Skip to content

    NIST CSF 2.0 to NIST SP 800-171 Rev 2 control mapping

    NIST CSF 2.0 and NIST SP 800-171 Rev 2 both map to 100 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    100
    NIST CSF 2.0 controls involved
    73
    NIST SP 800-171 Rev 2 controls involved
    63
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored NIST CSF 2.0 to NIST SP 800-171 Rev 2 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both NIST CSF 2.0 and NIST SP 800-171 Rev 2, with the controls on each side that map to them.
    NIST 800-53 controlFamilyNIST CSF 2.0 controlsNIST SP 800-171 Rev 2 controls
    AC-1Policy and ProceduresACAccess ControlGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-053.1.1
    AC-2(7)Privileged User AccountsACAccess ControlPR.AA-053.1.1, 3.1.2, 3.1.3
    AC-2(12)Account Monitoring for Atypical UsageACAccess ControlDE.CM-033.14.7
    AC-5Separation of DutiesACAccess ControlPR.AA-053.1.4
    AC-6Least PrivilegeACAccess ControlPR.AA-05, PR.DS-103.1.1, 3.1.5
    AC-20Use of External SystemsACAccess ControlID.AM-043.1.20
    AT-2Literacy Training and AwarenessATAwareness and TrainingPR.AT-013.2.1
    AT-2(2)Insider ThreatATAwareness and TrainingID.RA-033.2.3
    AT-2(6)Cyber Threat EnvironmentATAwareness and TrainingPR.AT-01, PR.AT-023.2.3
    AT-3Role-based TrainingATAwareness and TrainingPR.AT-01, PR.AT-023.2.2
    AT-3(2)Physical Security ControlsATAwareness and TrainingPR.AT-01, PR.AT-023.2.2
    AU-1Policy and ProceduresAUAudit and AccountabilityDE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-043.14.6, 3.3.3
    AU-2Event LoggingAUAudit and AccountabilityDE.AE-03, DE.AE-06, DE.CM-013.14.3, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    AU-3Content of Audit RecordsAUAudit and AccountabilityPR.PS-043.3.2
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and AccountabilityDE.AE-03, DE.AE-063.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and AccountabilityDE.AE-03, DE.AE-063.14.7, 3.3.5
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and AccountabilityDE.AE-03, DE.AE-063.14.7, 3.3.5
    CA-2Control AssessmentsCAAssessment, Authorization, and MonitoringID.IM-01, ID.IM-02, ID.RA-013.12.1
    CA-5Plan of Action and MilestonesCAAssessment, Authorization, and MonitoringID.IM-01, ID.IM-02, ID.RA-013.12.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringGV.OC-033.12.1, 3.12.3
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringGV.OC-033.12.1, 3.12.3
    CM-2Baseline ConfigurationCMConfiguration ManagementPR.DS-10, PR.PS-053.3.3, 3.4.1, 3.4.2
    CM-3Configuration Change ControlCMConfiguration ManagementID.RA-073.4.3
    CM-4Impact AnalysesCMConfiguration ManagementID.RA-073.4.4
    CM-5Access Restrictions for ChangeCMConfiguration ManagementID.RA-073.4.5
    CM-6Configuration SettingsCMConfiguration ManagementPR.DS-10, PR.PS-053.3.3, 3.4.1, 3.4.2
    CM-7Least FunctionalityCMConfiguration ManagementPR.PS-053.4.6
    CM-7(2)Prevent Program ExecutionCMConfiguration ManagementPR.PS-053.4.7
    CM-8System Component InventoryCMConfiguration ManagementID.AM-01, ID.AM-023.4.1
    CM-11User-installed SoftwareCMConfiguration ManagementPR.PS-053.4.9
    CM-11(2)Software Installation with Privileged StatusCMConfiguration ManagementPR.PS-053.4.9
    CP-9System BackupCPContingency PlanningPR.DS-113.8.9
    IA-1Policy and ProceduresIAIdentification and AuthenticationGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-053.1.1
    IA-2Identification and Authentication (Organizational Users)IAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-053.1.1, 3.5.1, 3.5.2
    IA-2(8)Access to Accounts — Replay ResistantIAIdentification and AuthenticationPR.AA-043.5.4
    IA-3Device Identification and AuthenticationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-053.5.1, 3.5.2
    IA-3(1)Cryptographic Bidirectional AuthenticationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-053.5.1, 3.5.2
    IA-3(4)Device AttestationIAIdentification and AuthenticationPR.AA-01, PR.AA-03, PR.AA-053.5.1, 3.5.2
    IA-4Identifier ManagementIAIdentification and AuthenticationPR.AA-03, PR.AA-04, PR.AA-053.5.5
    IR-4Incident HandlingIRIncident ResponseDE.AE-02, DE.AE-03, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, RC.CO-03, RC.RP-06, RS.AN-06, RS.CO-02, RS.CO-03, RS.MA-01, RS.MA-02, RS.MA-04, RS.MI-01, RS.MI-023.6.1, 3.6.2
    IR-4(4)Information CorrelationIRIncident ResponseDE.AE-03, DE.AE-063.14.7, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    IR-4(13)Behavior AnalysisIRIncident ResponseDE.CM-033.14.7
    MA-2Controlled MaintenanceMAMaintenancePR.PS-02, PR.PS-033.7.1
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionDE.CM-02, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-06, PR.IR-023.10.2
    PE-2Physical Access AuthorizationsPEPhysical and Environmental ProtectionPR.AA-063.10.1
    PE-2(1)Access by Position or RolePEPhysical and Environmental ProtectionPR.AA-063.10.1
    PE-3Physical Access ControlPEPhysical and Environmental ProtectionDE.CM-02, PR.AA-063.10.3, 3.10.5
    PE-3(2)Facility and SystemsPEPhysical and Environmental ProtectionDE.CM-02, PR.AA-063.10.3, 3.10.5
    PE-3(3)Continuous GuardsPEPhysical and Environmental ProtectionDE.CM-02, PR.AA-063.10.3, 3.10.5
    PE-6Monitoring Physical AccessPEPhysical and Environmental ProtectionDE.CM-023.10.2
    PE-8Visitor Access RecordsPEPhysical and Environmental ProtectionDE.CM-023.10.4
    PE-23Facility LocationPEPhysical and Environmental ProtectionDE.CM-02, GV.SC-06, PR.AA-06, PR.IR-023.10.1, 3.10.2
    PL-2System Security and Privacy PlansPLPlanningID.AM-033.12.4
    PL-10Baseline SelectionPLPlanningPR.DS-10, PR.PS-053.3.3, 3.4.1, 3.4.2
    RA-3Risk AssessmentRARisk AssessmentGV.RM-06, ID.IM-01, ID.IM-02, ID.RA-01, ID.RA-04, ID.RA-053.11.1
    RA-5Vulnerability Monitoring and ScanningRARisk AssessmentID.RA-013.11.2
    SA-4Acquisition ProcessSASystem and Services AcquisitionGV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10, ID.RA-09, PR.PS-063.1.1
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services AcquisitionPR.DS-10, PR.IR-01, PR.IR-03, PR.PS-053.13.2, 3.3.3, 3.4.1, 3.4.2
    SA-8(14)Least PrivilegeSASystem and Services AcquisitionPR.AA-05, PR.DS-103.1.5
    SA-8(31)Secure System ModificationSASystem and Services AcquisitionID.RA-073.4.3
    SA-15(2)Security and Privacy Tracking ToolsSASystem and Services AcquisitionID.IM-01, ID.IM-02, ID.RA-013.12.2
    SA-15(5)Attack Surface ReductionSASystem and Services AcquisitionPR.DS-10, PR.IR-01, PR.IR-03, PR.PS-053.13.2, 3.3.3, 3.4.1, 3.4.2
    SC-1Policy and ProceduresSCSystem and Communications ProtectionGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-033.13.1, 3.13.2
    SC-7(8)Route Traffic to Authenticated Proxy ServersSCSystem and Communications ProtectionDE.CM-033.1.3
    SC-7(18)Fail SecureSCSystem and Communications ProtectionPR.IR-01, PR.IR-033.13.2
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications ProtectionPR.DS-023.13.8
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionPR.DS-01, PR.DS-02, PR.DS-103.13.11, 3.13.8, 3.8.6
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionPR.DS-01, PR.DS-02, PR.DS-103.13.11, 3.8.7
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionPR.DS-01, PR.DS-02, PR.DS-103.13.11, 3.13.16, 3.8.6
