Directive NIS2 European Union
Revision 5 · Rev. 5

NIST SP 800-53 — Security and Privacy Controls for Information Systems and Organizations

NIS2 says what you must achieve, never how you demonstrate it. NIST 800-53 is the reference published for that purpose. If you operate there, this is what your regulator reads.

Member states using it
0

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

NIST SP 800-53 is a US federal control catalogue. It is not a European compliance route and no supervisor will accept it as one: it carries no certification, and mapping to it does not evidence NIS2 compliance. Its value here is different and real — a group that already operates an 800-53 control set, typically because of US federal or defence work, can see which families already carry each article 21(2) measure instead of rebuilding from nothing.

We put that first because it is the most expensive misunderstanding about any national framework. For a European compliance route use ISO/IEC 27001 or the national framework. Use 800-53 to reuse work already done, not to demonstrate compliance.

What it is built on

NIST 800-53 does not invent its own taxonomy. It sits on A control catalogue organised into families, with baselines selected by system impact level.

Revision 5 organises the catalogue into 20 control families, up from 18 in Rev. 4: PT (PII processing and transparency) and SR (supply chain risk management) were added. Controls are selected through baselines and tailoring rather than adopted wholesale.

Mapping

How it covers article 21(2)


Basis

Family-level mapping. Each article 21(2) measure is mapped to the families that carry the relevant controls. Family identifiers are stable across the revision and publicly documented.

Limit of this mapping

Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Mapped at the level of
NIST SP 800-53 Rev. 5 control family
Units in the framework
20
Units carrying article 21(2)
19
Each of the ten risk-management measures of article 21(2), mapped to the NIST SP 800-53 Rev. 5 control family units of NIST 800-53
Art. 21(2) Measure NIST 800-53 — NIST SP 800-53 Rev. 5 control family
(a) Risk analysis and security policies RA PL PM
(b) Incident handling IR AU SI
(c) Business continuity CP PE
(d) Supply chain security SR SA
(e) Security in acquisition, development and maintenance SA CM MA RA SI
(f) Assessing the effectiveness of the measures CA PM
(g) Basic cyber hygiene and cybersecurity training AT SI CM
(h) Cryptography and encryption SC
(i) Human resources security, access control and asset management PS AC IA CM MP PE
(j) Multi-factor authentication and secured communications IA AC SC
20 NIST SP 800-53 Rev. 5 control family units, in full
  • AC — Access Control
  • AT — Awareness and Training
  • AU — Audit and Accountability
  • CA — Assessment, Authorization and Monitoring
  • CM — Configuration Management
  • CP — Contingency Planning
  • IA — Identification and Authentication
  • IR — Incident Response
  • MA — Maintenance
  • MP — Media Protection
  • PE — Physical and Environmental Protection
  • PL — Planning
  • PM — Program Management
  • PS — Personnel Security
  • PT — PII Processing and Transparency
  • RA — Risk Assessment
  • SA — System and Services Acquisition
  • SC — System and Communications Protection
  • SI — System and Information Integrity
  • SR — Supply Chain Risk Management
Sources

We are not affiliated with National Institute of Standards and Technology (NIST). NIST 800-53 and related marks belong to their owners.

Cart 0