NIST SP 800-171 Rev 2 to NIST SP 800-53 Rev 5 control mapping
NIST SP 800-171 Rev 2 maps to 218 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the NIST SP 800-171 Rev 2 controls that map to it.
- Shared NIST 800-53 controls
- 218
- NIST SP 800-171 Rev 2 controls involved
- 110
- NIST 800-53 families touched
- 20
How this pairing is derived
NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored NIST SP 800-171 Rev 2 to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.
Shared controls in full
| NIST 800-53 control | Family | NIST SP 800-171 Rev 2 controls |
|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | 3.1.1 |
| AC-2Account Management | ACAccess Control | 3.1.2 |
| AC-2(1)Automated System Account Management | ACAccess Control | 3.1.1, 3.5.1, 3.5.2 |
| AC-2(3)Disable Accounts | ACAccess Control | 3.5.6 |
| AC-2(5)Inactivity Logout | ACAccess Control | 3.1.10 |
| AC-2(7)Privileged User Accounts | ACAccess Control | 3.1.1, 3.1.2, 3.1.3 |
| AC-2(12)Account Monitoring for Atypical Usage | ACAccess Control | 3.14.7 |
| AC-3Access Enforcement | ACAccess Control | 3.1.1 |
| AC-4Information Flow Enforcement | ACAccess Control | 3.1.3 |
| AC-4(21)Physical or Logical Separation of Information Flows | ACAccess Control | 3.13.5 |
| AC-5Separation of Duties | ACAccess Control | 3.1.4 |
| AC-6Least Privilege | ACAccess Control | 3.1.1, 3.1.5 |
| AC-6(1)Authorize Access to Security Functions | ACAccess Control | 3.1.5 |
| AC-6(2)Non-privileged Access for Nonsecurity Functions | ACAccess Control | 3.1.6 |
| AC-6(5)Privileged Accounts | ACAccess Control | 3.1.5 |
| AC-6(9)Log Use of Privileged Functions | ACAccess Control | 3.1.7 |
| AC-6(10)Prohibit Non-privileged Users from Executing Privileged Functions | ACAccess Control | 3.1.7 |
| AC-7Unsuccessful Logon Attempts | ACAccess Control | 3.1.8 |
| AC-8System Use Notification | ACAccess Control | 3.1.9 |
| AC-11Device Lock | ACAccess Control | 3.1.10 |
| AC-11(1)Pattern-hiding Displays | ACAccess Control | 3.1.10 |
| AC-12Session Termination | ACAccess Control | 3.1.11 |
| AC-17Remote Access | ACAccess Control | 3.1.12 |
| AC-17(1)Monitoring and Control | ACAccess Control | 3.1.12 |
| AC-17(2)Protection of Confidentiality and Integrity Using Encryption | ACAccess Control | 3.1.13 |
| AC-17(3)Managed Access Control Points | ACAccess Control | 3.1.14 |
| AC-17(4)Privileged Commands and Access | ACAccess Control | 3.1.15 |
| AC-17(6)Protection of Mechanism Information | ACAccess Control | 3.1.12 |
| AC-18Wireless Access | ACAccess Control | 3.1.16 |
| AC-18(1)Authentication and Encryption | ACAccess Control | 3.1.17 |
| AC-19Access Control for Mobile Devices | ACAccess Control | 3.1.18 |
| AC-19(5)Full Device or Container-based Encryption | ACAccess Control | 3.1.19 |
| AC-20Use of External Systems | ACAccess Control | 3.1.20 |
| AC-20(1)Limits on Authorized Use | ACAccess Control | 3.1.20 |
| AC-20(2)Portable Storage Devices — Restricted Use | ACAccess Control | 3.1.21 |
| AC-20(5)Portable Storage Devices — Prohibited Use | ACAccess Control | 3.1.21 |
| AC-22Publicly Accessible Content | ACAccess Control | 3.1.22 |
| AT-2Literacy Training and Awareness | ATAwareness and Training | 3.2.1 |
| AT-2(2)Insider Threat | ATAwareness and Training | 3.2.3 |
| AT-2(6)Cyber Threat Environment | ATAwareness and Training | 3.2.3 |
| AT-3Role-based Training | ATAwareness and Training | 3.2.2 |
| AT-3(2)Physical Security Controls | ATAwareness and Training | 3.2.2 |
| AU-1Policy and Procedures | AUAudit and Accountability | 3.14.6, 3.3.3 |
| AU-2Event Logging | AUAudit and Accountability | 3.14.3, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9 |
| AU-3Content of Audit Records | AUAudit and Accountability | 3.3.2 |