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications ProtectionID.RA-08, PR.PS-023.11.3, 3.13.13, 3.14.1
    SC-18(3)Prevent Downloading and ExecutionSCSystem and Communications ProtectionDE.CM-033.1.3, 3.13.13
    SC-28Protection of Information at RestSCSystem and Communications ProtectionPR.DS-013.13.16, 3.8.6
    SC-28(1)Cryptographic ProtectionSCSystem and Communications ProtectionPR.DS-01, PR.DS-023.13.16, 3.8.6, 3.8.9
    SC-28(2)Offline StorageSCSystem and Communications ProtectionPR.DS-113.8.9
    SI-1Policy and ProceduresSISystem and Information IntegrityGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-033.13.2
    SI-2Flaw RemediationSISystem and Information IntegrityID.RA-01, ID.RA-08, PR.PS-023.11.3, 3.14.1, 3.14.4
    SI-2(4)Automated Patch Management ToolsSISystem and Information IntegrityPR.PS-023.11.3, 3.14.1
    SI-3Malicious Code ProtectionSISystem and Information IntegrityDE.CM-09, ID.RA-01, ID.RA-08, PR.PS-023.11.3, 3.14.1, 3.14.2, 3.14.4, 3.14.5
    SI-4System MonitoringSISystem and Information IntegrityDE.AE-03, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-043.14.6, 3.3.1, 3.3.3, 3.3.5, 3.3.6, 3.3.8, 3.3.9
    SI-4(4)Inbound and Outbound Communications TrafficSISystem and Information IntegrityDE.CM-013.14.6
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information IntegrityDE.CM-033.14.7
    SI-4(16)Correlate Monitoring InformationSISystem and Information IntegrityDE.AE-03, DE.AE-063.14.7, 3.3.5
    SI-4(24)Indicators of CompromiseSISystem and Information IntegrityDE.CM-093.14.7
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information IntegrityDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-083.12.3, 3.14.3
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information IntegrityDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-083.12.3, 3.14.3
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegrityPR.DS-01, PR.DS-02, PR.DS-103.13.11
    MP-1Policy and ProceduresMPMedia ProtectionGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.AM-08, PR.DS-01, PR.DS-02, PR.DS-103.8.1, 3.8.3
    MP-2Media AccessMPMedia ProtectionDE.CM-093.1.3, 3.14.2, 3.8.2
    MP-4Media StorageMPMedia ProtectionID.AM-073.8.1
    PS-1Policy and ProceduresPSPersonnel SecurityGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-04, GV.SC-01, GV.SC-033.1.22
    PM-4Plan of Action and Milestones ProcessPMProgram ManagementID.IM-01, ID.IM-02, ID.RA-01, ID.RA-08, PR.PS-023.12.2, 3.14.1
    PM-5System InventoryPMProgram ManagementGV.SC-04, ID.AM-01, ID.AM-02, ID.AM-083.4.1, 3.8.3
    PM-14Testing, Training, and MonitoringPMProgram ManagementGV.OC-033.12.1, 3.12.3
    PM-15Security and Privacy Groups and AssociationsPMProgram ManagementDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-083.12.3, 3.14.3
    PM-16Threat Awareness ProgramPMProgram ManagementDE.AE-07, ID.RA-03, ID.RA-083.12.3, 3.14.3
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram ManagementDE.AE-07, ID.RA-02, ID.RA-03, ID.RA-083.12.3, 3.14.3
    PM-31Continuous Monitoring StrategyPMProgram ManagementDE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-043.14.6, 3.3.3
    PT-1Policy and ProceduresPTPII Processing and TransparencyGV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-033.13.2
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementGV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-103.1.1
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk ManagementGV.OC-02, GV.OC-03, GV.SC-02, GV.SC-05, GV.SC-06, GV.SC-103.1.1

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.