NIST SP 800 series
The SP 800 series is a set of technical guidelines on computer security, and it is widely referenced as the basis for the U.S. federal government’s information security requirements (FISMA). Of the full official set (220 documents), this page organizes the current Final editions plus key companions by category, excluding annual reports, items slated for withdrawal, and extremely niche sub-specifications (the PIV test guides, etc.).
For complete publication and revision information, see NIST CSRC SP 800. This page is a curated version; CSRC is always the primary source.
General / introductory
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-12 Rev.1 | An Introduction to Information Security | Rev.1 (2017) | Introduction to information security |
| SP 800-100 | Information Security Handbook: A Guide for Managers | Upd1 (2007) | Handbook for managers |
Risk management / frameworks / measurement
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-18 Rev.1 | Guide for Developing Security Plans for Federal Information Systems | Rev.1 (2006) | System Security Plan (SSP) |
| SP 800-30 Rev.1 | Guide for Conducting Risk Assessments | Rev.1 (2012) | How to conduct risk assessments |
| SP 800-37 Rev.2 | Risk Management Framework for Information Systems and Organizations | Rev.2 (2018) | The 6-step RMF |
| SP 800-39 | Managing Information Security Risk | Final (2011) | Organization-wide risk management |
| SP 800-53 Rev.5 | Security and Privacy Controls for Information Systems and Organizations | Rev.5 (2020, Upd1 2023) | Security/privacy control catalog |
| SP 800-53A Rev.5 | Assessing Security and Privacy Controls | Rev.5 (2022) | Procedures for assessing SP 800-53 controls |
| SP 800-53B | Control Baselines for Information Systems and Organizations | Upd1 (2023) | Low/Moderate/High baselines |
| SP 800-55 Vol.1 | Measurement Guide for Information Security Vol.1 — Identifying and Selecting Measures | Final (2024) | Selecting measurement metrics |
| SP 800-55 Vol.2 | Measurement Guide for Information Security Vol.2 — Developing a Measurement Program | Final (2024) | Building a measurement program |
| SP 800-160 Vol.1 Rev.1 | Engineering Trustworthy Secure Systems | Rev.1 (2022) | Systems security engineering |
| SP 800-160 Vol.2 Rev.1 | Developing Cyber-Resilient Systems | Rev.1 (2021) | Cyber resilience engineering |
| SP 800-221 | Enterprise Impact of Information and Communications Technology Risk | Final (2023) | Enterprise ICT risk |
| SP 800-221A | ICT Risk Outcomes | Final (2023) | Outcome metrics for 800-221 |
Contingency / training
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-34 Rev.1 | Contingency Planning Guide for Federal Information Systems | Rev.1 (2010) | Business continuity/recovery planning |
| SP 800-84 | Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities | Final (2006) | Testing/training/exercises |
CUI / FISMA / federal regulation / education
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-50 Rev.1 | Building a Cybersecurity and Privacy Learning Program | Rev.1 (2024) | Security education program |
| SP 800-59 | Guideline for Identifying an Information System as a National Security System | Final (2003) | NSS identification guide |
| SP 800-60 Vol.1 Rev.1 | Guide for Mapping Types of Information and Systems to Security Categories | Rev.1 (2008) | Information categorization |
| SP 800-60 Vol.2 Rev.1 | Mapping (Vol.2 — Appendices) | Rev.1 (2008) | Appendices to 800-60 Vol.1 |
| SP 800-66 Rev.2 | Implementing the HIPAA Security Rule | Rev.2 (2024) | HIPAA Security Rule |
| SP 800-171 Rev.3 | Protecting CUI in Nonfederal Systems and Organizations | Rev.3 (2024) | CUI protection requirements |
| SP 800-171A Rev.3 | Assessing Security Requirements for CUI | Rev.3 (2024) | Procedures for assessing 800-171 |
| SP 800-172 | Enhanced Security Requirements for Protecting CUI | Final (2021) | Enhanced requirements assuming APTs |
| SP 800-172A | Assessing Enhanced Security Requirements for CUI | Final (2022) | Procedures for assessing 800-172 |
| SP 800-181 Rev.1 | Workforce Framework for Cybersecurity (NICE Framework) | Rev.1 (2020) | NICE workforce framework |
Authentication / identity (PIV / Digital Identity)
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-63-4 | Digital Identity Guidelines | Rev.4 (2025) | Overall digital identity policy (latest) |
| SP 800-63A-4 | Identity Proofing and Enrollment | Rev.4 (2025) | Identity proofing / verification |
| SP 800-63B-4 | Authentication and Authenticator Management | Rev.4 (2025) | Authenticator / MFA / passphrase requirements |
| SP 800-63C-4 | Federation and Assertions | Rev.4 (2025) | Federation / SAML / OIDC |
| SP 800-73-5 Pt.1 | PIV Card Application Namespace | Rev.5 (2024) | PIV card namespace |
| SP 800-73-5 Pt.2 | Card Command Interface | Rev.5 (2024) | PIV command interface |
| SP 800-73-5 Pt.3 | Client Application Programming Interface | Rev.5 (2024) | PIV client API |
| SP 800-76-2 | Biometric Specifications for PIV | Final (2013) | PIV biometric specification |
| SP 800-78-5 | Cryptographic Algorithms and Key Sizes for PIV | Rev.5 (2024) | PIV cryptographic algorithms (latest) |
| SP 800-116 Rev.1 | PIV Credentials in Facility Access | Rev.1 (2018) | PIV for physical access |
| SP 800-157 | Derived PIV Credentials | Final (2014) | Derived PIV credentials |
| SP 800-162 | Attribute Based Access Control (ABAC) | Upd2 (2019) | Attribute-based access control |
| SP 800-205 | Attribute Considerations for Access Control Systems | Final (2019) | Considerations for selecting attributes |
Cryptography / key management / random numbers
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-22 Rev.1a | Statistical Test Suite for RNGs | Rev.1a (2010) | RNG statistical tests |
| SP 800-38A | Block Cipher Modes — Methods and Techniques | Final (2001) | ECB/CBC/CFB/OFB/CTR |
| SP 800-38A Sup. | Three Variants of Ciphertext Stealing | Final (2010) | CTS-1/2/3 |
| SP 800-38B | CMAC Mode for Authentication | Final (2016) | CMAC specification |
| SP 800-38C | CCM Mode for Authentication and Confidentiality | Final (2007) | CCM specification |
| SP 800-38D | GCM and GMAC | Final (2007) | GCM / GMAC |
| SP 800-38E | XTS-AES for Storage Devices | Final (2010) | XTS for storage |
| SP 800-38F | Methods for Key Wrapping | Final (2012) | Key wrapping (KW/KWP) |
| SP 800-38G | Format-Preserving Encryption (FPE) | Final (2016) | FF1 / FF3-1 (FF3 withdrawn) |
| SP 800-56A Rev.3 | Pair-Wise Key Establishment Using Discrete Logarithm | Rev.3 (2018) | DH/ECDH key exchange |
| SP 800-56B Rev.2 | Pair-Wise Key Establishment Using Integer Factorization | Rev.2 (2019) | RSA key exchange |
| SP 800-56C Rev.2 | Key Derivation in Key-Establishment Schemes | Rev.2 (2020) | KDF after key exchange |
| SP 800-57 Pt.1 Rev.5 | Key Management — General | Rev.5 (2020) | Key management in general |
| SP 800-57 Pt.2 Rev.1 | Key Management — Best Practices for Organizations | Rev.1 (2019) | Key management for organizations |
| SP 800-57 Pt.3 Rev.1 | Key Management — Application-Specific Guidance | Rev.1 (2015) | Per-application key management |
| SP 800-89 | Obtaining Assurances for Digital Signature Applications | Final (2006) | Assurance for signature verification |
| SP 800-90A Rev.1 | DRBG | Rev.1 (2015) | Deterministic random bit generation |
| SP 800-90B | Entropy Sources Used for Random Bit Generation | Final (2018) | Entropy source assessment |
| SP 800-90C | RBG Constructions | Final (2025) | RBG constructions (latest) |
| SP 800-107 Rev.1 | Recommendation for Applications Using Approved Hash Algorithms | Rev.1 (2012) | Using approved hashes |
| SP 800-108 Rev.1 | Key Derivation Using PRFs | Rev.1 Upd1 (2024) | PRF-based KDF |
| SP 800-130 | Framework for Designing CKMS | Final (2013) | Designing key management systems |
| SP 800-131A Rev.2 | Transitioning Cryptographic Algorithms and Key Lengths | Rev.2 (2019) | Algorithm migration |
| SP 800-132 | Password-Based Key Derivation | Final (2010) | PBKDF2 |
| SP 800-133 Rev.2 | Cryptographic Key Generation | Rev.2 (2020) | Cryptographic key generation |
| SP 800-135 Rev.1 | Application-Specific KDFs | Rev.1 (2011) | KDFs for TLS / IKE, etc. |
| SP 800-152 | Profile for U.S. Federal CKMS | Final (2015) | Federal CKMS profile |
| SP 800-175A | Cryptographic Standards: Directives, Mandates and Policies | Final (2016) | Federal cryptographic standards directives |
| SP 800-175B Rev.1 | Cryptographic Standards: Mechanisms | Rev.1 (2020) | Guidance on using cryptographic standards |
| SP 800-185 | SHA-3 Derived Functions: cSHAKE / KMAC / TupleHash / ParallelHash | Final (2016) | SHA-3 derived functions |
| SP 800-186 | Discrete Logarithm-based Cryptography: Elliptic Curve Domain Parameters | Final (2023) | ECC domains (P-256/P-384/Edwards, etc.) |
| SP 800-208 | Stateful Hash-Based Signature Schemes | Final (2020) | LMS / XMSS |
| SP 800-227 | Recommendations for Key-Encapsulation Mechanisms | Final (2025) | KEM (PQC context) |
| SP 800-232 | Ascon-Based Lightweight Cryptography Standards for Constrained Devices | Final (2025) | Lightweight cryptography Ascon |
CMVP / FIPS 140-3 test requirements
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-140 | FIPS 140-3 Derived Test Requirements (DTR) | Final (2020) | DTR |
| SP 800-140A | CMVP Documentation Requirements | Final (2020) | Documentation requirements |
| SP 800-140B Rev.1 | CMVP Security Policy Requirements | Rev.1 (2023) | Security policy requirements |
| SP 800-140C Rev.2 | CMVP Approved Security Functions | Rev.2 (2023) | Approved cryptographic functions |
| SP 800-140D Rev.2 | CMVP Approved SSP Generation/Establishment Methods | Rev.2 (2023) | SSP generation/establishment |
| SP 800-140E | CMVP Approved Authentication Mechanisms | Final (2020) | Authentication mechanisms |
| SP 800-140F | CMVP Approved Non-Invasive Attack Mitigation Test Metrics | Final (2020) | Non-invasive attack mitigation tests |
Logs / incident / forensics / audit
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-61 Rev.3 | Incident Response Recommendations and Considerations for Cybersecurity Risk Management | Rev.3 (2025) | Incident response (latest) |
| SP 800-83 Rev.1 | Malware Incident Prevention and Handling for Desktops and Laptops | Rev.1 (2013) | Malware response |
| SP 800-86 | Integrating Forensic Techniques into Incident Response | Final (2006) | Integrating forensics |
| SP 800-88 Rev.2 | Guidelines for Media Sanitization | Rev.2 (2025) | Secure media disposal (latest) |
| SP 800-92 | Computer Security Log Management | Final (2006) | Log management |
| SP 800-94 | Intrusion Detection and Prevention Systems (IDPS) | Final (2007) | IDS / IPS |
| SP 800-101 Rev.1 | Mobile Device Forensics | Rev.1 (2014) | Mobile device forensics |
| SP 800-137 | Information Security Continuous Monitoring (ISCM) | Final (2011) | Continuous monitoring |
| SP 800-137A | Assessing ISCM Programs | Final (2020) | Assessing ISCM programs |
