Free NIST 800-53 Compliance Check:
Which Baseline Applies to You, and How Many Controls Are You Missing?
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive NIST 800-53 risk check below to find out what your government or manufacturing contract actually expects of you.
Answer 8 quick questions, weighted toward multi-factor authentication, encryption, vendor risk, and whether you actually know your baseline, and get your gap score in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What NIST 800-53 Actually Covers (the short version)
NIST SP 800-53 Rev. 5 is the federal government’s master catalog of security and privacy controls, roughly 1,196 of them across 20 control families.
Almost nobody implements all of them. Instead, your system is scoped to one of three baselines, Low, Moderate, or High, based on the impact if the data you handle were exposed, altered, or made unavailable.
- Low
About 149 Controls
- Moderate
About 287 Controls
- High
About 370 Controls
The catalog itself doesn’t tell you which baseline applies to you, your contract, grant terms, or a cloud authorization (like a FedRAMP ATO) does that. That’s the single most common point of confusion for a manufacturer or municipal department handed an RFP that just says “must comply with NIST 800-53” and nothing else.
The checklist below walks the control areas that matter regardless of which baseline you land in, plus how 800-53 relates to the other frameworks it’s most often confused with.
The Full NIST 800-53 Gap Checklist
Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, an assessor can’t either.
- 1. Baseline Identification and your System Security Plan (SSP):
✓ A written SSP that names your actual baseline (Low, Moderate, or High) and lists the controls you have in place against it.
✓ A named owner for keeping the SSP current as systems, vendors, or contract terms change.
✓ Clarity on which regime is actually driving your requirement: 800-53 directly (a federal system or agency relationship), NIST 800-171/CMMC (a DoD contractor handling Controlled Unclassified Information), CJIS (criminal justice information), or IRS Publication 1075 (federal tax information). See the FAQ below if you’re not sure which applies. - 2. Access Control and Least Privilege:
✓ A unique login for every user, no shared accounts.
✓ Access granted on a need-to-know basis, tied to job function.
✓ Access removed the same day someone changes roles or leaves. - 3. Multi-Factor Authentication:
✓ MFA enforced on every system and remote-access path that touches the covered data.
✓ MFA required for administrator and privileged accounts specifically, not just standard user logins. - 4. Encryption:
✓ Data encrypted at rest: servers, workstations, laptops, and backups alike.
✓ Data encrypted in transit, whenever it moves over a network, including the internet.
✓ Cloud environments held to the same encryption standard as on-premises systems. - 5. Audit Logging and Monitoring:
✓ Access logging enabled on every system that stores or processes the covered data.
✓ Someone assigned to actually review those logs on a regular schedule, not just collect them. - 6. Configuration Management and Patching:
✓ A documented, secure baseline configuration for servers and workstations before they go into service.
✓ A patching schedule you can show evidence of following, not just a policy that says patches happen. - 7. Supply Chain and Vendor Risk:
✓ A current inventory of every vendor, IT provider, cloud host, and software vendor, who can reach the covered data.
✓ Written confirmation each vendor meets the same security bar you’re held to.
✓ Awareness that if your contract references Controlled Unclassified Information (CUI) or the clause DFARS 252.204-7012, this requirement flows down to your vendors, and it’s the specific focus of NIST SP 800-161, the supply-chain risk companion to the 800-53 catalog. - 8. Incident Response:
✓ A written incident-response plan specific to the data your contract covers.
✓ A named point of contact responsible for notifying your contracting agency, and a known notification window, commonly measured in hours, not days, once discovery happens. - 9. Personnel and Training:
✓ Background checks completed for staff and contractors with access to the covered data.
✓ Security awareness training completed at least annually, with records you could produce on request. - 10. Contingency Planning and Backup:
✓ Regular backups of the covered data that someone has actually tested by restoring.
✓ A documented disaster-recovery and continuity plan for the systems that hold it.
How to read your gaps?
- 0 – 2 Gaps
Strong Shape
- 3 – 6 Gaps
Real, findable gaps that would draw findings in an audit.
- 7+ Gaps or 2+ Critical Gaps
You’d likely fail that review today.
Most of the technical items above, MFA, encryption, logging, vendor vetting, live in your IT setup, not a policy binder, which is the half of NIST 800-53 a managed IT and cybersecurity partner operates for you.
NIST 800-53 Compliance FAQ
It’s the federal government’s catalog of security and privacy controls, used directly by federal agencies and their information systems under FISMA, and referenced (in whole or tailored form) by a wide range of other programs. If you’re a manufacturer, municipality, or other organization that received an RFP, grant condition, or contract citing “NIST 800-53,” it almost always means a specific baseline or a derivative framework applies to you, not the full 1,196-control catalog.
The baselines scale the control set to the impact of a security failure: Low (roughly 149 controls) for systems where a breach has limited consequences, Moderate (roughly 287) for most day-to-day government and contracted systems, and High (roughly 370) for systems where a failure could be catastrophic. Your contract, grant terms, or a cloud provider’s authorization should state which baseline you’re held to. If nothing states it, that’s itself a gap, and question 1 in the tool above is built around exactly that.
They’re related but not the same thing. If you’re a defense contractor or subcontractor handling Controlled Unclassified Information (CUI), the standard you’re actually held to is NIST SP 800-171, a 110-requirement subset built from the 800-53 Moderate baseline and scoped for non-federal systems. CMMC is the certification program that verifies you’ve implemented those 800-171 requirements. For more on what that involves, see our CMMC compliance guide for small businesses.
FedRAMP authorizes cloud service providers to sell into the federal government, and its Low, Moderate, and High baselines are built directly from NIST 800-53, tailored with cloud-specific controls added on top. If you’re a manufacturer or municipality using a FedRAMP-authorized cloud product, the provider carries that compliance burden; if you’re the one seeking a FedRAMP authorization for your own cloud service, you’re implementing 800-53 controls plus the FedRAMP overlay.
The FBI’s CJIS Security Policy, which governs any system that stores or processes criminal justice information (common for municipal police departments and their IT vendors), maps its own requirements to a large subset of NIST 800-53 controls at the Moderate level. If your municipality touches criminal justice information, CJIS is the specific policy you’re assessed against, not 800-53 directly, but implementing the 800-53 control areas above (MFA, encryption, access control, audit logging) covers most of the same ground.
You’re in the right place. Those requirements build on the same control catalog this check uses. DFARS 252.204-7012 requires defense contractors to protect Controlled Unclassified Information consistent with NIST SP 800-171 (itself derived from the 800-53 Moderate baseline), and NIST SP 800-161 extends the 800-53 catalog’s Supply Chain Risk Management (SR) control family into a full framework for vetting the vendors, cloud hosts, and software suppliers who touch your data. Question 7 above (vendor and supply-chain risk) is where this shows up in your result. You don’t need a separate check, run this one.
Almost certainly not all 1,196. Your real number is set by your baseline (roughly 149 to 370 controls) or, if a derivative framework applies to you (NIST 800-171/CMMC, CJIS, IRS Publication 1075), by that framework’s own scoped requirement set, which is smaller and more specific to your situation. Getting the SSP and baseline question right first, question 1 above, is what turns “the whole catalog” into a manageable, specific list.
Consequences vary by program and contract, but commonly include findings that must be remediated on a corrective-action timeline, restricted or suspended access to the government data or systems your work depends on, and, in contracts with data-handling clauses like DFARS 252.204-7012, potential breach-of-contract exposure.
Ready to close your gaps?
If your result flagged gaps in MFA, encryption, vendor vetting, or audit logging, most of that is technical and process work an IT and cybersecurity partner handles day to day.
LeadingIT helps Chicagoland manufacturers and municipal/government departments build the access controls, encryption, logging, and vendor-risk practices NIST 800-53, and whatever CMMC, CJIS, or IRS-1075 requirements ride on top of it, actually require, and keep the SSP documentation current between reviews. We deliver this FOR clients; there’s no NIST 800-53, CMMC, CJIS, or FedRAMP “certification” an IT company can hold, and we don’t claim one.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver this as a managed service.