NIST SP 800-53 — Security and Privacy Controls for Information Systems and Organizations
NIS2 says what you must achieve, never how you demonstrate it. NIST 800-53 is the reference published for that purpose. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
NIST SP 800-53 is a US federal control catalogue. It is not a European compliance route and no supervisor will accept it as one: it carries no certification, and mapping to it does not evidence NIS2 compliance. Its value here is different and real — a group that already operates an 800-53 control set, typically because of US federal or defence work, can see which families already carry each article 21(2) measure instead of rebuilding from nothing.
We put that first because it is the most expensive misunderstanding about any national framework. For a European compliance route use ISO/IEC 27001 or the national framework. Use 800-53 to reuse work already done, not to demonstrate compliance.
What it is built on
NIST 800-53 does not invent its own taxonomy. It sits on A control catalogue organised into families, with baselines selected by system impact level.
Revision 5 organises the catalogue into 20 control families, up from 18 in Rev. 4: PT (PII processing and transparency) and SR (supply chain risk management) were added. Controls are selected through baselines and tailoring rather than adopted wholesale.
How it covers article 21(2)
Family-level mapping. Each article 21(2) measure is mapped to the families that carry the relevant controls. Family identifiers are stable across the revision and publicly documented.
Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
| Art. 21(2) | Measure | NIST 800-53 — NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) | Risk analysis and security policies | RA PL PM |
| (b) | Incident handling | IR AU SI |
| (c) | Business continuity | CP PE |
| (d) | Supply chain security | SR SA |
| (e) | Security in acquisition, development and maintenance | SA CM MA RA SI |
| (f) | Assessing the effectiveness of the measures | CA PM |
| (g) | Basic cyber hygiene and cybersecurity training | AT SI CM |
| (h) | Cryptography and encryption | SC |
| (i) | Human resources security, access control and asset management | PS AC IA CM MP PE |
| (j) | Multi-factor authentication and secured communications | IA AC SC |
20 NIST SP 800-53 Rev. 5 control family units, in full
- AC — Access Control
- AT — Awareness and Training
- AU — Audit and Accountability
- CA — Assessment, Authorization and Monitoring
- CM — Configuration Management
- CP — Contingency Planning
- IA — Identification and Authentication
- IR — Incident Response
- MA — Maintenance
- MP — Media Protection
- PE — Physical and Environmental Protection
- PL — Planning
- PM — Program Management
- PS — Personnel Security
- PT — PII Processing and Transparency
- RA — Risk Assessment
- SA — System and Services Acquisition
- SC — System and Communications Protection
- SI — System and Information Integrity
- SR — Supply Chain Risk Management
We are not affiliated with National Institute of Standards and Technology (NIST). NIST 800-53 and related marks belong to their owners.