| SP 800-150 | Cyber Threat Information Sharing | Final (2016) | Threat information sharing |
| SP 800-184 | Cybersecurity Event Recovery | Final (2016) | Post-incident recovery |
Networks / protocols / communications
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-41 Rev.1 | Firewalls and Firewall Policy | Rev.1 (2009) | Firewall policy |
| SP 800-44 V2 | Securing Public Web Servers | V2 (2007) | Web servers |
| SP 800-45 V2 | Electronic Mail Security | V2 (2007) | Email security |
| SP 800-46 Rev.2 | Enterprise Telework, Remote Access, BYOD Security | Rev.2 (2016) | Remote access / BYOD |
| SP 800-47 Rev.1 | Managing the Security of Information Exchanges | Rev.1 (2021) | Inter-system information exchange |
| SP 800-52 Rev.2 | TLS Implementations | Rev.2 (2019) | TLS implementation guide |
| SP 800-77 Rev.1 | IPsec VPNs | Rev.1 (2020) | IPsec |
| SP 800-81 Rev.3 | Secure DNS Deployment Guide | Rev.3 (2026) | DNS / DNSSEC (latest) |
| SP 800-95 | Secure Web Services | Final (2007) | Web services |
| SP 800-113 | SSL VPNs | Final (2008) | SSL VPN |
| SP 800-114 Rev.1 | User’s Guide to Telework and BYOD Security | Rev.1 (2016) | BYOD for users |
| SP 800-115 | Information Security Testing and Assessment | Final (2008) | Penetration / vulnerability testing |
| SP 800-119 | Secure Deployment of IPv6 | Final (2010) | IPv6 |
| SP 800-177 Rev.1 | Trustworthy Email | Rev.1 (2019) | DMARC / DKIM / SPF / STARTTLS |
| SP 800-189 | Resilient Interdomain Traffic Exchange (BGP / RPKI) | Final (2019) | BGP security |
| SP 800-215 | Guide to a Secure Enterprise Network Landscape | Final (2022) | Enterprise networks |
Patching / configuration management / validation / SCAP
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-40 Rev.4 | Enterprise Patch Management Planning | Rev.4 (2022) | Patch management planning |
| SP 800-51 Rev.1 | Vulnerability Naming Schemes | Rev.1 (2011) | CVE / CWE / CPE naming |
| SP 800-70 Rev.5 | National Checklist Program for IT Products | Rev.5 (2026) | NCP (latest) |
| SP 800-126 Rev.3 | SCAP Version 1.3 Technical Specification | Rev.3 (2018) | SCAP 1.3 |
| SP 800-128 | Security-Focused Configuration Management | Upd1 (2019) | SecCM |
| SP 800-167 | Application Whitelisting | Final (2015) | Application allowlisting |
| SP 800-193 | Platform Firmware Resiliency Guidelines | Final (2018) | Firmware protection (NIST PFR) |
Virtualization / hypervisors
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-125 | Security for Full Virtualization Technologies | Final (2011) | Virtualization in general |
| SP 800-125A Rev.1 | Server-based Hypervisor Platforms | Rev.1 (2018) | Hypervisors |
| SP 800-125B | Secure Virtual Network Configuration for VM Protection | Final (2016) | VM networking |
Cloud / containers / microservices / supply chain / DevSecOps
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-144 | Security and Privacy in Public Cloud Computing | Final (2011) | Public cloud |
| SP 800-145 | The NIST Definition of Cloud Computing | Final (2011) | Definition of cloud |
| SP 800-161 Rev.1 | C-SCRM Practices for Systems and Organizations | Rev.1 Upd1 (2024) | Supply chain risk |
| SP 800-190 | Application Container Security Guide | Final (2017) | Containers |
| SP 800-201 | NIST Cloud Computing Forensic Reference Architecture | Final (2024) | Cloud forensics |
| SP 800-204 | Security Strategies for Microservices-Based Application Systems | Final (2019) | Microservices |
| SP 800-204A | Building Secure Microservices Using Service Mesh | Final (2020) | Service mesh |
| SP 800-204B | ABAC for Microservices using Service Mesh | Final (2021) | Service mesh ABAC |
