NIST 800-53 Control Families Explained: All 20 in Plain English
NIST 800-53 control families are the 20 topic groups that organize every security and privacy control in the catalog, from who gets a login to how a vendor gets vetted. Each family covers one slice of an organization’s security posture. Together they make up NIST SP 800-53 Revision 5, the federal control catalog published by the National Institute of Standards and Technology.
If you have already read what NIST SP 800-53 is and now want to know what the standard actually asks you to do, the families are where that gets specific. This guide walks through all 20, explains why two of them are new, and flags which ones carry the most weight for a small or mid-size business working with a managed IT provider.
We will not repeat the full history of the standard here. The pillar guide covers that. This page goes one level deeper, into the structure itself.
What Is a NIST 800-53 Control Family?
A control family is a group of related security or privacy controls, bundled under one topic and one two-letter ID. Access Control (AC) is a family. Incident Response (IR) is a family. Each one addresses a distinct risk area, and each control inside it is numbered (AC-1, AC-2, and so on).
Revision 5 of NIST SP 800-53 organizes its entire catalog into 20 control families. That is a fixed structural number set by NIST, not an estimate. The actual count of individual controls inside those 20 families is much larger and harder to pin down exactly, since NIST periodically adds, retires, or merges specific controls through maintenance releases. The family count of 20, though, has held steady since Revision 5 was published.
Think of the families as the table of contents for the whole standard. An auditor, a system owner, or an MSP managing your environment does not read 800-53 as one long list. They work family by family: first Access Control, then Audit and Accountability, then Configuration Management, and so on through all 20.
All 20 NIST 800-53 Control Families
Every family gets a two-letter identifier that shows up in front of every control number inside it (AC-2, AU-6, IR-4, and so on). Here is the full list, in the order NIST presents them:
| ID | Control Family | What It Covers |
|---|---|---|
| AC | Access Control | Who can get into systems, and what they can do once inside |
| AT | Awareness and Training | Keeping staff able to recognize and avoid security risks |
| AU | Audit and Accountability | Logging activity so you can see who did what, and when |
| CA | Assessment, Authorization, and Monitoring | Checking controls actually work, then approving the system to run |
| CM | Configuration Management | Locking down how systems are set up and tracking changes |
| CP | Contingency Planning | Keeping the business running, or recovering fast, after a disruption |
| IA | Identification and Authentication | Proving a user or device is who it claims to be |
| IR | Incident Response | Detecting, reporting, and containing a security incident |
| MA | Maintenance | Controlling who can service systems, and how |
| MP | Media Protection | Protecting data on drives, backups, and removable media |
| PE | Physical and Environmental Protection | Locking down the physical space around the equipment |
| PL | Planning | The documented security and privacy plans that guide everything else |
| PM | Program Management | Organization-wide security governance, not tied to one system |
| PS | Personnel Security | Vetting people before they get access, and cutting it off when they leave |
| PT | PII Processing and Transparency | Handling personal information responsibly (new in Revision 5) |
| RA | Risk Assessment | Finding and ranking the threats that matter most |
| SA | System and Services Acquisition | Building security into what you buy or build, not bolting it on later |
| SC | System and Communications Protection | Protecting data as it moves and while it sits in storage |
| SI | System and Information Integrity | Catching and fixing problems like malware or corrupted data |
| SR | Supply Chain Risk Management | Vetting the vendors and components behind your systems (new in Revision 5) |
That table is the whole map. Everything else in NIST 800-53, every control number you will ever see cited in an assessment or an SSP, falls under one of these 20 headings.
Why Revision 5 Added Two New Families (PT and SR)
Two of those 20 families, PT and SR, did not exist in the previous version of the standard. Why PT (PII Processing and Transparency) is new: earlier versions of 800-53 treated privacy controls as a separate track from security controls. Revision 5 folded them into the same catalog. PT now sits alongside Access Control and Incident Response as a first-class family, not a bolt-on appendix. That single change reflects a broader shift: NIST no longer treats “protect the system” and “protect the person’s data inside the system” as two different jobs.

Why SR (Supply Chain Risk Management) is new: modern breaches increasingly start with a vendor, a component, or a piece of third-party code rather than a direct attack on the target organization. SR gives supply-chain risk its own dedicated family instead of scattering it across other topics.
A few things worth knowing about how these two additions changed the catalog’s structure:
- Privacy is no longer siloed. PT controls live in the same numbered system as every security control, so a system owner selects and tracks them the same way. – Supply chain risk got promoted from “something CM or SA touches on” to its own named family with its own control set. Rev 5 treats privacy and supply chain as core security concerns, not adjacent topics. – Every one of the 20 families, including PT and SR, still gets tailored to an organization’s actual risk. Not every control in every family applies at every impact level, which is the baseline concept the next section covers.