| AU-3(1)Additional Audit Information | AUAudit and Accountability | 3.3.8 |
| AU-5Response to Audit Logging Process Failures | AUAudit and Accountability | 3.3.4 |
| AU-6Audit Record Review, Analysis, and Reporting | AUAudit and Accountability | 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9 |
| AU-6(1)Automated Process Integration | AUAudit and Accountability | 3.3.8 |
| AU-6(3)Correlate Audit Record Repositories | AUAudit and Accountability | 3.14.7, 3.3.5 |
| AU-6(9)Correlation with Information from Nontechnical Sources | AUAudit and Accountability | 3.14.7, 3.3.5 |
| AU-7Audit Record Reduction and Report Generation | AUAudit and Accountability | 3.3.6 |
| AU-7(1)Automatic Processing | AUAudit and Accountability | 3.3.6 |
| AU-8Time Stamps | AUAudit and Accountability | 3.3.7 |
| AU-9Protection of Audit Information | AUAudit and Accountability | 3.3.8 |
| AU-9(4)Access by Subset of Privileged Users | AUAudit and Accountability | 3.3.9 |
| AU-11Audit Record Retention | AUAudit and Accountability | 3.3.1 |
| AU-12Audit Record Generation | AUAudit and Accountability | 3.3.6 |
| CA-2Control Assessments | CAAssessment, Authorization, and Monitoring | 3.12.1 |
| CA-5Plan of Action and Milestones | CAAssessment, Authorization, and Monitoring | 3.12.2 |
| CA-7Continuous Monitoring | CAAssessment, Authorization, and Monitoring | 3.12.1, 3.12.3 |
| CA-7(1)Independent Assessment | CAAssessment, Authorization, and Monitoring | 3.12.1, 3.12.3 |
| CM-2Baseline Configuration | CMConfiguration Management | 3.3.3, 3.4.1, 3.4.2 |
| CM-3Configuration Change Control | CMConfiguration Management | 3.4.3 |
| CM-4Impact Analyses | CMConfiguration Management | 3.4.4 |
| CM-4(1)Separate Test Environments | CMConfiguration Management | 3.4.5 |
| CM-5Access Restrictions for Change | CMConfiguration Management | 3.4.5 |
| CM-6Configuration Settings | CMConfiguration Management | 3.3.3, 3.4.1, 3.4.2 |
| CM-7Least Functionality | CMConfiguration Management | 3.4.6 |
| CM-7(1)Periodic Review | CMConfiguration Management | 3.4.7 |
| CM-7(2)Prevent Program Execution | CMConfiguration Management | 3.4.7 |
| CM-7(4)Unauthorized Software — Deny-by-exception | CMConfiguration Management | 3.4.8 |
| CM-7(5)Authorized Software — Allow-by-exception | CMConfiguration Management | 3.4.8 |
| CM-8System Component Inventory | CMConfiguration Management | 3.4.1 |
| CM-11User-installed Software | CMConfiguration Management | 3.4.9 |
| CM-11(2)Software Installation with Privileged Status | CMConfiguration Management | 3.4.9 |
| CP-9System Backup | CPContingency Planning | 3.8.9 |
| CP-9(8)Cryptographic Protection | CPContingency Planning | 3.8.9 |
| IA-1Policy and Procedures | IAIdentification and Authentication | 3.1.1 |
| IA-2Identification and Authentication (Organizational Users) | IAIdentification and Authentication | 3.1.1, 3.5.1, 3.5.2 |
| IA-2(1)Multi-factor Authentication to Privileged Accounts | IAIdentification and Authentication | 3.5.3, 3.7.5 |
| IA-2(2)Multi-factor Authentication to Non-privileged Accounts | IAIdentification and Authentication | 3.5.3, 3.7.5 |
| IA-2(8)Access to Accounts — Replay Resistant | IAIdentification and Authentication | 3.5.4 |
| IA-3Device Identification and Authentication | IAIdentification and Authentication | 3.5.1, 3.5.2 |
| IA-3(1)Cryptographic Bidirectional Authentication | IAIdentification and Authentication | 3.5.1, 3.5.2 |
| IA-3(4)Device Attestation | IAIdentification and Authentication | 3.5.1, 3.5.2 |
| IA-4Identifier Management | IAIdentification and Authentication | 3.5.5 |
| IA-5Authenticator Management | IAIdentification and Authentication | 3.5.8, 3.5.9 |
| IA-5(1)Password-based Authentication | IAIdentification and Authentication | 3.5.7, 3.5.8, 3.5.9 |
