Skip to content

    PCI DSS v4.0.1 to NIST CSF 2.0 control mapping

    PCI DSS v4.0.1 and NIST CSF 2.0 both map to 166 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    166
    PCI DSS v4.0.1 controls involved
    259
    NIST CSF 2.0 controls involved
    101
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored PCI DSS v4.0.1 to NIST CSF 2.0 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both PCI DSS v4.0.1 and NIST CSF 2.0, with the controls on each side that map to them.
    NIST 800-53 controlFamilyPCI DSS v4.0.1 controlsNIST CSF 2.0 controls
    AC-1Policy and ProceduresACAccess Control1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05
    AC-2(7)Privileged User AccountsACAccess Control1.3, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.5, 7.3, 7.3.1, 7.3.2, 7.3.3PR.AA-05
    AC-2(12)Account Monitoring for Atypical UsageACAccess Control3.1, A3.2.6.1DE.CM-03
    AC-4(25)Data SanitizationACAccess Control10.5.1, 9.4.6, 9.4.7ID.AM-07
    AC-5Separation of DutiesACAccess Control11.2, 4.1, 4.2.1, 6.5.4PR.AA-05
    AC-6Least PrivilegeACAccess Control1.3, 3.4, 3.4.2, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.5, 7.2.6, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.6, 8.6.1PR.AA-05, PR.DS-10
    AT-1Policy and ProceduresATAwareness and Training1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.5.1, 9.5.1.3, A3.1.4GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03
    AT-2Literacy Training and AwarenessATAwareness and Training12.6, 12.6.1, 12.6.3, 12.6.3.1, 8.3.8, 9.5.1, 9.5.1.3PR.AT-01
    AT-2(6)Cyber Threat EnvironmentATAwareness and Training12.6.3, 12.6.3.1, 12.6.3.2, 9.5.1, 9.5.1.3PR.AT-01, PR.AT-02
    AT-3Role-based TrainingATAwareness and Training1.1.2, 12.6, 12.6.1, 12.6.3, 12.6.3.1, 12.6.3.2, 6.2.2, 8.3.8, 9.5.1, 9.5.1.3PR.AT-01, PR.AT-02
    AT-3(2)Physical Security ControlsATAwareness and Training1.1.2, 12.6, 12.6.1, 12.6.3, 12.6.3.1, 12.6.3.2, 6.2.2, 8.3.8, 9.5.1, 9.5.1.3PR.AT-01, PR.AT-02
    AU-1Policy and ProceduresAUAudit and Accountability1.1.1, 10.1, 10.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.3.1, A3.5DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-04
    AU-2Event LoggingAUAudit and Accountability10.3.3, 10.4, 10.4.1, 10.4.1.1, 10.4.2, 10.4.2.1, 10.4.3, 12.4.2DE.AE-03, DE.AE-06, DE.CM-01
    AU-3Content of Audit RecordsAUAudit and Accountability10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 6.4.2PR.PS-04
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and Accountability10.3.3, 10.4, 10.4.1, 10.4.1.1DE.AE-03, DE.AE-06
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and Accountability10.4.1.1, 12.10.5DE.AE-03, DE.AE-06
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and Accountability10.4.1.1, 12.10.5DE.AE-03, DE.AE-06
    CA-1Policy and ProceduresCAAssessment, Authorization, and Monitoring1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-01
    CA-2Control AssessmentsCAAssessment, Authorization, and Monitoring1.1, 1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.4.2ID.IM-01, ID.IM-02, ID.RA-01
    CA-7Continuous MonitoringCAAssessment, Authorization, and Monitoring10.7, 10.7.1, 10.7.2, 10.7.3GV.OC-03
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring10.7, 10.7.1, 10.7.2, 10.7.3GV.OC-03
    CM-1Policy and ProceduresCMConfiguration Management1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1, 2.1.1, 2.2, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-01, PR.PS-05
    CM-2Baseline ConfigurationCMConfiguration Management1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 12.4.2, 2.2, 2.2.1, 8.3.2, 8.5PR.DS-10, PR.PS-05
    CM-3Configuration Change ControlCMConfiguration Management1.2.2, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.3, 6.5.6ID.RA-07
    CM-3(1)Automated Documentation, Notification, and Prohibition of ChangesCMConfiguration Management1.2.2, 6.5, 6.5.1ID.RA-07
    CM-3(2)Testing, Validation, and Documentation of ChangesCMConfiguration Management10.7.3, 6.5, 6.5.1, 6.5.2, A3.2.2.1ID.RA-07
    CM-3(7)Review System ChangesCMConfiguration Management6.5, 6.5.1, 6.5.2, A3.2.2.1ID.RA-07
    CM-4Impact AnalysesCMConfiguration Management6.5.2, 6.5.6, A3.2.2, A3.2.3ID.RA-07
    CM-5Access Restrictions for ChangeCMConfiguration Management1.2.8ID.RA-07
    CM-6Configuration SettingsCMConfiguration Management1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 8.3.2, 8.5PR.DS-10, PR.PS-05
    CM-7Least FunctionalityCMConfiguration Management1.2.5, 1.2.6, 1.4, 1.4.1, 1.4.2, 2.2.4PR.PS-05
    CM-8System Component InventoryCMConfiguration Management11.2, 11.2.2, 6.3.2, 9.5.1, 9.5.1.1ID.AM-01, ID.AM-02
    CM-9Configuration Management PlanCMConfiguration Management2.1, 2.2, 8.5PR.PS-01, PR.PS-05
    CP-1Policy and ProceduresCPContingency Planning1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    CP-9System BackupCPContingency Planning12.10.1, 9.4.1.1, 9.4.1.2PR.DS-11
    IA-1Policy and ProceduresIAIdentification and Authentication1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05
    IA-2Identification and Authentication (Organizational Users)IAIdentification and Authentication7.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.2, 8.3, 8.3.3, 8.3.9PR.AA-01, PR.AA-03, PR.AA-05
    IA-2(8)Access to Accounts — Replay ResistantIAIdentification and Authentication8.5.1PR.AA-04
    IA-4Identifier ManagementIAIdentification and Authentication8.2, 8.2.1PR.AA-03, PR.AA-04, PR.AA-05
    IA-4(4)Identify User StatusIAIdentification and Authentication8.2, 8.2.1PR.AA-03, PR.AA-04, PR.AA-05
    IA-8Identification and Authentication (Non-organizational Users)IAIdentification and Authentication7.2.1PR.AA-01, PR.AA-03, PR.AA-05
    IA-9Service Identification and AuthenticationIAIdentification and Authentication8.2.3PR.AA-01, PR.AA-03, PR.AA-05
    IA-12Identity ProofingIAIdentification and Authentication8.3.3PR.AA-02
    IR-1Policy and ProceduresIRIncident Response1.1.1, 10.1.1, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.10, 12.10.2, 12.10.6, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.5GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-02, ID.IM-03, ID.IM-04, RS.AN-03
    IR-4Incident HandlingIRIncident Response12.10, 12.10.5DE.AE-02, DE.AE-03, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, RC.CO-03, RC.RP-06, RS.AN-06, RS.CO-02, RS.CO-03, RS.MA-01, RS.MA-02, RS.MA-04, RS.MI-01, RS.MI-02
    IR-4(3)Continuity of OperationsIRIncident Response12.10DE.AE-02, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.AN-08, RS.MA-03, RS.MA-05
    IR-4(4)Information CorrelationIRIncident Response10.3.3, 10.4, 10.4.1, 10.4.1.1, 12.10.5DE.AE-03, DE.AE-06
    IR-4(10)Supply Chain CoordinationIRIncident Response10.7, 10.7.1, 10.7.2, 10.7.3GV.SC-08, RS.CO-02, RS.CO-03
    IR-4(11)Integrated Incident Response TeamIRIncident Response12.10.3DE.AE-06, RS.MA-01, RS.MA-04
    IR-4(12)Malicious Code and Forensic AnalysisIRIncident Response12.10.6ID.IM-02, ID.IM-03, RS.AN-03, RS.AN-06, RS.AN-07
    IR-4(13)Behavior AnalysisIRIncident Response3.1, A3.2.6.1DE.CM-03
    IR-5Incident MonitoringIRIncident ResponseA3.3.1DE.AE-06, RC.RP-06, RS.AN-06
    IR-6Incident ReportingIRIncident Response12.1.4, 12.10.1, A1.2.3DE.AE-06, RC.CO-03, RS.CO-02, RS.CO-03, RS.MA-01
    IR-6(2)Vulnerabilities Related to IncidentsIRIncident Response12.10.6ID.IM-02, ID.IM-03, RS.AN-03
    IR-8Incident Response PlanIRIncident Response12.10, 12.10.1, 12.10.5, 12.10.7DE.AE-06, ID.IM-04, RS.MA-01, RS.MA-02, RS.MA-04
    MA-1Policy and ProceduresMAMaintenance1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.7, 8.3.8, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-02, PR.PS-03
    MA-6Timely MaintenanceMAMaintenance10.7, 11.3PR.PS-02, PR.PS-03
