT.L2-3.2.2
    AU-1Policy and ProceduresAUAudit and AccountabilityAU.L2-3.3.3, SI.L2-3.14.6
    AU-2Event LoggingAUAudit and AccountabilityAU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9, SI.L2-3.14.3
    AU-3Content of Audit RecordsAUAudit and AccountabilityAU.L2-3.3.2
    AU-3(1)Additional Audit InformationAUAudit and AccountabilityAU.L2-3.3.8
    AU-5Response to Audit Logging Process FailuresAUAudit and AccountabilityAU.L2-3.3.4
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and AccountabilityAU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9
    AU-6(1)Automated Process IntegrationAUAudit and AccountabilityAU.L2-3.3.8
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and AccountabilityAU.L2-3.3.5, SI.L2-3.14.7
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and AccountabilityAU.L2-3.3.5, SI.L2-3.14.7
    AU-7Audit Record Reduction and Report GenerationAUAudit and AccountabilityAU.L2-3.3.6
    AU-7(1)Automatic ProcessingAUAudit and AccountabilityAU.L2-3.3.6
    AU-8Time StampsAUAudit and AccountabilityAU.L2-3.3.7
    AU-9Protection of Audit InformationAUAudit and AccountabilityAU.L2-3.3.8
    AU-9(4)Access by Subset of Privileged UsersAUAudit and AccountabilityAU.L2-3.3.9
    AU-11Audit Record RetentionAUAudit and AccountabilityAU.L2-3.3.1
    AU-12Audit Record GenerationAUAudit and AccountabilityAU.L2-3.3.6
    CA-2Control AssessmentsCAAssessment, Authorization, and MonitoringCA.L2-3.12.1
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and MonitoringCA.L2-3.12.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringCA.L2-3.12.1, CA.L2-3.12.3
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringCA.L2-3.12.1, CA.L2-3.12.3
    CM-2Baseline ConfigurationCMConfiguration ManagementAU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2
    CM-3Configuration Change ControlCMConfiguration ManagementCM.L2-3.4.3
    CM-4Impact AnalysesCMConfiguration ManagementCM.L2-3.4.4
    CM-4(1)Separate Test EnvironmentsCMConfiguration ManagementCM.L2-3.4.5
    CM-5Access Restrictions for ChangeCMConfiguration ManagementCM.L2-3.4.5
    CM-6Configuration SettingsCMConfiguration ManagementAU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2
    CM-7Least FunctionalityCMConfiguration ManagementCM.L2-3.4.6
    CM-7(1)Periodic ReviewCMConfiguration ManagementCM.L2-3.4.7
    CM-7(2)Prevent Program ExecutionCMConfiguration ManagementCM.L2-3.4.7
    CM-7(4)Unauthorized Software — Deny-by-exceptionCMConfiguration ManagementCM.L2-3.4.8
    CM-7(5)Authorized Software — Allow-by-exceptionCMConfiguration ManagementCM.L2-3.4.8
    CM-8System Component InventoryCMConfiguration ManagementCM.L2-3.4.1
    CM-11User-installed SoftwareCMConfiguration ManagementCM.L2-3.4.9
    CM-11(2)Software Installation with Privileged StatusCMConfiguration ManagementCM.L2-3.4.9
    CP-9System BackupCPContingency PlanningMP.L2-3.8.9
    CP-9(8)Cryptographic ProtectionCPContingency PlanningMP.L2-3.8.9
    IA-1Policy and ProceduresIAIdentification and AuthenticationAC.L1-3.1.1
    IA-2Identification and Authentication (Organizational Users)IAIdentification and AuthenticationAC.L1-3.1.1, IA.L1-3.5.1, IA.L1-3.5.2
    IA-2(1)Multi-factor Authentication to Privileged AccountsIAIdentification and AuthenticationIA.L2-3.5.3, MA.L2-3.7.5
    IA-2(2)Multi-factor Authentication to Non-privileged AccountsIAIdentification and AuthenticationIA.L2-3.5.3, MA.L2-3.7.5
    IA-2(8)Access to Accounts — Replay ResistantIAIdentification and AuthenticationIA.L2-3.5.4
    IA-3Device Identification and AuthenticationIAIdentification and AuthenticationIA.L1-3.5.1, IA.L1-3.5.2
    IA-3(1)Cryptographic Bidirectional AuthenticationIAIdentification and AuthenticationIA.L1-3.5.1, IA.L1-3.5.2