| IA-5(6)Protection of Authenticators | IAIdentification and Authentication | 3.5.10 |
| IA-6Authentication Feedback | IAIdentification and Authentication | 3.5.11 |
| IR-2Incident Response Training | IRIncident Response | 3.6.1 |
| IR-2(3)Breach | IRIncident Response | 3.6.1 |
| IR-3Incident Response Testing | IRIncident Response | 3.6.3 |
| IR-4Incident Handling | IRIncident Response | 3.6.1, 3.6.2 |
| IR-4(4)Information Correlation | IRIncident Response | 3.14.7, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9 |
| IR-4(13)Behavior Analysis | IRIncident Response | 3.14.7 |
| MA-2Controlled Maintenance | MAMaintenance | 3.7.1 |
| MA-3Maintenance Tools | MAMaintenance | 3.7.2 |
| MA-3(2)Inspect Media | MAMaintenance | 3.7.4 |
| MA-3(5)Execution with Privilege | MAMaintenance | 3.7.2 |
| MA-3(6)Software Updates and Patches | MAMaintenance | 3.7.2 |
| MA-4Nonlocal Maintenance | MAMaintenance | 3.7.5 |
| MA-4(7)Disconnect Verification | MAMaintenance | 3.7.5 |
| MA-5Maintenance Personnel | MAMaintenance | 3.7.6 |
| MA-5(1)Individuals Without Appropriate Access | MAMaintenance | 3.7.6 |
| MA-5(2)Security Clearances for Classified Systems | MAMaintenance | 3.7.6 |
| MA-5(3)Citizenship Requirements for Classified Systems | MAMaintenance | 3.7.6 |
| MA-5(4)Foreign Nationals | MAMaintenance | 3.7.6 |
| MA-5(5)Non-system Maintenance | MAMaintenance | 3.7.6 |
| PE-1Policy and Procedures | PEPhysical and Environmental Protection | 3.10.2 |
| PE-2Physical Access Authorizations | PEPhysical and Environmental Protection | 3.10.1 |
| PE-2(1)Access by Position or Role | PEPhysical and Environmental Protection | 3.10.1 |
| PE-2(3)Restrict Unescorted Access | PEPhysical and Environmental Protection | 3.10.3 |
| PE-3Physical Access Control | PEPhysical and Environmental Protection | 3.10.3, 3.10.5 |
| PE-3(1)System Access | PEPhysical and Environmental Protection | 3.10.1 |
| PE-3(2)Facility and Systems | PEPhysical and Environmental Protection | 3.10.3, 3.10.5 |
| PE-3(3)Continuous Guards | PEPhysical and Environmental Protection | 3.10.3, 3.10.5 |
| PE-4Access Control for Transmission | PEPhysical and Environmental Protection | 3.10.1 |
| PE-5Access Control for Output Devices | PEPhysical and Environmental Protection | 3.10.1 |
| PE-6Monitoring Physical Access | PEPhysical and Environmental Protection | 3.10.2 |
| PE-6(1)Intrusion Alarms and Surveillance Equipment | PEPhysical and Environmental Protection | 3.10.2 |
| PE-6(4)Monitoring Physical Access to Systems | PEPhysical and Environmental Protection | 3.10.2 |
| PE-8Visitor Access Records | PEPhysical and Environmental Protection | 3.10.4 |
| PE-17Alternate Work Site | PEPhysical and Environmental Protection | 3.10.6 |
| PE-18Location of System Components | PEPhysical and Environmental Protection | 3.10.1 |
| PE-23Facility Location | PEPhysical and Environmental Protection | 3.10.1, 3.10.2 |
| PL-2System Security and Privacy Plans | PLPlanning | 3.12.4 |
| PL-4Rules of Behavior | PLPlanning | 3.1.22 |
| PL-4(1)Social Media and External Site/Application Usage Restrictions | PLPlanning | 3.1.22 |
| PL-8(1)Defense in Depth | PLPlanning | 3.13.2 |
| PL-10Baseline Selection | PLPlanning | 3.3.3, 3.4.1, 3.4.2 |
| PL-11Baseline Tailoring | PLPlanning | 3.3.3 |
| RA-3Risk Assessment | RARisk Assessment | 3.11.1 |
| RA-5Vulnerability Monitoring and Scanning | RARisk Assessment | 3.11.2 |
| RA-5(5)Privileged Access | RARisk Assessment | 3.11.2 |
| SA-4Acquisition Process | SASystem and Services Acquisition | 3.1.1 |
| SA-8Security and Privacy Engineering Principles | SASystem and Services Acquisition | 3.13.2, 3.3.3, 3.4.1, 3.4.2 |
| SA-8(14)Least Privilege | SASystem and Services Acquisition | 3.1.5 |
