United States of America: National Institute of Standards and Technology Security and Privacy Controls for Information Systems and Organisations

Progress

Current status
adopted
27 Aug 2025 adopted
07 Nov 2023 adopted
01 Oct 2021 processing consultation
03 Aug 2021 in consultation

Scope

Implementers
United States of America
Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Government Branch
executive
Government Body
other regulatory body
Implementation Level
national

Timeline of events

27 Aug 2025
adopted

National Institute of Standards and Technology released updated Security and Privacy Controls for Information Systems and Organisations (SP 800-53 5.2.0)

On 27 August 2025, the National Institute of Standards and Technology (NIST) issued a patch release of its Security and Privacy Controls for Information Systems and Organisations (SP 800-53 5.2.0). The Controls group together a catalogue of tools fo…

Source
Event type outline
Action type adoption
Government branch executive
Government body other regulatory body
07 Nov 2023
adopted

National Institute of Standards and Technology adopted patch release on Security and Privacy Controls for Information Systems and Organisations (SP 800-53 5.1.1)

On 7 November 2023, the National Institute of Standards and Technology (NIST) issued a patch release of its Security and Privacy Controls for Information Systems and Organisations (SP 800-53 5.1.1). The Controls group together a catalogue of tools f…

Source
Event type outline
Action type adoption
Government branch executive
Government body other regulatory body
01 Oct 2021
processing consultation

NIST closes consultation on Assessing Security and Privacy Controls in Information Systems and Organisations draft (SP 800-53A)

On 1 October 2021, the consultation on the Assessing Security and Privacy Controls in Information Systems and Organisations draft was closed by the National Institute of Standards and Technology (NIST). In particular, the draft provides a framework …

Source
Event type outline
Action type consultation closed
Government branch executive
Government body other regulatory body
03 Aug 2021
in consultation

NIST opened consultation on Assessing Security and Privacy Controls in Information Systems and Organisations draft (SP 800-53A)

On 3 August 2021, the consultation on the Assessing Security and Privacy Controls in Information Systems and Organisations draft was opened by the National Institute of Standards and Technology (NIST). The consultation period will run until 1 Octobe…

Source
Event type outline
Action type consultation opened
Government branch executive
Government body other regulatory body