Back to Blog
Compliance Governance
8 min read

NIST 800-53 for Smaller Organisations: Tailoring Without Gaming It

Over a thousand controls is not a checklist for a 50-person organisation. Baselines, tailoring and the overlay approach that makes it proportionate.

GuardsArm Team

Security Experts

February 26, 2025

NIST 800-53

NIST SP 800-53 contains over a thousand controls and enhancements. Handed to a 50-person organisation as a checklist it produces paralysis, and then a spreadsheet of assertions nobody believes. The standard was never intended to be applied in full to everything — tailoring is part of the method, not a shortcut around it.

Baselines first
Low, Moderate and High baselines select a subset by impact level
Tailoring is legitimate
Documented tailoring is the intended method, not an evasion
Inherit what you can
Cloud providers satisfy a substantial share of infrastructure controls

Do you actually need 800-53?

Worth asking before committing. It is required where a federal contract, FedRAMP or a regulator mandates it. If nothing does, a lighter framework may serve better:

SituationBetter fit
Federal contract requiring it, or FedRAMP800-53
Handling Controlled Unclassified Information800-171 — 110 requirements, derived from 800-53
General programme structure, no mandateNIST CSF — functions and outcomes, far lighter
Customer asking for an attestationSOC 2 or ISO 27001 — see the comparison
Healthcare with no federal contractHIPAA Security Rule, using CSF for structure

Choosing 800-53 when 800-171 or CSF would satisfy the actual requirement is a common and expensive mistake.


Start from the baseline, not the catalogue

Categorise the system by impact — Low, Moderate or High — then take the corresponding baseline. That step alone removes most of the catalogue. For many smaller organisations the Low or Moderate baseline is the correct starting point, and the High baseline is not applicable to anything they run.


Tailoring, done defensibly

Tailoring means adjusting the baseline to your context. It is explicitly provided for, and it needs to be written down.

Applying 800-53 proportionatelyApplying 800-53 proportionately1CategoriseStep 1Impact level per system, based on confidentiality, integrity and availability.2Select the baselineStep 2Low, Moderate or High. This is most of the reduction.3TailorStep 3Scope out what does not apply; add what your risk assessment demands.4Document the rationaleStep 4Every deviation needs a reason an assessor can follow.5Implement and assessStep 5Evidence of operation, not just of existence.
Step 4 is what separates tailoring from simply not doing things.

Legitimate tailoring includes scoping out controls for technology you do not use, applying compensating controls where the specified one is impractical, and adjusting parameters — the standard leaves many values for the organisation to set. What is not legitimate is marking a control satisfied because implementing it was inconvenient.

Inherit aggressively from your cloud provider
Major providers publish control responsibility matrices showing which 800-53 controls they satisfy for infrastructure. For a smaller organisation running entirely in cloud, inheritance can cover a large share of the baseline — provided you document the inheritance and keep evidence of the provider attestation.

Sequence by risk, not by control number

Working through the families alphabetically is how programmes stall in AC with budget exhausted. A workable order for a smaller organisation:

  1. Identification and authentication (IA) and access control (AC) — the highest-value families
  2. Configuration management (CM) — baselines and change control
  3. Audit and accountability (AU) — you cannot investigate without it
  4. Incident response (IR) — plan, roles, exercise
  5. Contingency planning (CP) — backup and recovery
  6. Risk assessment (RA) and system and information integrity (SI)
  7. Everything else

The first three cover a disproportionate share of realistic risk.


The POA&M is part of the answer

Nothing will be fully implemented on day one, and pretending otherwise is the failure mode that causes real trouble. A plan of action and milestones — each gap with an owner, a compensating control where one exists, and a realistic date — is a stronger position in front of an assessor than a self-assessment claiming everything is satisfied. Under a federal contract, an overstated compliance assertion carries consequences well beyond the security finding.

Two further mistakes recur:

  • Treating the control as the goal. A documented policy satisfies the wording of many controls without changing anything. Assessors increasingly ask for evidence of operation — logs, tickets, review records — rather than the document.
  • One boundary for everything. Drawing a single system boundary around the whole organisation forces the highest impact level onto every system in it. Separate boundaries, properly documented, let the low-impact systems stay low-impact.

Where to start

Confirm what is actually mandated. If it is CUI, 800-171's 110 requirements are the obligation and 800-53 is only the source catalogue behind them. Getting this right at the outset can reduce the programme by an order of magnitude.

GuardsArm supports control framework selection and tailoring for smaller organisations. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.