Skip to content

    NIST SP 800-171 Rev 2 to NIST SP 800-53 Rev 5 control mapping

    NIST SP 800-171 Rev 2 maps to 218 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the NIST SP 800-171 Rev 2 controls that map to it.

    Shared NIST 800-53 controls
    218
    NIST SP 800-171 Rev 2 controls involved
    110
    NIST 800-53 families touched
    20

    How this pairing is derived

    NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored NIST SP 800-171 Rev 2 to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls that NIST SP 800-171 Rev 2 maps to, with the NIST SP 800-171 Rev 2 controls that map to each one.
    NIST 800-53 controlFamilyNIST SP 800-171 Rev 2 controls
    AC-1Policy and ProceduresACAccess Control3.1.1
    AC-2Account ManagementACAccess Control3.1.2
    AC-2(1)Automated System Account ManagementACAccess Control3.1.1, 3.5.1, 3.5.2
    AC-2(3)Disable AccountsACAccess Control3.5.6
    AC-2(5)Inactivity LogoutACAccess Control3.1.10
    AC-2(7)Privileged User AccountsACAccess Control3.1.1, 3.1.2, 3.1.3
    AC-2(12)Account Monitoring for Atypical UsageACAccess Control3.14.7
    AC-3Access EnforcementACAccess Control3.1.1
    AC-4Information Flow EnforcementACAccess Control3.1.3
    AC-4(21)Physical or Logical Separation of Information FlowsACAccess Control3.13.5
    AC-5Separation of DutiesACAccess Control3.1.4
    AC-6Least PrivilegeACAccess Control3.1.1, 3.1.5
    AC-6(1)Authorize Access to Security FunctionsACAccess Control3.1.5
    AC-6(2)Non-privileged Access for Nonsecurity FunctionsACAccess Control3.1.6
    AC-6(5)Privileged AccountsACAccess Control3.1.5
    AC-6(9)Log Use of Privileged FunctionsACAccess Control3.1.7
    AC-6(10)Prohibit Non-privileged Users from Executing Privileged FunctionsACAccess Control3.1.7
    AC-7Unsuccessful Logon AttemptsACAccess Control3.1.8
    AC-8System Use NotificationACAccess Control3.1.9
    AC-11Device LockACAccess Control3.1.10
    AC-11(1)Pattern-hiding DisplaysACAccess Control3.1.10
    AC-12Session TerminationACAccess Control3.1.11
    AC-17Remote AccessACAccess Control3.1.12
    AC-17(1)Monitoring and ControlACAccess Control3.1.12
    AC-17(2)Protection of Confidentiality and Integrity Using EncryptionACAccess Control3.1.13
    AC-17(3)Managed Access Control PointsACAccess Control3.1.14
    AC-17(4)Privileged Commands and AccessACAccess Control3.1.15
    AC-17(6)Protection of Mechanism InformationACAccess Control3.1.12
    AC-18Wireless AccessACAccess Control3.1.16
    AC-18(1)Authentication and EncryptionACAccess Control3.1.17
    AC-19Access Control for Mobile DevicesACAccess Control3.1.18
    AC-19(5)Full Device or Container-based EncryptionACAccess Control3.1.19
    AC-20Use of External SystemsACAccess Control3.1.20
    AC-20(1)Limits on Authorized UseACAccess Control3.1.20
    AC-20(2)Portable Storage Devices — Restricted UseACAccess Control3.1.21
    AC-20(5)Portable Storage Devices — Prohibited UseACAccess Control3.1.21
    AC-22Publicly Accessible ContentACAccess Control3.1.22
    AT-2Literacy Training and AwarenessATAwareness and Training3.2.1
    AT-2(2)Insider ThreatATAwareness and Training3.2.3
    AT-2(6)Cyber Threat EnvironmentATAwareness and Training3.2.3
    AT-3Role-based TrainingATAwareness and Training3.2.2
    AT-3(2)Physical Security ControlsATAwareness and Training3.2.2
    AU-1Policy and ProceduresAUAudit and Accountability3.14.6, 3.3.3
    AU-2Event LoggingAUAudit and Accountability3.14.3, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    AU-3Content of Audit RecordsAUAudit and Accountability3.3.2
    AU-3(1)Additional Audit InformationAUAudit and Accountability3.3.8
    AU-5Response to Audit Logging Process FailuresAUAudit and Accountability3.3.4
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and Accountability3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    AU-6(1)Automated Process IntegrationAUAudit and Accountability3.3.8
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and Accountability3.14.7, 3.3.5
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and Accountability3.14.7, 3.3.5
    AU-7Audit Record Reduction and Report GenerationAUAudit and Accountability3.3.6
    AU-7(1)Automatic ProcessingAUAudit and Accountability3.3.6
    AU-8Time StampsAUAudit and Accountability3.3.7
    AU-9Protection of Audit InformationAUAudit and Accountability3.3.8
    AU-9(4)Access by Subset of Privileged UsersAUAudit and Accountability3.3.9
    AU-11Audit Record RetentionAUAudit and Accountability3.3.1
    AU-12Audit Record GenerationAUAudit and Accountability3.3.6
    CA-2Control AssessmentsCAAssessment, Authorization, and Monitoring3.12.1
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and Monitoring3.12.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and Monitoring3.12.1, 3.12.3
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring3.12.1, 3.12.3
    CM-2Baseline ConfigurationCMConfiguration Management3.3.3, 3.4.1, 3.4.2
    CM-3Configuration Change ControlCMConfiguration Management3.4.3
    CM-4Impact AnalysesCMConfiguration Management3.4.4
    CM-4(1)Separate Test EnvironmentsCMConfiguration Management3.4.5
    CM-5Access Restrictions for ChangeCMConfiguration Management3.4.5
    CM-6Configuration SettingsCMConfiguration Management3.3.3, 3.4.1, 3.4.2
    CM-7Least FunctionalityCMConfiguration Management3.4.6
    CM-7(1)Periodic ReviewCMConfiguration Management3.4.7
    CM-7(2)Prevent Program ExecutionCMConfiguration Management3.4.7
    CM-7(4)Unauthorized Software — Deny-by-exceptionCMConfiguration Management3.4.8
    CM-7(5)Authorized Software — Allow-by-exceptionCMConfiguration Management3.4.8
    CM-8System Component InventoryCMConfiguration Management3.4.1
    CM-11User-installed SoftwareCMConfiguration Management3.4.9
    CM-11(2)Software Installation with Privileged StatusCMConfiguration Management3.4.9
    CP-9System BackupCPContingency Planning3.8.9
    CP-9(8)Cryptographic ProtectionCPContingency Planning3.8.9
    IA-1Policy and ProceduresIAIdentification and Authentication3.1.1
    IA-2Identification and Authentication (Organizational Users)IAIdentification and Authentication3.1.1, 3.5.1, 3.5.2
    IA-2(1)Multi-factor Authentication to Privileged AccountsIAIdentification and Authentication3.5.3, 3.7.5
    IA-2(2)Multi-factor Authentication to Non-privileged AccountsIAIdentification and Authentication3.5.3, 3.7.5
    IA-2(8)Access to Accounts — Replay ResistantIAIdentification and Authentication3.5.4
    IA-3Device Identification and AuthenticationIAIdentification and Authentication3.5.1, 3.5.2
    IA-3(1)Cryptographic Bidirectional AuthenticationIAIdentification and Authentication3.5.1, 3.5.2
    IA-3(4)Device AttestationIAIdentification and Authentication3.5.1, 3.5.2
    IA-4Identifier ManagementIAIdentification and Authentication3.5.5
    IA-5Authenticator ManagementIAIdentification and Authentication3.5.8, 3.5.9
    IA-5(1)Password-based AuthenticationIAIdentification and Authentication3.5.7, 3.5.8, 3.5.9
    IA-5(6)Protection of AuthenticatorsIAIdentification and Authentication3.5.10
    IA-6Authentication FeedbackIAIdentification and Authentication3.5.11
    IR-2Incident Response TrainingIRIncident Response3.6.1
    IR-2(3)BreachIRIncident Response3.6.1
    IR-3Incident Response TestingIRIncident Response3.6.3
    IR-4Incident HandlingIRIncident Response3.6.1, 3.6.2
    IR-4(4)Information CorrelationIRIncident Response3.14.7, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    IR-4(13)Behavior AnalysisIRIncident Response3.14.7
    MA-2Controlled MaintenanceMAMaintenance3.7.1
    MA-3Maintenance ToolsMAMaintenance3.7.2
    MA-3(2)Inspect MediaMAMaintenance3.7.4
    MA-3(5)Execution with PrivilegeMAMaintenance3.7.2
    MA-3(6)Software Updates and PatchesMAMaintenance3.7.2
    MA-4Nonlocal MaintenanceMAMaintenance3.7.5
    MA-4(7)Disconnect VerificationMAMaintenance3.7.5
    MA-5Maintenance PersonnelMAMaintenance3.7.6
    MA-5(1)Individuals Without Appropriate AccessMAMaintenance3.7.6
    MA-5(2)Security Clearances for Classified SystemsMAMaintenance3.7.6
    MA-5(3)Citizenship Requirements for Classified SystemsMAMaintenance3.7.6
    MA-5(4)Foreign NationalsMAMaintenance3.7.6
    MA-5(5)Non-system MaintenanceMAMaintenance3.7.6
    PE-1Policy and ProceduresPEPhysical and Environmental Protection3.10.2
    PE-2Physical Access AuthorizationsPEPhysical and Environmental Protection3.10.1
    PE-2(1)Access by Position or RolePEPhysical and Environmental Protection3.10.1
    PE-2(3)Restrict Unescorted AccessPEPhysical and Environmental Protection3.10.3
    PE-3Physical Access ControlPEPhysical and Environmental Protection3.10.3, 3.10.5
    PE-3(1)System AccessPEPhysical and Environmental Protection3.10.1
    PE-3(2)Facility and SystemsPEPhysical and Environmental Protection3.10.3, 3.10.5
    PE-3(3)Continuous GuardsPEPhysical and Environmental Protection3.10.3, 3.10.5
    PE-4Access Control for TransmissionPEPhysical and Environmental Protection3.10.1
    PE-5Access Control for Output DevicesPEPhysical and Environmental Protection3.10.1
    PE-6Monitoring Physical AccessPEPhysical and Environmental Protection3.10.2
    PE-6(1)Intrusion Alarms and Surveillance EquipmentPEPhysical and Environmental Protection3.10.2
    PE-6(4)Monitoring Physical Access to SystemsPEPhysical and Environmental Protection3.10.2
    PE-8Visitor Access RecordsPEPhysical and Environmental Protection3.10.4
    PE-17Alternate Work SitePEPhysical and Environmental Protection3.10.6
    PE-18Location of System ComponentsPEPhysical and Environmental Protection3.10.1
    PE-23Facility LocationPEPhysical and Environmental Protection3.10.1, 3.10.2
    PL-2System Security and Privacy PlansPLPlanning3.12.4
    PL-4Rules of BehaviorPLPlanning3.1.22
    PL-4(1)Social Media and External Site/Application Usage RestrictionsPLPlanning3.1.22
    PL-8(1)Defense in DepthPLPlanning3.13.2
    PL-10Baseline SelectionPLPlanning3.3.3, 3.4.1, 3.4.2
    PL-11Baseline TailoringPLPlanning3.3.3
    RA-3Risk AssessmentRARisk Assessment3.11.1
    RA-5Vulnerability Monitoring and ScanningRARisk Assessment3.11.2
    RA-5(5)Privileged AccessRARisk Assessment3.11.2
    SA-4Acquisition ProcessSASystem and Services Acquisition3.1.1
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services Acquisition3.13.2, 3.3.3, 3.4.1, 3.4.2
    SA-8(14)Least PrivilegeSASystem and Services Acquisition3.1.5
    SA-8(31)Secure System ModificationSASystem and Services Acquisition3.4.3
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services Acquisition3.12.2
    SA-15(5)Attack Surface ReductionSASystem and Services Acquisition3.13.2, 3.3.3, 3.4.1, 3.4.2
    SC-1Policy and ProceduresSCSystem and Communications Protection3.13.1, 3.13.2
    SC-2Separation of System and User FunctionalitySCSystem and Communications Protection3.13.3
    SC-2(1)Interfaces for Non-privileged UsersSCSystem and Communications Protection3.13.3
    SC-3(5)Layered StructuresSCSystem and Communications Protection3.13.2
    SC-4Information in Shared System ResourcesSCSystem and Communications Protection3.13.4
    SC-7Boundary ProtectionSCSystem and Communications Protection3.13.1
    SC-7(5)Deny by Default — Allow by ExceptionSCSystem and Communications Protection3.13.6
    SC-7(7)Split Tunneling for Remote DevicesSCSystem and Communications Protection3.13.7
    SC-7(8)Route Traffic to Authenticated Proxy ServersSCSystem and Communications Protection3.1.3
    SC-7(9)Restrict Threatening Outgoing Communications TrafficSCSystem and Communications Protection3.13.1
    SC-7(11)Restrict Incoming Communications TrafficSCSystem and Communications Protection3.13.1, 3.13.6
    SC-7(14)Protect Against Unauthorized Physical ConnectionsSCSystem and Communications Protection3.10.1
    SC-7(18)Fail SecureSCSystem and Communications Protection3.13.2
    SC-7(29)Separate Subnets to Isolate FunctionsSCSystem and Communications Protection3.13.2
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications Protection3.13.8
    SC-8(1)Cryptographic ProtectionSCSystem and Communications Protection3.13.11, 3.13.8, 3.8.6
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications Protection3.13.11, 3.8.7
    SC-8(3)Cryptographic Protection for Message ExternalsSCSystem and Communications Protection3.13.14
    SC-10Network DisconnectSCSystem and Communications Protection3.13.9
    SC-12Cryptographic Key Establishment and ManagementSCSystem and Communications Protection3.13.10
    SC-13Cryptographic ProtectionSCSystem and Communications Protection3.13.11, 3.13.16, 3.8.6
    SC-15Collaborative Computing Devices and ApplicationsSCSystem and Communications Protection3.13.12