    PE-1Policy and ProceduresPEPhysical and Environmental Protection1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1, 9.1.1, 9.2DE.CM-02, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-06, PR.IR-02
    PE-2Physical Access AuthorizationsPEPhysical and Environmental Protection8.3.11, 9.1, 9.2, 9.2.1, 9.3, 9.3.1PR.AA-06
    PE-2(1)Access by Position or RolePEPhysical and Environmental Protection8.3.11, 9.1, 9.2, 9.2.1, 9.3, 9.3.1, 9.3.1.1PR.AA-06
    PE-3Physical Access ControlPEPhysical and Environmental Protection9.1, 9.1.2, 9.2, 9.2.1DE.CM-02, PR.AA-06
    PE-3(2)Facility and SystemsPEPhysical and Environmental Protection9.1, 9.1.2, 9.2, 9.2.1DE.CM-02, PR.AA-06
    PE-3(3)Continuous GuardsPEPhysical and Environmental Protection9.1, 9.1.2, 9.2, 9.2.1DE.CM-02, PR.AA-06
    PE-6Monitoring Physical AccessPEPhysical and Environmental Protection9.2.1.1DE.CM-02
    PE-8Visitor Access RecordsPEPhysical and Environmental Protection9.2.1, 9.2.1.1DE.CM-02
    PE-22Component MarkingPEPhysical and Environmental ProtectionA3.2.5ID.AM-05
    PE-23Facility LocationPEPhysical and Environmental Protection12.5.2, 3.2.1, 9.1, 9.1.1, 9.2, 9.2.2, 9.2.3, 9.2.4DE.CM-02, GV.SC-06, PR.AA-06, PR.IR-02
    PL-1Policy and ProceduresPLPlanning1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 12.4.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1, A3.1.1GV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-03, GV.SC-01, GV.SC-03, GV.SC-05, ID.RA-09, PR.PS-06
    PL-2System Security and Privacy PlansPLPlanning1.2.3, 1.2.4ID.AM-03
    PL-8Security and Privacy ArchitecturesPLPlanning1.2PR.IR-01, PR.IR-03
    PL-9Central ManagementPLPlanning1.1, 1.1.2, 10.1.2, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 5.3.4, 6.1.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3GV.RM-05, GV.RR-01, GV.RR-02
    PL-10Baseline SelectionPLPlanning1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 8.3.2, 8.5PR.DS-10, PR.PS-05
    RA-1Policy and ProceduresRARisk Assessment1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1GV.OV-01, GV.OV-02, GV.OV-03, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09
    RA-2Security CategorizationRARisk Assessment9.4.2ID.RA-04
    RA-3Risk AssessmentRARisk Assessment1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.3, 12.3.1, 12.3.2, 12.4.2GV.RM-06, ID.IM-01, ID.IM-02, ID.RA-01, ID.RA-04, ID.RA-05
    RA-5Vulnerability Monitoring and ScanningRARisk Assessment11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.4.1ID.RA-01
    RA-7Risk ResponseRARisk Assessment10.7, 10.7.1, 10.7.2, 10.7.3GV.RM-04, ID.RA-05, ID.RA-06
    RA-8Privacy Impact AssessmentsRARisk AssessmentA3.2.2ID.RA-04
    RA-9Criticality AnalysisRARisk Assessment1.1GV.OC-04, GV.OC-05, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, ID.AM-05, ID.RA-04, ID.RA-10, PR.PS-06
    SA-1Policy and ProceduresSASystem and Services Acquisition1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 6.2.4, 7.1.1, 8.1.1, 8.3.8, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-09, PR.PS-06
    SA-3System Development Life CycleSASystem and Services Acquisition12.3.4GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-3(1)Manage Preproduction EnvironmentSASystem and Services Acquisition11.4.5, 11.4.6, 12.3.4, 6.5.3GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-3(3)Technology RefreshSASystem and Services Acquisition12.3.4GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-4Acquisition ProcessSASystem and Services Acquisition12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 6.2, 6.2.1, 8.2.3, A2.1.3GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10, ID.RA-09, PR.PS-06
    SA-4(1)Functional Properties of ControlsSASystem and Services Acquisition1.2.3, 1.2.4ID.AM-03
    SA-4(2)Design and Implementation Information for ControlsSASystem and Services Acquisition1.2.3, 1.2.4ID.AM-03