Together, these two additions tell you where the standard is heading. NIST is not just cataloging technical controls anymore. It is cataloging the full set of risks a modern system faces, from an employee’s login to a vendor’s unpatched component.
How Control Families Connect to Baselines
Not every business needs all 20 families running at full strength. NIST adds a second layer on top of the family structure to handle that: the baseline.

There is a Low baseline, a Moderate baseline, a High baseline, and a separate Privacy baseline that pulls specifically from the PT family and related privacy controls elsewhere in the catalog.
Selecting and applying a baseline is a two-step process:
- Select. Pick the baseline that matches your system’s impact level, Low, Moderate, or High, plus the Privacy baseline where personal information is involved.
- Tailor. Add or remove specific controls from that baseline, with documented justification, based on your organization’s actual risk.
That select-then-tailor sequence is not a standalone idea. It is one step inside a larger seven-step process called the Risk Management Framework. If you want to see how the two publications fit together, read NIST 800-37 vs 800-53.
Either way, the practical question stays the same. Which controls, out of which families, actually apply to your system?
Which Families Carry the Most Weight for a Small or Mid-Size Business
Most small and mid-size businesses never touch all 20 families directly. In an MSP-managed environment, effort concentrates on the families that do the heaviest daily work.
| Family | What It Looks Like Day to Day |
|---|---|
| AC, Access Control | Unique logins, least-privilege access, multifactor authentication |
| AU, Audit and Accountability | Centralized logging and regular log review |
| CM, Configuration Management | Hardened, documented system baselines |
| IR, Incident Response | A tested response plan, with fast reporting if a DoD contract requires it |
| SC, System and Communications Protection | Network segmentation, encryption in transit and at rest |
| SI, System and Information Integrity | Patch management, endpoint detection, vulnerability scanning |
For a defense contractor, Incident Response carries extra weight.
Six families, Access Control, Audit and Accountability, Configuration Management, Incident Response, System and Communications Protection, and System and Information Integrity, cover most of the day-to-day work a small or mid-size business will actually do under NIST 800-53.
If your business is a DoD contractor or subcontractor, the standard you need to meet is usually narrower than the full 800-53 catalog. See NIST 800-53 vs CMMC for how the two relate and which one actually governs your scope.
Many businesses hand this work to a managed IT provider that already runs these controls as standard practice, rather than building a compliance program from scratch.
See Where You Stand
You do not need to read all 20 families end to end to know where your organization stands today. Answer a few plain-English questions and see your gaps against the families that matter most.
Take the free 2-minute NIST 800-53 Risk-Check
Related Guides
- What Is NIST SP 800-53? The Plain-English Guide
- NIST 800-53 Compliance Checklist: The Practical Starting Point
- NIST 800-53 vs. CMMC: What’s the Difference?
- NIST 800-37 vs. NIST 800-53: What’s the Difference?
Frequently Asked Questions
NIST SP 800-53 Revision 5 organizes its entire catalog into 20 control families. Two of them, PII Processing and Transparency and Supply Chain Risk Management, were added in Revision 5 and did not exist in the prior version.
No. From there, organizations tailor the baseline by adding or removing controls with documented justification, based on their actual risk.
Direct legal obligation falls on federal agencies under FISMA, and on cloud providers seeking FedRAMP authorization. Most private businesses without a direct federal contract are not directly bound.<details> <summary>Which NIST 800-53 control families matter most for a small business working with an MSP?</summary> <p>Six families carry most of the day-to-day weight: Access Control, Audit and Accountability, Configuration Management, Incident Response, System and Communications Protection, and System and Information Integrity. These map to concrete safeguards like MFA, centralized logging, hardened system baselines, a tested incident response plan, network segmentation, and patch management.
NIST 800-53 itself carries no fines, since it is a technical standard, not a statute. Consequences flow through the systems built on top of it: a federal system that cannot meet its baseline does not get an Authorization to Operate, an unauthorized cloud vendor cannot sell to federal agencies, and a contractor that falsely certifies compliance risks False Claims Act liability, contract termination, and debarment from future federal contracts.
Get These Controls Built Into Your Environment, Not Bolted On
Mapping which of the 20 families apply to your systems is only half the job. Implementing and documenting them, so they hold up under an assessment, is the other half.
See our NIST 800-53 and federal compliance IT services, or book a call to walk through where your environment actually stands.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
