Which best describes your industry?
What this NIST 800-53 self-assessment covers
Assess your control posture against NIST SP 800-53 Rev.5 control families — the baseline for FISMA, FedRAMP and many US programmes. It runs to 22 control questions across 6 domains, scored against the 287 requirements that make up NIST 800-53, so the percentage you see reflects the size of the standard rather than the length of this questionnaire.
- Access Control & Identity (AC/IA) — 4 questions
- Audit & Accountability (AU) — 3 questions
- Config, Risk & Assessment (CM/RA/CA) — 4 questions
- Incident & Contingency (IR/CP) — 3 questions
- System & Comms Protection (SC/SI) — 4 questions
- Programme, People & Privacy (PM/PS/PT) — 4 questions
Who it is for
It is built for the person who has been asked where the organisation stands on NIST 800-53 and needs a defensible answer this week — typically a security lead, compliance owner, CTO or founder facing a customer security review, a regulator, or a board question. You do not need prior NIST 800-53 experience to complete it; the questions are written in plain terms and you can mark anything genuinely out of scope as N/A so it does not count against you.
How to read your score
Readiness is calculated as the proportion of applicable questions answered Yes, so marking items N/A narrows the scope rather than inflating the result. Bands run from Initial through Developing, Defined and Managed to Optimised. The domain breakdown matters more than the headline number: a strong overall score with one weak domain is a more accurate description of most organisations than any single percentage, and it tells you where the work is.
What a self-assessment cannot tell you
This is an indicator, not an audit, and the difference is evidence. A self-assessment records what you believe is in place; an assessor tests whether it operated over a period and asks for the tickets, logs and approvals that prove it. Teams are also, in our experience, consistently optimistic about documentation and access reviews — two areas where the answer feels like Yes until someone asks for the artefact. Use the gap list as the agenda for that conversation.
If the result raises more questions than it answers, Talk to a NIST advisor — a scoping conversation is usually quicker than a second self-assessment.