    IA-3(4)Device AttestationIAIdentification and AuthenticationIA.L1-3.5.1, IA.L1-3.5.2
    IA-4Identifier ManagementIAIdentification and AuthenticationIA.L2-3.5.5
    IA-5Authenticator ManagementIAIdentification and AuthenticationIA.L2-3.5.8, IA.L2-3.5.9
    IA-5(1)Password-based AuthenticationIAIdentification and AuthenticationIA.L2-3.5.7, IA.L2-3.5.8, IA.L2-3.5.9
    IA-5(6)Protection of AuthenticatorsIAIdentification and AuthenticationIA.L2-3.5.10
    IA-6Authentication FeedbackIAIdentification and AuthenticationIA.L2-3.5.11
    IR-2Incident Response TrainingIRIncident ResponseIR.L2-3.6.1
    IR-2(3)BreachIRIncident ResponseIR.L2-3.6.1
    IR-3Incident Response TestingIRIncident ResponseIR.L2-3.6.3
    IR-4Incident HandlingIRIncident ResponseIR.L2-3.6.1, IR.L2-3.6.2
    IR-4(4)Information CorrelationIRIncident ResponseAU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9, SI.L2-3.14.7
    IR-4(13)Behavior AnalysisIRIncident ResponseSI.L2-3.14.7
    MA-2Controlled MaintenanceMAMaintenanceMA.L2-3.7.1
    MA-3Maintenance ToolsMAMaintenanceMA.L2-3.7.2
    MA-3(2)Inspect MediaMAMaintenanceMA.L2-3.7.4
    MA-3(5)Execution with PrivilegeMAMaintenanceMA.L2-3.7.2
    MA-3(6)Software Updates and PatchesMAMaintenanceMA.L2-3.7.2
    MA-4Nonlocal MaintenanceMAMaintenanceMA.L2-3.7.5
    MA-4(7)Disconnect VerificationMAMaintenanceMA.L2-3.7.5
    MA-5Maintenance PersonnelMAMaintenanceMA.L2-3.7.6
    MA-5(1)Individuals Without Appropriate AccessMAMaintenanceMA.L2-3.7.6
    MA-5(2)Security Clearances for Classified SystemsMAMaintenanceMA.L2-3.7.6
    MA-5(3)Citizenship Requirements for Classified SystemsMAMaintenanceMA.L2-3.7.6
    MA-5(4)Foreign NationalsMAMaintenanceMA.L2-3.7.6
    MA-5(5)Non-system MaintenanceMAMaintenanceMA.L2-3.7.6
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionPE.L2-3.10.2
    PE-2Physical Access AuthorizationsPEPhysical and Environmental ProtectionPE.L1-3.10.1
    PE-2(1)Access by Position or RolePEPhysical and Environmental ProtectionPE.L1-3.10.1
    PE-2(3)Restrict Unescorted AccessPEPhysical and Environmental ProtectionPE.L1-3.10.3
    PE-3Physical Access ControlPEPhysical and Environmental ProtectionPE.L1-3.10.3, PE.L1-3.10.5
    PE-3(1)System AccessPEPhysical and Environmental ProtectionPE.L1-3.10.1
    PE-3(2)Facility and SystemsPEPhysical and Environmental ProtectionPE.L1-3.10.3, PE.L1-3.10.5
    PE-3(3)Continuous GuardsPEPhysical and Environmental ProtectionPE.L1-3.10.3, PE.L1-3.10.5
    PE-4Access Control for TransmissionPEPhysical and Environmental ProtectionPE.L1-3.10.1
    PE-5Access Control for Output DevicesPEPhysical and Environmental ProtectionPE.L1-3.10.1
    PE-6Monitoring Physical AccessPEPhysical and Environmental ProtectionPE.L2-3.10.2
    PE-6(1)Intrusion Alarms and Surveillance EquipmentPEPhysical and Environmental ProtectionPE.L2-3.10.2
    PE-6(4)Monitoring Physical Access to SystemsPEPhysical and Environmental ProtectionPE.L2-3.10.2
    PE-8Visitor Access RecordsPEPhysical and Environmental ProtectionPE.L1-3.10.4
    PE-17Alternate Work SitePEPhysical and Environmental ProtectionPE.L2-3.10.6
    PE-18Location of System ComponentsPEPhysical and Environmental ProtectionPE.L1-3.10.1
    PE-23Facility LocationPEPhysical and Environmental ProtectionPE.L1-3.10.1, PE.L2-3.10.2
    PL-2System Security and Privacy PlansPLPlanningCA.L2-3.12.4
    PL-4Rules of BehaviorPLPlanningAC.L1-3.1.22
    PL-4(1)Social Media and External Site/Application Usage RestrictionsPLPlanningAC.L1-3.1.22
    PL-8(1)Defense in DepthPLPlanningSC.L2-3.13.2
    PL-10Baseline SelectionPLPlanningAU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2
    PL-11Baseline TailoringPLPlanningAU.L2-3.3.3
    RA-3Risk AssessmentRARisk AssessmentRA.L2-3.11.1
    RA-5Vulnerability Monitoring and ScanningRARisk AssessmentRA.L2-3.11.2
