Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-70 Rev. 5

National Checklist Program for IT Products: Guidelines for Checklist Users and Developers

Date Published: May 2026

Supersedes: SP 800-70 Rev. 4 (02/15/2018)

Planning Note (06/08/2026):

The current version of the NIST SP800-70 revision 5 maintains language referencing FAR 39.101(c) (see pages 4 and 9).  However, the current RFO deviation specifically excludes FAR 39.101(c). The FAR RFO final rule is undergoing review, and NIST will update the revision to correspond to any changes to FAR 39.101(c) once the rule is finalized. Note: the RFO companion guide (see page 98) provides readers with hyperlinks to NIST guidance and statutory requirements related to the acquisition of ICT.


Author(s)

Stephen Quinn (NIST), Blair Heiserman (NIST)

Abstract

Keywords

benchmark; change detection; checklist; information security; National Checklist Program (NCP); Security Automation; secure configuration; security configuration checklist; Security Content Automation Protocol (SCAP); software configuration; vulnerability
Control Families

None selected