    SA-4(3)Development Methods, Techniques, and PracticesSASystem and Services Acquisition6.2, 6.2.1, 6.2.4PR.PS-06
    SA-4(12)Data OwnershipSASystem and Services Acquisition2.2.2, 2.2.4, 2.2.5, 6.5.2, 9.4.1ID.AM-08
    SA-5System DocumentationSASystem and Services AcquisitionA3.2.5ID.AM-05
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services Acquisition1.1, 1.2, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 6.1, 6.2, 6.2.1, 8.3.2, 8.5, 8.5.1PR.DS-10, PR.IR-01, PR.IR-03, PR.PS-05
    SA-8(14)Least PrivilegeSASystem and Services Acquisition1.3, 3.4, 3.4.2, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.6, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.6, 8.6.1PR.AA-05, PR.DS-10
    SA-8(30)Procedural RigorSASystem and Services Acquisition12.3.4GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03
    SA-8(31)Secure System ModificationSASystem and Services Acquisition1.2.2, 10.7.3, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.6, A3.2.2.1ID.RA-07
    SA-9External System ServicesSASystem and Services Acquisition12.8.2, 12.9, 12.9.1, 12.9.2, 8.2.3GV.SC-06, GV.SC-07, ID.AM-04
    SA-9(1)Risk Assessments and Organizational ApprovalsSASystem and Services Acquisition12.8.3GV.SC-06, GV.SC-07, ID.IM-01, ID.IM-02, ID.RA-10
    SA-9(3)Establish and Maintain Trust Relationship with ProvidersSASystem and Services Acquisition12.4.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2GV.OC-02, GV.OC-04, GV.OC-05, GV.RM-05, GV.RR-02, GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-09, GV.SC-10, ID.AM-05, ID.RA-10
    SA-9(5)Processing, Storage, and Service LocationSASystem and Services Acquisition12.5.2, 3.2.1GV.SC-06, ID.AM-03
    SA-11Developer Testing and EvaluationSASystem and Services Acquisition6.2.3, 6.2.3.1, 6.2.4, 6.5.6ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-06
    SA-11(2)Threat Modeling and Vulnerability AnalysesSASystem and Services Acquisition11.4.1, 11.4.4, 12.4.2.1, 6.2.1, 6.2.2, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.4.1, 6.4.2, A1.2.3GV.OC-01, PR.PS-06
    SA-11(5)Penetration TestingSASystem and Services Acquisition11.4, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 11.4.5, 11.4.6, 11.4.7, 12.4.2.1, 6.2.1, 6.2.2, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.4.1, 6.4.2, 6.5.6, A1.2.3, A3.2.4ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-06
    SA-11(6)Attack Surface ReviewsSASystem and Services Acquisition11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.3.2, 6.5.6ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-02, PR.PS-06
    SA-11(7)Verify Scope of Testing and EvaluationSASystem and Services Acquisition11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.3.2, 6.5.6ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-02, PR.PS-06
    SA-15Development Process, Standards, and ToolsSASystem and Services Acquisition6.2, 6.2.1, 6.2.4PR.PS-06
    SA-15(5)Attack Surface ReductionSASystem and Services Acquisition1.1, 1.2, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 6.1, 6.2, 6.2.1, 8.3.2, 8.5, 8.5.1PR.DS-10, PR.IR-01, PR.IR-03, PR.PS-05
    SA-23SpecializationSASystem and Services Acquisition6.2, 6.2.1GV.SC-09, ID.RA-09, PR.PS-06
    SC-1Policy and ProceduresSCSystem and Communications Protection1.1, 1.1.1, 1.2, 10.1.1, 11.1.1, 11.2.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SC-7(18)Fail SecureSCSystem and Communications Protection1.2, 6.1, 6.2, 6.2.1, 8.5, 8.5.1PR.IR-01, PR.IR-03
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications Protection3.7.5, 4.2, 4.2.1, 4.2.1.2, 8.3.2, A2.1, A2.1.1, A2.1.2PR.DS-02
    SC-8(1)Cryptographic ProtectionSCSystem and Communications Protection12.3.3, 2.2.7, 3.3.2, 4.2, 4.2.1, 4.2.1.2, 8.3.2, A2.1, A2.1.1, A2.1.2PR.DS-01, PR.DS-02, PR.DS-10
