Table of Contents
NIST SP 800-53 is a federal catalog of security and privacy controls, currently in its fifth revision, organized into 20 control families spanning roughly 1,196 individual controls. It exists to give federal agencies and their contractors a structured way to select, implement, and assess safeguards for information systems under the Federal Information Security Modernization Act (FISMA). It is not a certification a product earns, it is a catalog a system is assessed against.
Where NIST 800-53 Sits Inside the Risk Management Framework
NIST 800-53 doesn’t operate on its own. It sits inside NIST’s Risk Management Framework (RMF), a six-step process: Categorize, Select, Implement, Assess, Authorize, Monitor. The 800-53 catalog is specifically what an organization draws from during the Select and Implement steps, once a system’s impact level has been categorized under FIPS 199.
Two artifacts carry the practical weight of this process. The System Security Plan (SSP) documents exactly which controls apply to a system and how each one is implemented. Where a control isn’t fully in place, the organization produces a Plan of Action and Milestones (POA&M), which tracks the gap, the remediation timeline, and who owns it.
An independent assessor, often a Third-Party Assessment Organization (3PAO) in FedRAMP contexts, reviews both documents before an Authorizing Official grants an Authority to Operate (ATO). Skipping this context is exactly why so many “what is NIST 800-53” explainers read as incomplete to anyone who has actually gone through an ATO cycle.
Control Families and Exact Baseline Counts
Revision 5 organizes its catalog into 20 families, up from 17 in Revision 4, with PT (PII Processing and Transparency) and SR (Supply Chain Risk Management) added to close gaps the prior revision left open. The total control count moves with each release. NIST’s Release 5.2.0, published in August 2025, added three controls, which is why older articles cite lower totals than current ones.
| Baseline (per NIST SP 800-53B) | Revision 4 controls | Revision 5 controls |
| Low | ~149 | ~150 |
| Moderate | ~325 | ~304 |
| High | ~421 | ~392 |
Note that Revision 5’s baselines shrank in Moderate and High even as the overall catalog grew, because controls were consolidated and made technology-neutral rather than duplicated across families.
How 800-53 Relates to CSF, 800-171, CMMC, and FedRAMP
Most organizations never implement 800-53 directly. They inherit it through whichever downstream framework actually governs their contract. NIST CSF is a top-down, risk-prioritization framework meant to complement 800-53, not replace its detailed controls. NIST 800-171, now in Revision 3, protects Controlled Unclassified Information on non-federal systems, and its requirements were restructured for direct, line-by-line alignment with 800-53 Revision 5 controls.
CMMC assessments for Defense Industrial Base contractors are built on 800-53 mappings, and FedRAMP authorizations for cloud service providers use 800-53 baselines as their assessment basis. Knowing which of these four actually applies to your organization matters more than memorizing 800-53 in isolation.
AC-17 Remote Access Requirements — and Why PureVPN for Teams Was Built Around Them
AC-17 governs remote access, and its base control is a governance requirement: document usage restrictions for every remote access method, and authorize each one before any connection happens.
Encryption enters through AC-17(2), which names encrypted VPNs and TLS as acceptable mechanisms, cross-referenced to SC-8, SC-12, and SC-13. AC-17(3) adds a second requirement, routing remote connections through managed, authorized access control points rather than leaving them scattered across the network.
Neither enhancement satisfies the base control on its own; documentation, authorization, and monitoring remain separate obligations regardless of which tool handles encryption. This is precisely the pair of technical requirements PureVPN for Teams was designed to close.
How PureVPN for Teams Satisfies AC-17’s Encryption and Access-Point Requirements
PureVPN for Teams was built around exactly the two technical enhancements AC-17 names, and it’s worth being precise about where its coverage starts and stops.
| Control | Requirement | PureVPN for Teams status |
| AC-17(2) | Encrypt remote sessions | Satisfied — AES-256 encryption across a managed server network |
| AC-17(3) | Managed access control points | Satisfied — dedicated static IPs, whitelistable in cloud services and applications |
| AC-17 base | Documented authorization before connection | Organization’s responsibility — dashboard provisions users, but authorization records are policy, not product |
| AU / CA families | Audit logging, continuous monitoring | Organization’s responsibility — not a confirmed PureVPN for Teams capability |
PureVPN for Teams closes the two technical gaps that trip up most remote-access reviews, encryption and access-point management, without pretending to close the governance gaps that only your own compliance process can close.
If your organization is heading into an ATO review, a FedRAMP assessment, or a CMMC audit and remote access is on the checklist, see how PureVPN for Teams secures remote connections before the auditor asks the question first.