    RA-5(5)Privileged AccessRARisk AssessmentRA.L2-3.11.2
    SA-4Acquisition ProcessSASystem and Services AcquisitionAC.L1-3.1.1
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services AcquisitionAU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2, SC.L2-3.13.2
    SA-8(14)Least PrivilegeSASystem and Services AcquisitionAC.L2-3.1.5
    SA-8(31)Secure System ModificationSASystem and Services AcquisitionCM.L2-3.4.3
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services AcquisitionCA.L2-3.12.2
    SA-15(5)Attack Surface ReductionSASystem and Services AcquisitionAU.L2-3.3.3, CM.L2-3.4.1, CM.L2-3.4.2, SC.L2-3.13.2
    SC-1Policy and ProceduresSCSystem and Communications ProtectionSC.L1-3.13.1, SC.L2-3.13.2
    SC-2Separation of System and User FunctionalitySCSystem and Communications ProtectionSC.L2-3.13.3
    SC-2(1)Interfaces for Non-privileged UsersSCSystem and Communications ProtectionSC.L2-3.13.3
    SC-3(5)Layered StructuresSCSystem and Communications ProtectionSC.L2-3.13.2
    SC-4Information in Shared System ResourcesSCSystem and Communications ProtectionSC.L2-3.13.4
    SC-7Boundary ProtectionSCSystem and Communications ProtectionSC.L1-3.13.1
    SC-7(5)Deny by Default — Allow by ExceptionSCSystem and Communications ProtectionSC.L2-3.13.6
    SC-7(7)Split Tunneling for Remote DevicesSCSystem and Communications ProtectionSC.L2-3.13.7
    SC-7(8)Route Traffic to Authenticated Proxy ServersSCSystem and Communications ProtectionAC.L2-3.1.3
    SC-7(9)Restrict Threatening Outgoing Communications TrafficSCSystem and Communications ProtectionSC.L1-3.13.1
    SC-7(11)Restrict Incoming Communications TrafficSCSystem and Communications ProtectionSC.L1-3.13.1, SC.L2-3.13.6
    SC-7(14)Protect Against Unauthorized Physical ConnectionsSCSystem and Communications ProtectionPE.L1-3.10.1
    SC-7(18)Fail SecureSCSystem and Communications ProtectionSC.L2-3.13.2
    SC-7(29)Separate Subnets to Isolate FunctionsSCSystem and Communications ProtectionSC.L2-3.13.2
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications ProtectionSC.L2-3.13.8
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionMP.L2-3.8.6, SC.L2-3.13.11, SC.L2-3.13.8
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionMP.L2-3.8.7, SC.L2-3.13.11
    SC-8(3)Cryptographic Protection for Message ExternalsSCSystem and Communications ProtectionSC.L2-3.13.14
    SC-10Network DisconnectSCSystem and Communications ProtectionSC.L2-3.13.9
    SC-12Cryptographic Key Establishment and ManagementSCSystem and Communications ProtectionSC.L2-3.13.10
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionMP.L2-3.8.6, SC.L2-3.13.11, SC.L2-3.13.16
    SC-15Collaborative Computing Devices and ApplicationsSCSystem and Communications ProtectionSC.L2-3.13.12
    SC-15(1)Physical or Logical DisconnectSCSystem and Communications ProtectionSC.L2-3.13.12
    SC-17Public Key Infrastructure CertificatesSCSystem and Communications ProtectionSC.L2-3.13.10
    SC-18Mobile CodeSCSystem and Communications ProtectionSC.L2-3.13.13
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications ProtectionRA.L2-3.11.3, SC.L2-3.13.13, SI.L1-3.14.1
    SC-18(2)Acquisition, Development, and UseSCSystem and Communications ProtectionSC.L2-3.13.13
    SC-18(3)Prevent Downloading and ExecutionSCSystem and Communications ProtectionAC.L2-3.1.3, SC.L2-3.13.13
    SC-18(4)Prevent Automatic ExecutionSCSystem and Communications ProtectionCM.L2-3.4.8, SC.L2-3.13.13
    SC-23Session AuthenticitySCSystem and Communications ProtectionSC.L2-3.13.15
    SC-27Platform-independent ApplicationsSCSystem and Communications ProtectionSC.L2-3.13.13
    SC-28Protection of Information at RestSCSystem and Communications ProtectionMP.L2-3.8.6, SC.L2-3.13.16