| SA-8(31)Secure System Modification | SASystem and Services Acquisition | 3.4.3 |
| SA-15(2)Security and Privacy Tracking Tools | SASystem and Services Acquisition | 3.12.2 |
| SA-15(5)Attack Surface Reduction | SASystem and Services Acquisition | 3.13.2, 3.3.3, 3.4.1, 3.4.2 |
| SC-1Policy and Procedures | SCSystem and Communications Protection | 3.13.1, 3.13.2 |
| SC-2Separation of System and User Functionality | SCSystem and Communications Protection | 3.13.3 |
| SC-2(1)Interfaces for Non-privileged Users | SCSystem and Communications Protection | 3.13.3 |
| SC-3(5)Layered Structures | SCSystem and Communications Protection | 3.13.2 |
| SC-4Information in Shared System Resources | SCSystem and Communications Protection | 3.13.4 |
| SC-7Boundary Protection | SCSystem and Communications Protection | 3.13.1 |
| SC-7(5)Deny by Default — Allow by Exception | SCSystem and Communications Protection | 3.13.6 |
| SC-7(7)Split Tunneling for Remote Devices | SCSystem and Communications Protection | 3.13.7 |
| SC-7(8)Route Traffic to Authenticated Proxy Servers | SCSystem and Communications Protection | 3.1.3 |
| SC-7(9)Restrict Threatening Outgoing Communications Traffic | SCSystem and Communications Protection | 3.13.1 |
| SC-7(11)Restrict Incoming Communications Traffic | SCSystem and Communications Protection | 3.13.1, 3.13.6 |
| SC-7(14)Protect Against Unauthorized Physical Connections | SCSystem and Communications Protection | 3.10.1 |
| SC-7(18)Fail Secure | SCSystem and Communications Protection | 3.13.2 |
| SC-7(29)Separate Subnets to Isolate Functions | SCSystem and Communications Protection | 3.13.2 |
| SC-8Transmission Confidentiality and Integrity | SCSystem and Communications Protection | 3.13.8 |
| SC-8(1)Cryptographic Protection | SCSystem and Communications Protection | 3.13.11, 3.13.8, 3.8.6 |
| SC-8(2)Pre- and Post-transmission Handling | SCSystem and Communications Protection | 3.13.11, 3.8.7 |
| SC-8(3)Cryptographic Protection for Message Externals | SCSystem and Communications Protection | 3.13.14 |
| SC-10Network Disconnect | SCSystem and Communications Protection | 3.13.9 |
| SC-12Cryptographic Key Establishment and Management | SCSystem and Communications Protection | 3.13.10 |
| SC-13Cryptographic Protection | SCSystem and Communications Protection | 3.13.11, 3.13.16, 3.8.6 |
| SC-15Collaborative Computing Devices and Applications | SCSystem and Communications Protection | 3.13.12 |
| SC-15(1)Physical or Logical Disconnect | SCSystem and Communications Protection | 3.13.12 |
| SC-17Public Key Infrastructure Certificates | SCSystem and Communications Protection | 3.13.10 |
| SC-18Mobile Code | SCSystem and Communications Protection | 3.13.13 |
| SC-18(1)Identify Unacceptable Code and Take Corrective Actions | SCSystem and Communications Protection | 3.11.3, 3.13.13, 3.14.1 |
| SC-18(2)Acquisition, Development, and Use | SCSystem and Communications Protection | 3.13.13 |
| SC-18(3)Prevent Downloading and Execution | SCSystem and Communications Protection | 3.1.3, 3.13.13 |
| SC-18(4)Prevent Automatic Execution | SCSystem and Communications Protection | 3.13.13, 3.4.8 |
| SC-23Session Authenticity | SCSystem and Communications Protection | 3.13.15 |
| SC-27Platform-independent Applications | SCSystem and Communications Protection | 3.13.13 |
| SC-28Protection of Information at Rest | SCSystem and Communications Protection | 3.13.16, 3.8.6 |
| SC-28(1)Cryptographic Protection | SCSystem and Communications Protection | 3.13.16, 3.8.6, 3.8.9 |
| SC-28(2)Offline Storage | SCSystem and Communications Protection | 3.8.9 |
| SC-28(3)Cryptographic Keys | SCSystem and Communications Protection | 3.13.10 |
| SC-45System Time Synchronization | SCSystem and Communications Protection | 3.3.7 |
