1,196
Controls across 20 families
Rev 5 is the full catalog — security and privacy controls in 20 families. You don't implement all of them; your impact level decides which baseline applies.
NIST 800-53 is the 1,196-control catalog behind every federal Authority to Operate — the controls FISMA, FedRAMP, and the RMF all draw from. If you operate or sell to a federal system, you can't go live without an ATO, and that's a 12-month process built on these controls. We get you authorization-ready.
Book a NIST 800-53 Strategy Call →// WHY 800-53, WHY NOW
1,196
Rev 5 is the full catalog — security and privacy controls in 20 families. You don't implement all of them; your impact level decides which baseline applies.
287
Where most federal civilian systems land, and the dominant FedRAMP path. FedRAMP Moderate starts from these 287 controls and layers its own parameters on top.
~12–15 MO
The RMF runs categorize through authorize over roughly a year, then continuous monitoring. No federal system goes to production without that ATO.
// CONTROLS AREN'T THE AUTHORIZATION
Implementing 800-53 controls is necessary but not sufficient. A federal system goes live only when an authorizing official grants an ATO — and that requires the full RMF: a FIPS 199 categorization, the right baseline from 800-53B, a System Security Plan, and an independent assessment proving the controls actually work. Controls on paper with no SSP, no assessment, and no authorization is the profile that stalls in the RMF and never reaches production.
// THE CATALOG // THREE BASELINES
You don't implement the whole catalog. A FIPS 199 categorization sets your impact level, and 800-53B picks the baseline. Moderate is where most systems land — and the dominant FedRAMP path.
The default target for most federal civilian systems: 287 controls for systems where a loss of confidentiality, integrity, or availability would have a serious adverse effect. A FedRAMP Moderate authorization starts here and layers FedRAMP parameter values on top. The two baselines below flank it — chosen only when your impact level calls for them.
// LOW · 149
Low Baseline
For systems where a compromise would have a limited adverse effect — limited loss, limited harm.
// HIGH · 370
High Baseline
For severe or catastrophic effect — major loss, severe harm, or national-security impact.
Categorize first. The wrong impact level breaks the whole authorization.
// THE RMF
The Risk Management Framework (NIST 800-37) turns the catalog into an authorization. The amber stages are where outside parties enter — the independent assessment, and the authorizing official who grants the ATO.
Categorize
FIPS 199
WK 1–3
Select
Baseline & Tailor
WK 3–6
Implement
SSP & Controls
MO 2–9
Assess
Control Assessment
MO 9–12
Authorize
ATO Grant
MO 12–15
Monitor
Continuous Monitoring
ONGOING
Amber stages are where outside parties enter — the independent security control assessment, and the authorizing official's ATO decision. The authorization is sustained by continuous monitoring, not a one-time pass.
// IS THIS YOU?
// 01 // FEDERAL SALE
Federal agencies can't buy your service without a FedRAMP authorization — and FedRAMP is 800-53 at the Moderate baseline plus its parameters. No ATO, no federal market.
// 02 // ATO DEADLINE
You have a federal system waiting on an Authority to Operate. The RMF is a ~12-month process — if the go-live date is fixed, the authorization clock started yesterday.
// 03 // FISMA / AGENCY
Under FISMA and OMB A-130, your agency or integrator system runs on 800-53 through the RMF. If the categorization or SSP is shaky, the authorization is at risk.
// WHAT WE DO
// Phase 01 · Scope
We run the FIPS 199 categorization that sets your impact level, then select and tailor the right 800-53B baseline — the decision everything downstream depends on.
// Phase 02 · Implement
We build the System Security Plan and stand up the controls with the evidence an assessor requires — documentation that proves implementation, not just intent.
// Phase 03 · Authorize
We prepare you for the independent assessment, support the authorization decision, and stand up the continuous monitoring that keeps the ATO alive.
// THE RMF TAKES A YEAR
// FREQUENTLY ASKED
It's not a preference — it's set by the impact of a confidentiality, integrity, or availability compromise, categorized with FIPS 199. NIST SP 800-53B defines three baselines: Low (149 controls) for a limited adverse effect, Moderate (287) for a serious adverse effect, and High (370) for a severe or catastrophic effect.
Moderate is the default for most federal civilian systems and the dominant FedRAMP path — FedRAMP Moderate starts from those 287 controls and adds its own parameters. Most engagements land at Moderate, but categorization comes first: the wrong impact level either under-protects a system that won't authorize or over-builds controls you didn't need.
The Risk Management Framework (NIST SP 800-37) is the six-step process federal systems follow: Categorize (FIPS 199), Select the baseline (800-53B), Implement the controls and document them in an SSP, Assess through an independent control assessment (800-53A), Authorize — the ATO, granted by an authorizing official who accepts the residual risk — and Monitor continuously after.
800-53 is the control catalog; the RMF is the process that turns those controls into an authorization. No federal system reaches production without an ATO. A first authorization commonly runs about 12 to 15 months, and it's not permanent — monitoring and reauthorization keep it alive.
If you want to sell cloud services to federal agencies, yes — through FedRAMP, which is built directly on 800-53. A cloud provider implements the 800-53 controls at the appropriate baseline (most commonly Moderate, the 287-control set plus FedRAMP parameters) to earn an ATO that lets agencies buy and use the service. Without it, you generally can't sell into the federal cloud market.
Beyond government, Rev 5 is technology-neutral and outcome-based, and is widely adopted voluntarily by state, local, and private-sector organizations — and it's the backbone other frameworks like FedRAMP and CMMC build on. Aligning to 800-53 is often the most direct path to the controls those programs require.
Revision 5 (September 2020, the current version) expanded the catalog to 1,196 controls across 20 families, adding two families — PT (PII Processing and Transparency) and SR (Supply Chain Risk Management) — and integrating privacy throughout the catalog instead of isolating it in the old Appendix J. It made control language outcome-based and technology-neutral for modern cloud, and dropped "Federal" from the title.
Rev 5 also moved the Low/Moderate/High baselines into a companion document, NIST SP 800-53B, so baseline assignments can update without revising the whole catalog. Rev 5 is what you build to today — there's no successor revision you should be targeting instead. Build to Rev 5 against the correct 800-53B baseline for your impact level.
// THE NEXT MOVE
Book a 30-minute NIST 800-53 strategy call with a WatchUr6 advisor. Bring the system or federal opportunity driving this, whether you're targeting FedRAMP, and your go-live or ATO timeline. You'll walk away with the right impact categorization, a baseline that fits, and a realistic path to authorization — whether you hire us or not.
Book a NIST 800-53 Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED