NIST SP 800-53 for small software teams

SP 800-53 Revision 5 has 20 control families and three security baselines. A small team does not need to read all of it. Here is how to find the controls that apply and document them once.

What NIST SP 800-53 is, in one paragraph

NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations, is the catalog of controls federal systems are measured against. The current revision is Revision 5, first published in September 2020. NIST issues minor releases of the catalog, and the most recent at the time of writing is release 5.2.0 from August 2025. Revision 5 merged privacy controls into the main catalog instead of keeping them in a separate appendix, and it added a family for supply chain risk management.

The catalog is large, but it is not a checklist you must complete in full. Small teams succeed with it by understanding its structure, selecting the right baseline, and tailoring.

The 20 control families

Revision 5 organizes controls into 20 families, each with a two-letter identifier. Knowing the families helps you route work: some belong to engineering, some to operations, and many are organization-wide policy that a small vendor inherits from the agency or prime.

  • Mostly engineering: Access Control (AC), Audit and Accountability (AU), Identification and Authentication (IA), System and Communications Protection (SC), System and Information Integrity (SI), Configuration Management (CM)
  • Mostly operations: Contingency Planning (CP), Incident Response (IR), Maintenance (MA), Media Protection (MP)
  • Mostly program and policy: Assessment, Authorization and Monitoring (CA), Planning (PL), Program Management (PM), Risk Assessment (RA), System and Services Acquisition (SA), Supply Chain Risk Management (SR)
  • Mostly people and facilities: Awareness and Training (AT), Personnel Security (PS), Physical and Environmental Protection (PE)
  • Privacy: PII Processing and Transparency (PT)

How an SP 800-53 control is structured

Each control has a base statement of what must be done, a discussion section that explains intent, a list of related controls, and often a set of control enhancements that add strength or specificity. Enhancements are numbered after the base control, so AC-2(1) is the first enhancement to AC-2, Account Management. Baselines specify which enhancements are required, and higher baselines generally require more of them.

Many controls include organization-defined parameters: blanks the organization fills in, such as a time period, a frequency or a list of roles. These are where vague documentation usually comes from. A statement that says sessions time out after an organization-defined period is not evidence. A statement that names the period, the setting and the place it is configured is.

Baselines: low, moderate and high

You do not choose controls from scratch. FIPS 199 has the agency rate the potential impact of a loss of confidentiality, integrity and availability as low, moderate or high. Because those three ratings can differ, FIPS 200 applies a high water mark: the system takes the highest of the three as its overall impact level.

That impact level selects one of the three security control baselines in NIST SP 800-53B: low, moderate or high. SP 800-53B also defines a privacy baseline that applies regardless of impact level. The baseline is your starting set. For most small teams supporting a civilian agency, the system categorization is set by the agency, so the first question to ask is simply: which baseline are we working to?

Tailoring: making the baseline fit your system

A baseline is a starting point, not the answer. SP 800-53B describes tailoring, which can include:

  • Identifying and designating common controls that are provided once and inherited by many systems
  • Applying scoping considerations, so controls that do not apply to your technology or environment are documented as such
  • Selecting compensating controls when a baseline control cannot be implemented as written
  • Assigning values to organization-defined parameters, such as how long a session can sit idle
  • Supplementing the baseline with additional controls or enhancements when risk calls for it

Mapping controls without drowning in paperwork

The paperwork burden comes mainly from documenting the same fact many times. These habits keep it under control.

  • Start with inheritance. List what the cloud provider, the agency and the prime already cover, and get it in writing. For a small team this often removes a large share of the physical, personnel and policy controls from your plate.
  • Map controls to things you already do. A pull request review process supports configuration and change control. Centralized logging supports audit controls. Single sign-on supports identification and authentication. Write each fact once and reference it from every control it supports, so a change to the process means one update, not ten.
  • Keep the evidence where the work happens. Pipeline logs, scan reports and ticket history are better evidence than a screenshot pasted into a document months later.
  • Write implementation statements in plain, specific language: what component, what setting, who reviews it, how often.
  • Track gaps honestly in the plan of action and milestones, with owners and dates.
  • Review your statements whenever the architecture changes. A new service, data store or external connection can change which controls apply and how.

A practical first month for a small team

If you are new to 800-53 work, this sequence keeps effort where it matters.

  • Week 1: confirm the baseline, get the agency or prime templates, and collect the responsibility matrix from your hosting provider.
  • Week 2: mark every control in the baseline as inherited, shared, system-specific, or not applicable, with a one-line reason for each.
  • Week 3: draft implementation statements for the engineering families first: AC, AU, IA, SC, SI and CM.
  • Week 4: connect evidence sources, such as pipeline logs, scan output and change tickets, and open POA&M items for real gaps.
  • After that: review the draft with the security officer, fix what they flag, and set a monthly time to keep the documentation current.

How SP 800-53 fits with the RMF and assessments

SP 800-53 is the catalog. The Risk Management Framework in SP 800-37 is the process that uses it: categorize, select, implement, assess, authorize and monitor. NIST SP 800-53A provides the matching assessment procedures, which tell you how an assessor will examine, interview and test each control. Reading the 800-53A procedures for your highest-risk controls is one of the fastest ways to learn what good evidence looks like.

Expect the catalog to keep moving. Minor releases such as 5.2.0 add or revise individual controls, and agencies adopt new releases on their own schedules. Note which release your documentation targets, and check with the security officer before updating references to a newer one.

If your organization handles controlled unclassified information on its own systems rather than a federal one, the requirements usually come from NIST SP 800-171 instead, whose current revision is Revision 3 from May 2024. Check your contract to see which applies.

Where Foundry Peak fits

Foundry Peak builds to NIST SP 800-53 Revision 5 controls on federal work and writes control implementation statements alongside the code. We do not claim certifications, and we do not sell compliance as a product. We help agencies and primes produce systems, and evidence, that hold up under assessment.

Sources

Common questions

How many control families are in NIST SP 800-53 Rev. 5?

NIST SP 800-53 Revision 5 organizes its controls into 20 families, each with a two-letter identifier such as AC for Access Control and SR for Supply Chain Risk Management. Revision 5 added the PII Processing and Transparency and Supply Chain Risk Management families and merged privacy controls into the main catalog.

How do you choose an SP 800-53 baseline?

The agency categorizes the system under FIPS 199 by rating confidentiality, integrity and availability as low, moderate or high. Under FIPS 200, the highest of the three becomes the system impact level, which selects the low, moderate or high security baseline in NIST SP 800-53B. A separate privacy baseline also applies.

What does tailoring mean in NIST SP 800-53?

Tailoring adapts a control baseline to a specific system. Under SP 800-53B it can include designating common controls, applying scoping considerations, choosing compensating controls, setting values for organization-defined parameters, and adding controls or enhancements when risk requires them. Each tailoring decision should be documented with its reason.

Tell us what you're building.

We reply within one business day. If we're not the right fit, we'll say so and point you somewhere better.