Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

NIST 800-53 Control Families Explained: All 20 in Plain English

August 11, 2026
hero-nist-800-53-control-families-explained-1.png

NIST 800-53 control families are the 20 topic groups that organize every security and privacy control in the catalog, from who gets a login to how a vendor gets vetted. Each family covers one slice of an organization’s security posture. Together they make up NIST SP 800-53 Revision 5, the federal control catalog published by the National Institute of Standards and Technology.

If you have already read what NIST SP 800-53 is and now want to know what the standard actually asks you to do, the families are where that gets specific. This guide walks through all 20, explains why two of them are new, and flags which ones carry the most weight for a small or mid-size business working with a managed IT provider.

We will not repeat the full history of the standard here. The pillar guide covers that. This page goes one level deeper, into the structure itself.

What Is a NIST 800-53 Control Family?

A control family is a group of related security or privacy controls, bundled under one topic and one two-letter ID. Access Control (AC) is a family. Incident Response (IR) is a family. Each one addresses a distinct risk area, and each control inside it is numbered (AC-1, AC-2, and so on).

Revision 5 of NIST SP 800-53 organizes its entire catalog into 20 control families. That is a fixed structural number set by NIST, not an estimate. The actual count of individual controls inside those 20 families is much larger and harder to pin down exactly, since NIST periodically adds, retires, or merges specific controls through maintenance releases. The family count of 20, though, has held steady since Revision 5 was published.

Think of the families as the table of contents for the whole standard. An auditor, a system owner, or an MSP managing your environment does not read 800-53 as one long list. They work family by family: first Access Control, then Audit and Accountability, then Configuration Management, and so on through all 20.

All 20 NIST 800-53 Control Families

Every family gets a two-letter identifier that shows up in front of every control number inside it (AC-2, AU-6, IR-4, and so on). Here is the full list, in the order NIST presents them:

IDControl FamilyWhat It Covers
ACAccess ControlWho can get into systems, and what they can do once inside
ATAwareness and TrainingKeeping staff able to recognize and avoid security risks
AUAudit and AccountabilityLogging activity so you can see who did what, and when
CAAssessment, Authorization, and MonitoringChecking controls actually work, then approving the system to run
CMConfiguration ManagementLocking down how systems are set up and tracking changes
CPContingency PlanningKeeping the business running, or recovering fast, after a disruption
IAIdentification and AuthenticationProving a user or device is who it claims to be
IRIncident ResponseDetecting, reporting, and containing a security incident
MAMaintenanceControlling who can service systems, and how
MPMedia ProtectionProtecting data on drives, backups, and removable media
PEPhysical and Environmental ProtectionLocking down the physical space around the equipment
PLPlanningThe documented security and privacy plans that guide everything else
PMProgram ManagementOrganization-wide security governance, not tied to one system
PSPersonnel SecurityVetting people before they get access, and cutting it off when they leave
PTPII Processing and TransparencyHandling personal information responsibly (new in Revision 5)
RARisk AssessmentFinding and ranking the threats that matter most
SASystem and Services AcquisitionBuilding security into what you buy or build, not bolting it on later
SCSystem and Communications ProtectionProtecting data as it moves and while it sits in storage
SISystem and Information IntegrityCatching and fixing problems like malware or corrupted data
SRSupply Chain Risk ManagementVetting the vendors and components behind your systems (new in Revision 5)

That table is the whole map. Everything else in NIST 800-53, every control number you will ever see cited in an assessment or an SSP, falls under one of these 20 headings.

Why Revision 5 Added Two New Families (PT and SR)

Two of those 20 families, PT and SR, did not exist in the previous version of the standard. Why PT (PII Processing and Transparency) is new: earlier versions of 800-53 treated privacy controls as a separate track from security controls. Revision 5 folded them into the same catalog. PT now sits alongside Access Control and Incident Response as a first-class family, not a bolt-on appendix. That single change reflects a broader shift: NIST no longer treats “protect the system” and “protect the person’s data inside the system” as two different jobs.

New Control Families

Why SR (Supply Chain Risk Management) is new: modern breaches increasingly start with a vendor, a component, or a piece of third-party code rather than a direct attack on the target organization. SR gives supply-chain risk its own dedicated family instead of scattering it across other topics.

A few things worth knowing about how these two additions changed the catalog’s structure:

  • Privacy is no longer siloed. PT controls live in the same numbered system as every security control, so a system owner selects and tracks them the same way. – Supply chain risk got promoted from “something CM or SA touches on” to its own named family with its own control set. Rev 5 treats privacy and supply chain as core security concerns, not adjacent topics. – Every one of the 20 families, including PT and SR, still gets tailored to an organization’s actual risk. Not every control in every family applies at every impact level, which is the baseline concept the next section covers.

Together, these two additions tell you where the standard is heading. NIST is not just cataloging technical controls anymore. It is cataloging the full set of risks a modern system faces, from an employee’s login to a vendor’s unpatched component.

How Control Families Connect to Baselines

Not every business needs all 20 families running at full strength. NIST adds a second layer on top of the family structure to handle that: the baseline.

Select and Tailor Baselines

There is a Low baseline, a Moderate baseline, a High baseline, and a separate Privacy baseline that pulls specifically from the PT family and related privacy controls elsewhere in the catalog.

Selecting and applying a baseline is a two-step process:

  • Select. Pick the baseline that matches your system’s impact level, Low, Moderate, or High, plus the Privacy baseline where personal information is involved.
  • Tailor. Add or remove specific controls from that baseline, with documented justification, based on your organization’s actual risk.

That select-then-tailor sequence is not a standalone idea. It is one step inside a larger seven-step process called the Risk Management Framework. If you want to see how the two publications fit together, read NIST 800-37 vs 800-53.

Either way, the practical question stays the same. Which controls, out of which families, actually apply to your system?

Which Families Carry the Most Weight for a Small or Mid-Size Business

Most small and mid-size businesses never touch all 20 families directly. In an MSP-managed environment, effort concentrates on the families that do the heaviest daily work.

FamilyWhat It Looks Like Day to Day
AC, Access ControlUnique logins, least-privilege access, multifactor authentication
AU, Audit and AccountabilityCentralized logging and regular log review
CM, Configuration ManagementHardened, documented system baselines
IR, Incident ResponseA tested response plan, with fast reporting if a DoD contract requires it
SC, System and Communications ProtectionNetwork segmentation, encryption in transit and at rest
SI, System and Information IntegrityPatch management, endpoint detection, vulnerability scanning

For a defense contractor, Incident Response carries extra weight.

Six families, Access Control, Audit and Accountability, Configuration Management, Incident Response, System and Communications Protection, and System and Information Integrity, cover most of the day-to-day work a small or mid-size business will actually do under NIST 800-53.

If your business is a DoD contractor or subcontractor, the standard you need to meet is usually narrower than the full 800-53 catalog. See NIST 800-53 vs CMMC for how the two relate and which one actually governs your scope.

Many businesses hand this work to a managed IT provider that already runs these controls as standard practice, rather than building a compliance program from scratch.

See Where You Stand

You do not need to read all 20 families end to end to know where your organization stands today. Answer a few plain-English questions and see your gaps against the families that matter most.

Take the free 2-minute NIST 800-53 Risk-Check

Frequently Asked Questions

NIST SP 800-53 Revision 5 organizes its entire catalog into 20 control families. Two of them, PII Processing and Transparency and Supply Chain Risk Management, were added in Revision 5 and did not exist in the prior version.

No. From there, organizations tailor the baseline by adding or removing controls with documented justification, based on their actual risk.

Direct legal obligation falls on federal agencies under FISMA, and on cloud providers seeking FedRAMP authorization. Most private businesses without a direct federal contract are not directly bound.<details> <summary>Which NIST 800-53 control families matter most for a small business working with an MSP?</summary> <p>Six families carry most of the day-to-day weight: Access Control, Audit and Accountability, Configuration Management, Incident Response, System and Communications Protection, and System and Information Integrity. These map to concrete safeguards like MFA, centralized logging, hardened system baselines, a tested incident response plan, network segmentation, and patch management.

NIST 800-53 itself carries no fines, since it is a technical standard, not a statute. Consequences flow through the systems built on top of it: a federal system that cannot meet its baseline does not get an Authorization to Operate, an unauthorized cloud vendor cannot sell to federal agencies, and a contractor that falsely certifies compliance risks False Claims Act liability, contract termination, and debarment from future federal contracts.

Get These Controls Built Into Your Environment, Not Bolted On

Mapping which of the 20 families apply to your systems is only half the job. Implementing and documenting them, so they hold up under an assessment, is the other half.

See our NIST 800-53 and federal compliance IT services, or book a call to walk through where your environment actually stands.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.