Glossary

NIST 800-53

NIST Special Publication 800-53 is the US federal government’s control catalog: hundreds of security and privacy controls organized into 20 families (access control, audit, incident response, and so on), with Low/Moderate/High baselines selecting which apply. Where NIST CSF is a taxonomy, 800-53 is the exhaustive parts list.

Why a startup would ever meet it

Federal gravity. FedRAMP authorizations assess against 800-53 baselines; FISMA obligations flow it down to agencies’ vendors; and defense-adjacent work meets its cousin 800-171 (the CUI-protection subset behind CMMC). If government or defense customers are in your pipeline, 800-53’s vocabulary is arriving with them.

How it compares to what you have

An 800-53 Moderate baseline is substantially deeper than SOC 2 — more controls, more specificity, more documentation. But the overlap is real: a mature SOC 2/ISO control set typically satisfies a meaningful fraction on day one, and published mappings make the gap analysis mechanical rather than mysterious.

The practical posture

Don’t implement 800-53 speculatively — its weight is only justified by federal revenue. Do keep your control set mapped, so when the first agency-adjacent deal appears you can answer “where do you stand against 800-53 Moderate?” with a gap list instead of a shrug. That answer alone clears many early federal conversations.

Related Terms

CMMC — CMMC is the DoD's cybersecurity certification for contractors — three levels, anchored to NIST 800-171, now appearing in defense contracts and flow-downs.

FedRAMP — FedRAMP is the US government's cloud security authorization program — mandatory for selling cloud services to federal agencies, and a major undertaking.

NIST CSF — NIST CSF is the voluntary framework organizing security into six functions — Govern, Identify, Protect, Detect, Respond, Recover — used as a common language.