    SC-15(1)Physical or Logical DisconnectSCSystem and Communications Protection3.13.12
    SC-17Public Key Infrastructure CertificatesSCSystem and Communications Protection3.13.10
    SC-18Mobile CodeSCSystem and Communications Protection3.13.13
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications Protection3.11.3, 3.13.13, 3.14.1
    SC-18(2)Acquisition, Development, and UseSCSystem and Communications Protection3.13.13
    SC-18(3)Prevent Downloading and ExecutionSCSystem and Communications Protection3.1.3, 3.13.13
    SC-18(4)Prevent Automatic ExecutionSCSystem and Communications Protection3.13.13, 3.4.8
    SC-23Session AuthenticitySCSystem and Communications Protection3.13.15
    SC-27Platform-independent ApplicationsSCSystem and Communications Protection3.13.13
    SC-28Protection of Information at RestSCSystem and Communications Protection3.13.16, 3.8.6
    SC-28(1)Cryptographic ProtectionSCSystem and Communications Protection3.13.16, 3.8.6, 3.8.9
    SC-28(2)Offline StorageSCSystem and Communications Protection3.8.9
    SC-28(3)Cryptographic KeysSCSystem and Communications Protection3.13.10
    SC-45System Time SynchronizationSCSystem and Communications Protection3.3.7
    SC-45(1)Synchronization with Authoritative Time SourceSCSystem and Communications Protection3.3.7
    SI-1Policy and ProceduresSISystem and Information Integrity3.13.2
    SI-2Flaw RemediationSISystem and Information Integrity3.11.3, 3.14.1, 3.14.4
    SI-2(4)Automated Patch Management ToolsSISystem and Information Integrity3.11.3, 3.14.1
    SI-3Malicious Code ProtectionSISystem and Information Integrity3.11.3, 3.14.1, 3.14.2, 3.14.4, 3.14.5
    SI-4System MonitoringSISystem and Information Integrity3.14.6, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    SI-4(4)Inbound and Outbound Communications TrafficSISystem and Information Integrity3.14.6
    SI-4(9)Testing of Monitoring Tools and MechanismsSISystem and Information Integrity3.6.3
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information Integrity3.14.7
    SI-4(16)Correlate Monitoring InformationSISystem and Information Integrity3.14.7, 3.3.5
    SI-4(24)Indicators of CompromiseSISystem and Information Integrity3.14.7
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information Integrity3.12.3, 3.14.3
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information Integrity3.12.3, 3.14.3
    SI-7(6)Cryptographic ProtectionSISystem and Information Integrity3.13.11
    MP-1Policy and ProceduresMPMedia Protection3.8.1, 3.8.3
    MP-2Media AccessMPMedia Protection3.1.3, 3.14.2, 3.8.2
    MP-3Media MarkingMPMedia Protection3.8.4
    MP-4Media StorageMPMedia Protection3.8.1
    MP-5Media TransportMPMedia Protection3.8.5
    MP-6Media SanitizationMPMedia Protection3.7.3, 3.8.3
    MP-6(3)Nondestructive TechniquesMPMedia Protection3.7.3, 3.8.3
    MP-7Media UseMPMedia Protection3.8.7, 3.8.8
    PS-1Policy and ProceduresPSPersonnel Security3.1.22
    PS-3Personnel ScreeningPSPersonnel Security3.9.1
    PS-3(1)Classified InformationPSPersonnel Security3.9.1
    PS-3(2)Formal IndoctrinationPSPersonnel Security3.2.1, 3.2.2
    PS-3(3)Information Requiring Special Protective MeasuresPSPersonnel Security3.9.1
    PS-4Personnel TerminationPSPersonnel Security3.9.2
    PS-5Personnel TransferPSPersonnel Security3.9.2
    PM-4Plan of Action and Milestones ProcessPMProgram Management3.12.2, 3.14.1
    PM-5System InventoryPMProgram Management3.4.1, 3.8.3
    PM-14Testing, Training, and MonitoringPMProgram Management3.12.1, 3.12.3
    PM-15Security and Privacy Groups and AssociationsPMProgram Management3.12.3, 3.14.3
    PM-16Threat Awareness ProgramPMProgram Management3.12.3, 3.14.3
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram Management3.12.3, 3.14.3
    PM-31Continuous Monitoring StrategyPMProgram Management3.14.6, 3.3.3
    PT-1Policy and ProceduresPTPII Processing and Transparency3.13.2
    SR-1Policy and ProceduresSRSupply Chain Risk Management3.1.1
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk Management3.1.1
    SR-12Component DisposalSRSupply Chain Risk Management3.8.3

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.