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications Protection12.3.3, 2.2.7, 3.3.2, 8.3.2PR.DS-01, PR.DS-02, PR.DS-10
    SC-13Cryptographic ProtectionSCSystem and Communications Protection12.3.3, 2.2.7, 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 8.3.2, 9.4PR.DS-01, PR.DS-02, PR.DS-10
    SC-16(1)Integrity VerificationSCSystem and Communications Protection3.7.5PR.DS-02
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications Protection11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.3.3ID.RA-08, PR.PS-02
    SC-28Protection of Information at RestSCSystem and Communications Protection1.5, 1.5.1, 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 8.3.2, 9.4PR.DS-01
    SC-28(1)Cryptographic ProtectionSCSystem and Communications Protection3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 3.7.5, 8.3.2, 9.4PR.DS-01, PR.DS-02
    SC-28(2)Offline StorageSCSystem and Communications Protection12.10.1, 9.4.1.1, 9.4.1.2PR.DS-11
    SC-48Sensor RelocationSCSystem and Communications Protection10.4, 10.4.1, 10.4.1.1ID.RA-03
    SI-1Policy and ProceduresSISystem and Information Integrity1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SI-2Flaw RemediationSISystem and Information Integrity11.3, 5.3, 5.3.1, 6.3, 6.3.1, 6.3.3ID.RA-01, ID.RA-08, PR.PS-02
    SI-2(4)Automated Patch Management ToolsSISystem and Information Integrity6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3PR.PS-02
    SI-3Malicious Code ProtectionSISystem and Information Integrity11.2, 11.3, 4.1, 4.2.1, 5.2, 5.2.1, 5.2.2, 5.3, 5.3.1, 5.3.2, 5.3.2.1, 5.3.3, 5.3.4, 5.3.5, 6.3, 6.3.1, 6.3.3DE.CM-09, ID.RA-01, ID.RA-08, PR.PS-02
    SI-4System MonitoringSISystem and Information Integrity10.1, 10.3.3, 10.4, 10.4.1, 10.4.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.2, 4.1, 4.2.1, A3.3.1, A3.5DE.AE-03, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-04
    SI-4(1)System-wide Intrusion Detection SystemSISystem and Information Integrity1.4.3, 11.5, 11.5.1, 11.5.1.1DE.CM-01
    SI-4(5)System-generated AlertsSISystem and Information Integrity10.2, 10.4, 10.4.1, 10.4.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3DE.CM-01, PR.PS-04
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information Integrity3.1, A3.2.6.1DE.CM-03
    SI-4(12)Automated Organization-generated AlertsSISystem and Information IntegrityA3.2.6.1DE.AE-06
    SI-4(16)Correlate Monitoring InformationSISystem and Information Integrity10.4.1.1, 12.10.5DE.AE-03, DE.AE-06
    SI-4(24)Indicators of CompromiseSISystem and Information Integrity10.3.4, 10.4, 11.5, 11.5.2, 11.6.1DE.CM-09
    SI-4(25)Optimize Network Traffic AnalysisSISystem and Information Integrity1.4.2, 1.4.3, 11.2.1, 11.5, 11.5.1, 11.5.1.1DE.CM-01
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information Integrity11.2, 4.1, 4.2.1, 6.3.1DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information Integrity6.3.1DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    SI-7Software, Firmware, and Information IntegritySISystem and Information Integrity10.3.4, 11.2, 11.5, 11.5.2, 11.6.1, 4.1, 4.2.1DE.CM-09
    SI-7(6)Cryptographic ProtectionSISystem and Information Integrity12.3.3, 2.2.7, 3.3.2, 8.3.2PR.DS-01, PR.DS-02, PR.DS-10
    SI-12Information Management and RetentionSISystem and Information Integrity10.5, 10.5.1, 11.4.1, 3.2, 3.2.1, 9.4.6, 9.4.7ID.AM-07
    SI-12(3)Information DisposalSISystem and Information Integrity10.5.1, 9.4.6, 9.4.7ID.AM-07
    MP-1Policy and ProceduresMPMedia Protection1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.4, 9.4.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.AM-08, PR.DS-01, PR.DS-02, PR.DS-10
    MP-2Media AccessMPMedia Protection1.5, 1.5.1, 5.1DE.CM-09
    MP-4Media StorageMPMedia Protection9.1, 9.4, 9.4.1, 9.4.1.2ID.AM-07
    PS-1Policy and ProceduresPSPersonnel Security1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.2, 12.2.1, 12.7, 12.7.1, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-04, GV.SC-01, GV.SC-03
    PS-2Position Risk DesignationPSPersonnel Security12.7, 12.7.1, 6.2.2GV.RR-02, PR.AA-05
    PS-9Position DescriptionsPSPersonnel Security1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.3GV.RM-05, GV.RR-02
    PM-1Information Security Program PlanPMProgram Management1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1.2GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-09
    PM-2Information Security Program Leadership RolePMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3GV.RM-05, GV.RR-01, GV.RR-02
    PM-4Plan of Action and Milestones ProcessPMProgram Management11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1ID.IM-01, ID.IM-02, ID.RA-01, ID.RA-08, PR.PS-02
    PM-5System InventoryPMProgram Management11.2, 11.2.2, 6.3.2, 9.5.1, 9.5.1.1GV.SC-04, ID.AM-01, ID.AM-02, ID.AM-08
    PM-5(1)Inventory of Personally Identifiable InformationPMProgram Management12.5.1ID.AM-07
    PM-6Measures of PerformancePMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3GV.OV-01, GV.OV-03, GV.RM-05, GV.RR-01, GV.RR-02, GV.SC-09, ID.IM-03
    PM-7Enterprise ArchitecturePMProgram Management1.2PR.IR-01, PR.IR-03
    PM-8Critical Infrastructure PlanPMProgram Management12.4, 12.4.2, A3.1, A3.1.1GV.OC-03, GV.SC-05, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05
    PM-9Risk Management StrategyPMProgram Management12.3GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-02, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, ID.RA-04
    PM-13Security and Privacy WorkforcePMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 8.3.8, 9.1.2, 9.5.1, 9.5.1.3, A3.1.3, A3.1.4GV.RM-05, GV.RR-02
    PM-14Testing, Training, and MonitoringPMProgram Management10.7, 10.7.1, 10.7.2, 10.7.3, A3.1.4GV.OC-03
    PM-15Security and Privacy Groups and AssociationsPMProgram Management6.3, 6.3.1, A3.5.1DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    PM-16Threat Awareness ProgramPMProgram Management6.3, A3.5.1DE.AE-07, ID.RA-03, ID.RA-08
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram Management6.3.1DE.AE-07, ID.RA-02, ID.RA-03, ID.RA-08
    PM-28Risk FramingPMProgram Management12.3.1, 12.3.2GV.OC-01, GV.RM-04, GV.RM-06, GV.RM-07, ID.RA-05, ID.RA-06
    PM-29Risk Management Program Leadership RolesPMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.3, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-05, GV.RM-06, GV.RR-01, GV.RR-02, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10
    PM-31Continuous Monitoring StrategyPMProgram Management10.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, A3.3.1, A3.5DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-04
    PT-1Policy and ProceduresPTPII Processing and Transparency1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1GV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03
    SR-1Policy and ProceduresSRSupply Chain Risk Management1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.3, 8.3.8, 9.1.1, A2.1.3GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk Management12.4.2, 12.4.2.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2, 8.2.3GV.OC-02, GV.OC-03, GV.SC-02, GV.SC-05, GV.SC-06, GV.SC-10
    SR-6Supplier Assessments and ReviewsSRSupply Chain Risk Management12.4.2, 12.4.2.1, 12.8.4GV.SC-07, ID.IM-01, ID.IM-02
    SR-6(1)Testing and AnalysisSRSupply Chain Risk Management12.4.2, 12.4.2.1, 12.8.4GV.SC-07, ID.IM-01, ID.IM-02
    SR-7Supply Chain Operations SecuritySRSupply Chain Risk Management1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10
    SR-9Tamper Resistance and DetectionSRSupply Chain Risk Management9.5.1ID.RA-09
    SR-9(1)Multiple Stages of System Development Life CycleSRSupply Chain Risk Management9.5.1ID.RA-09

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.