| SP 800-204C | DevSecOps for Microservices-based Application | Final (2022) | DevSecOps implementation |
| SP 800-204D | Software Supply Chain Security in DevSecOps CI/CD Pipelines | Final (2024) | SSC × CI/CD |
| SP 800-207 | Zero Trust Architecture | Final (2020) | ZTA |
| SP 800-207A | ZTA Model for Access Control in Cloud-Native Applications | Final (2023) | Cloud-native ZTA |
| SP 800-209 | Security Guidelines for Storage Infrastructure | Final (2020) | Storage |
| SP 800-210 | General Access Control Guidance for Cloud Systems | Final (2020) | Cloud access control |
| SP 800-218 | Secure Software Development Framework (SSDF) | Ver.1.1 (2022) | Secure development |
| SP 800-218A | SSDF for Generative AI and Dual-Use Foundation Models | Final (2024) | SSDF for generative AI |
| SP 800-228 | API Protection for Cloud-Native Systems | Final (2026) | API protection |
| SP 800-233 | Service Mesh Proxy Models for Cloud-Native Applications | Final (2024) | Proxy models |
Mobile / IoT / OT / wireless / storage / firmware
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-82 Rev.3 | Operational Technology (OT) Security | Rev.3 (2023) | ICS / OT |
| SP 800-98 | Securing Radio Frequency Identification (RFID) Systems | Final (2007) | RFID |
| SP 800-111 | Storage Encryption Technologies for End User Devices | Final (2007) | Full-disk / file encryption |
| SP 800-121 Rev.2 | Bluetooth Security | Rev.2 Upd1 (2022) | Bluetooth |
| SP 800-123 | General Server Security | Final (2008) | General servers |
| SP 800-124 Rev.2 | Managing Mobile Devices in the Enterprise | Rev.2 (2023) | Enterprise mobile |
| SP 800-147 | BIOS Protection Guidelines | Final (2011) | BIOS protection |
| SP 800-147B | BIOS Protection Guidelines for Servers | Final (2014) | Server BIOS |
| SP 800-153 | Securing Wireless Local Area Networks (WLANs) | Final (2012) | WLAN |
| SP 800-187 | LTE Security | Final (2017) | LTE |
| SP 800-213 | IoT Device Cybersecurity Guidance for the Federal Government | Final (2021) | IoT guidance for federal use |
| SP 800-213A | IoT Device Cybersecurity Requirement Catalog | Final (2021) | IoT requirement catalog |
| SP 800-219 Rev.1 | Automated Secure Configuration Guidance from mSCP (macOS) | Rev.1 (2023) | macOS security |
Data protection / privacy
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-122 | Protecting the Confidentiality of PII | Final (2010) | PII protection |
| SP 800-188 | De-Identifying Government Data Sets | Final (2023) | Data de-identification |
| SP 800-226 | Evaluating Differential Privacy Guarantees | Final (2025) | Differential privacy evaluation |
Vulnerability / disclosure
| Number | Title | Edition | Overview |
|---|---|---|---|
| SP 800-216 | Recommendations for Federal Vulnerability Disclosure Guidelines | Final (2023) | Vulnerability disclosure (federal) |
Legend and the policy of this page
- Edition: Final = finalized / Rev.N = Nth revision / Upd = update / Ver.X = version
- All links in the tables are official NIST CSRC pages. Older documents may redirect to legacy URLs in the
csrc.nist.gov/publications/detail/...form. - This page is a curated version of the official 220 documents. The following are intentionally excluded:
- 13 Annual Reports (SP 800-170 / 176 / 182 / 195 / 203 / 206 / 211 / 214 / 220 / 225 / 229 / 236, etc.)
- Revisions in Draft (the next edition of the SP 800-63 family, 172 Rev.3, 92 Rev.1, 133 Rev.3, 131A Rev.3, etc.) — to be incorporated once finalized
- Extremely niche PIV test/identifier sub-specifications (SP 800-79-2 / 85A-4 / 85B / 87 Rev.2 / 96 / 156 / 163 Rev.1 / 166, etc.)
- Withdrawn
- For the complete list, withdrawn documents, and the Draft list, see NIST CSRC SP 800.