| SC-45(1)Synchronization with Authoritative Time Source | SCSystem and Communications Protection | 3.3.7 |
| SI-1Policy and Procedures | SISystem and Information Integrity | 3.13.2 |
| SI-2Flaw Remediation | SISystem and Information Integrity | 3.11.3, 3.14.1, 3.14.4 |
| SI-2(4)Automated Patch Management Tools | SISystem and Information Integrity | 3.11.3, 3.14.1 |
| SI-3Malicious Code Protection | SISystem and Information Integrity | 3.11.3, 3.14.1, 3.14.2, 3.14.4, 3.14.5 |
| SI-4System Monitoring | SISystem and Information Integrity | 3.14.6, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9 |
| SI-4(4)Inbound and Outbound Communications Traffic | SISystem and Information Integrity | 3.14.6 |
| SI-4(9)Testing of Monitoring Tools and Mechanisms | SISystem and Information Integrity | 3.6.3 |
| SI-4(11)Analyze Communications Traffic Anomalies | SISystem and Information Integrity | 3.14.7 |
| SI-4(16)Correlate Monitoring Information | SISystem and Information Integrity | 3.14.7, 3.3.5 |
| SI-4(24)Indicators of Compromise | SISystem and Information Integrity | 3.14.7 |
| SI-5Security Alerts, Advisories, and Directives | SISystem and Information Integrity | 3.12.3, 3.14.3 |
| SI-5(1)Automated Alerts and Advisories | SISystem and Information Integrity | 3.12.3, 3.14.3 |
| SI-7(6)Cryptographic Protection | SISystem and Information Integrity | 3.13.11 |
| MP-1Policy and Procedures | MPMedia Protection | 3.8.1, 3.8.3 |
| MP-2Media Access | MPMedia Protection | 3.1.3, 3.14.2, 3.8.2 |
| MP-3Media Marking | MPMedia Protection | 3.8.4 |
| MP-4Media Storage | MPMedia Protection | 3.8.1 |
| MP-5Media Transport | MPMedia Protection | 3.8.5 |
| MP-6Media Sanitization | MPMedia Protection | 3.7.3, 3.8.3 |
| MP-6(3)Nondestructive Techniques | MPMedia Protection | 3.7.3, 3.8.3 |
| MP-7Media Use | MPMedia Protection | 3.8.7, 3.8.8 |
| PS-1Policy and Procedures | PSPersonnel Security | 3.1.22 |
| PS-3Personnel Screening | PSPersonnel Security | 3.9.1 |
| PS-3(1)Classified Information | PSPersonnel Security | 3.9.1 |
| PS-3(2)Formal Indoctrination | PSPersonnel Security | 3.2.1, 3.2.2 |
| PS-3(3)Information Requiring Special Protective Measures | PSPersonnel Security | 3.9.1 |
| PS-4Personnel Termination | PSPersonnel Security | 3.9.2 |
| PS-5Personnel Transfer | PSPersonnel Security | 3.9.2 |
| PM-4Plan of Action and Milestones Process | PMProgram Management | 3.12.2, 3.14.1 |
| PM-5System Inventory | PMProgram Management | 3.4.1, 3.8.3 |
| PM-14Testing, Training, and Monitoring | PMProgram Management | 3.12.1, 3.12.3 |
| PM-15Security and Privacy Groups and Associations | PMProgram Management | 3.12.3, 3.14.3 |
| PM-16Threat Awareness Program | PMProgram Management | 3.12.3, 3.14.3 |
| PM-16(1)Automated Means for Sharing Threat Intelligence | PMProgram Management | 3.12.3, 3.14.3 |
| PM-31Continuous Monitoring Strategy | PMProgram Management | 3.14.6, 3.3.3 |
| PT-1Policy and Procedures | PTPII Processing and Transparency | 3.13.2 |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | 3.1.1 |
| SR-3(3)Sub-tier Flow Down | SRSupply Chain Risk Management | 3.1.1 |
| SR-12Component Disposal | SRSupply Chain Risk Management | 3.8.3 |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.
Related pairings
- PCI DSS v4.0.1 to NIST SP 800-53 Rev 5 control mapping326 shared controls
- SOC 2 Type II to NIST SP 800-53 Rev 5 control mapping301 shared controls
- NIST CSF 2.0 to NIST SP 800-53 Rev 5 control mapping233 shared controls
- CMMC Level 2 to NIST SP 800-171 Rev 2 control mapping218 shared controls
- CMMC Level 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls
- HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 Rev 5 control mapping165 shared controls