    SC-28(1)Cryptographic ProtectionSCSystem and Communications ProtectionMP.L2-3.8.6, MP.L2-3.8.9, SC.L2-3.13.16
    SC-28(2)Offline StorageSCSystem and Communications ProtectionMP.L2-3.8.9
    SC-28(3)Cryptographic KeysSCSystem and Communications ProtectionSC.L2-3.13.10
    SC-45System Time SynchronizationSCSystem and Communications ProtectionAU.L2-3.3.7
    SC-45(1)Synchronization with Authoritative Time SourceSCSystem and Communications ProtectionAU.L2-3.3.7
    SI-1Policy and ProceduresSISystem and Information IntegritySC.L2-3.13.2
    SI-2Flaw RemediationSISystem and Information IntegrityRA.L2-3.11.3, SI.L1-3.14.1, SI.L1-3.14.4
    SI-2(4)Automated Patch Management ToolsSISystem and Information IntegrityRA.L2-3.11.3, SI.L1-3.14.1
    SI-3Malicious Code ProtectionSISystem and Information IntegrityRA.L2-3.11.3, SI.L1-3.14.1, SI.L1-3.14.2, SI.L1-3.14.4, SI.L1-3.14.5
    SI-4System MonitoringSISystem and Information IntegrityAU.L2-3.3.1, AU.L2-3.3.3, AU.L2-3.3.5, AU.L2-3.3.6, AU.L2-3.3.8, AU.L2-3.3.9, SI.L2-3.14.6
    SI-4(4)Inbound and Outbound Communications TrafficSISystem and Information IntegritySI.L2-3.14.6
    SI-4(9)Testing of Monitoring Tools and MechanismsSISystem and Information IntegrityIR.L2-3.6.3
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information IntegritySI.L2-3.14.7
    SI-4(16)Correlate Monitoring InformationSISystem and Information IntegrityAU.L2-3.3.5, SI.L2-3.14.7
    SI-4(24)Indicators of CompromiseSISystem and Information IntegritySI.L2-3.14.7
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information IntegrityCA.L2-3.12.3, SI.L2-3.14.3
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information IntegrityCA.L2-3.12.3, SI.L2-3.14.3
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegritySC.L2-3.13.11
    MP-1Policy and ProceduresMPMedia ProtectionMP.L1-3.8.3, MP.L2-3.8.1
    MP-2Media AccessMPMedia ProtectionAC.L2-3.1.3, MP.L2-3.8.2, SI.L1-3.14.2
    MP-3Media MarkingMPMedia ProtectionMP.L2-3.8.4
    MP-4Media StorageMPMedia ProtectionMP.L2-3.8.1
    MP-5Media TransportMPMedia ProtectionMP.L2-3.8.5
    MP-6Media SanitizationMPMedia ProtectionMA.L2-3.7.3, MP.L1-3.8.3
    MP-6(3)Nondestructive TechniquesMPMedia ProtectionMA.L2-3.7.3, MP.L1-3.8.3
    MP-7Media UseMPMedia ProtectionMP.L2-3.8.7, MP.L2-3.8.8
    PS-1Policy and ProceduresPSPersonnel SecurityAC.L1-3.1.22
    PS-3Personnel ScreeningPSPersonnel SecurityPS.L2-3.9.1
    PS-3(1)Classified InformationPSPersonnel SecurityPS.L2-3.9.1
    PS-3(2)Formal IndoctrinationPSPersonnel SecurityAT.L2-3.2.1, AT.L2-3.2.2
    PS-3(3)Information Requiring Special Protective MeasuresPSPersonnel SecurityPS.L2-3.9.1
    PS-4Personnel TerminationPSPersonnel SecurityPS.L2-3.9.2
    PS-5Personnel TransferPSPersonnel SecurityPS.L2-3.9.2
    PM-4Plan of Action and Milestones ProcessPMProgram ManagementCA.L2-3.12.2, SI.L1-3.14.1
    PM-5System InventoryPMProgram ManagementCM.L2-3.4.1, MP.L1-3.8.3
    PM-14Testing, Training, and MonitoringPMProgram ManagementCA.L2-3.12.1, CA.L2-3.12.3
    PM-15Security and Privacy Groups and AssociationsPMProgram ManagementCA.L2-3.12.3, SI.L2-3.14.3
    PM-16Threat Awareness ProgramPMProgram ManagementCA.L2-3.12.3, SI.L2-3.14.3
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram ManagementCA.L2-3.12.3, SI.L2-3.14.3
    PM-31Continuous Monitoring StrategyPMProgram ManagementAU.L2-3.3.3, SI.L2-3.14.6
    PT-1Policy and ProceduresPTPII Processing and TransparencySC.L2-3.13.2
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementAC.L1-3.1.1
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk ManagementAC.L1-3.1.1
    SR-12Component DisposalSRSupply Chain Risk ManagementMP.L1-3.8.3

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.