Framework overlap

Does NIST SP 800-53A Rev. 5 cover CMMC 2.0?

You hold NIST SP 800-53A Rev. 5 and have been told to do CMMC 2.0. Here is how much overlaps, control by control.

2% of CMMC 2.0 you already have

NIST SP 800-53A Rev. 5 already covers about 2% of CMMC 2.0, leaving 108 of 110 controls as genuinely new work.

Already covered 0 Likely covered 2 New work 108

No control in NIST SP 800-53A Rev. 5 maps directly to one in CMMC 2.0. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-53A Rev. 5 reaches these. This is the list to scope.

AC.L2-3.1.1
Authorized Access Control
AC.L2-3.1.10
Session Lock
AC.L2-3.1.11
Session Termination
AC.L2-3.1.12
Control Remote Access
AC.L2-3.1.13
Remote Access Confidentiality
AC.L2-3.1.14
Remote Access Routing
AC.L2-3.1.15
Privileged Remote Access
AC.L2-3.1.16
Wireless Access Authorization
AC.L2-3.1.17
Wireless Access Protection
AC.L2-3.1.18
Mobile Device Connection
AC.L2-3.1.19
Encrypt CUI on Mobile
AC.L2-3.1.2
Transaction & Function Control
AC.L2-3.1.20
External Connections
AC.L2-3.1.21
Portable Storage Use
AC.L2-3.1.22
Control Public Information
AC.L2-3.1.3
Control CUI Flow
AC.L2-3.1.4
Separation of Duties
AC.L2-3.1.5
Least Privilege
AC.L2-3.1.6
Non-Privileged Account Use
AC.L2-3.1.7
Privileged Functions
AC.L2-3.1.8
Unsuccessful Logon Attempts
AC.L2-3.1.9
Privacy & Security Notices
AT.L2-3.2.1
Role-Based Risk Awareness
AT.L2-3.2.2
Role-Based Training
AT.L2-3.2.3
Insider Threat Awareness
AU.L2-3.3.1
System Auditing
AU.L2-3.3.2
User Accountability
AU.L2-3.3.3
Event Review
AU.L2-3.3.4
Audit Failure Alerting
AU.L2-3.3.5
Audit Correlation
AU.L2-3.3.6
Reduction & Reporting
AU.L2-3.3.7
Time Stamps & Synchronization
AU.L2-3.3.8
Audit Protection
AU.L2-3.3.9
Audit Management
CA.L2-3.12.3
Security Control Monitoring
CA.L2-3.12.4
System Security Plan
CM.L2-3.4.1
System Baselining
CM.L2-3.4.2
Security Configuration Enforcement
CM.L2-3.4.3
System Change Management
CM.L2-3.4.4
Security Impact Analysis
CM.L2-3.4.5
Access Restrictions for Change
CM.L2-3.4.6
Least Functionality
CM.L2-3.4.7
Nonessential Functionality
CM.L2-3.4.8
Application Execution Policy
CM.L2-3.4.9
User-Installed Software
IA.L2-3.5.1
Identification
IA.L2-3.5.10
Cryptographically-Protected Passwords
IA.L2-3.5.11
Obscure Feedback
IA.L2-3.5.2
Authentication
IA.L2-3.5.3
Multifactor Authentication
IA.L2-3.5.4
Replay-Resistant Authentication
IA.L2-3.5.5
Identifier Reuse
IA.L2-3.5.6
Identifier Handling
IA.L2-3.5.7
Password Complexity
IA.L2-3.5.8
Password Reuse
IA.L2-3.5.9
Temporary Passwords
IR.L2-3.6.1
Incident Handling
IR.L2-3.6.2
Incident Reporting
IR.L2-3.6.3
Incident Response Testing
MA.L2-3.7.1
Perform Maintenance
MA.L2-3.7.2
System Maintenance Control
MA.L2-3.7.3
Equipment Sanitization
MA.L2-3.7.4
Media Inspection
MA.L2-3.7.5
Nonlocal Maintenance
MA.L2-3.7.6
Maintenance Personnel
MP.L2-3.8.1
Media Protection
MP.L2-3.8.2
Media Access
MP.L2-3.8.3
Media Disposal
MP.L2-3.8.4
Media Markings
MP.L2-3.8.5
Media Accountability
MP.L2-3.8.6
Portable Storage Encryption
MP.L2-3.8.7
Removable Media
MP.L2-3.8.8
Shared Media
MP.L2-3.8.9
Protect Backups
PE.L2-3.10.1
Limit Physical Access
PE.L2-3.10.2
Monitor Facility
PE.L2-3.10.3
Escort Visitors
PE.L2-3.10.4
Physical Access Logs
PE.L2-3.10.5
Manage Physical Access
PE.L2-3.10.6
Alternative Work Sites
PS.L2-3.9.1
Screen Individuals
PS.L2-3.9.2
Personnel Actions
RA.L2-3.11.1
Risk Assessments
RA.L2-3.11.2
Vulnerability Scan
RA.L2-3.11.3
Vulnerability Remediation
SC.L2-3.13.1
Boundary Protection
SC.L2-3.13.10
Key Management
SC.L2-3.13.11
CUI Encryption
SC.L2-3.13.12
Collaborative Device Control
SC.L2-3.13.13
Mobile Code
SC.L2-3.13.14
Voice over Internet Protocol
SC.L2-3.13.15
Communications Authenticity
SC.L2-3.13.16
Data at Rest
SC.L2-3.13.2
Security Engineering
SC.L2-3.13.3
Role Separation
SC.L2-3.13.4
Shared Resource Control
SC.L2-3.13.5
Public-Access System Separation
SC.L2-3.13.6
Network Communication by Exception
SC.L2-3.13.7
Split Tunneling
SC.L2-3.13.8
Data in Transit
SC.L2-3.13.9
Connections Termination
SI.L2-3.14.1
Flaw Remediation
SI.L2-3.14.2
Malicious Code Protection
SI.L2-3.14.3
Security Alerts & Advisories
SI.L2-3.14.4
Update Malicious Code Protection
SI.L2-3.14.5
System & File Scanning
SI.L2-3.14.6
Monitor Communications for Attacks
SI.L2-3.14.7
Identify Unauthorized Use
Show the 2 you already have
CA.L2-3.12.1
Security Control Assessment
CA.L2-3.12.2
Plan of Action

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-53A Rev. 5 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition