U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 584 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Fortinet FortiGate Firewall STIG (Y22M07) Fortinet Fortigate Firewall
Defense Information Systems Agency
08/06/2022 Standalone XCCDF 1.1.4 - Fortinet FortiGate Firewall STIG
Microsoft Access 2016 STIG (Version 1, Release 2) Microsoft Access 2016
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Access 2016 STIG - Ver 1, Rel 1
Word 2013 STIG (Version 1, Release 6) Microsoft Word 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Word 2013 STIG - Ver 1, Rel 6
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 4) Microsoft Windows Defender
Defense Information Systems Agency
08/06/2022 SCAP 1.2 Content - Microsoft Defender Antivirus STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.5 Windows
GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Defender Antivirus STIG - Ver 2, Rel 4
Microsoft Office System 2013 STIG (Version 2, Release 1) Office System 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Office System 2013 STIG - Ver 2, Rel 1
Microsoft Windows Server 2019 (Ver 2, Rel 4) Microsoft Windows Server 2019
Defense Information Systems Agency
08/06/2022 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.5 Windows
GPOs - Group Policy Objects (GPOs) - July 2022
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 4
Microsoft One Drive for Business 2016 STIG (Version 2, Release 2) Microsoft One Drive for Business 2016
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft OneDrive STIG - Ver 2, Rel 2
Microsoft Project 2016 STIG (Version 1, Release 2) Microsoft Project 2016
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Project 2016 STIG - Ver 1, Rel 1
Microsoft Outlook 2016 STIG (Version 2, Release 3) Microsoft Outlook 2016
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Outlook 2016 STIG - Ver 2, Rel 3
Mozilla Firefox STIG (Version 6, Release 2) Mozilla Firefox
Defense Information Systems Agency
08/06/2022 SCAP 1.2 Content - Mozilla Firefox for Linux STIG Benchmark - Ver 6, Rel 2
SCAP 1.2 Content - Mozilla Firefox for Windows STIG Benchmark - Ver 6, Rel 2
Automated Content - SCC 5.5 Windows
Automated Content - SCC 5.5 RHEL 6 i686
Automated Content - SCC 5.5 RHEL 6 x86 64
Automated Content - SCC 5.5 RHEL 7/Oracle Linux 7/SLES12 x86 64
Automated Content - SCC 5.5 RHEL 8 Aarch 64
Automated Content - SCC 5.5 RHEL 8 x86 64
GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 3
Excel 2013 STIG (Version 1, Release 7) Microsoft Excel 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Excel 2013 STIG - Ver 1, Rel 7
Microsoft Windows 10 STIG (Version 2, Release 4) Microsoft Windows 10
Defense Information Systems Agency
08/06/2022 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 2, Rel 5
Automated Content - SCC 5.5 Windows
GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 2, Rel 4
Apple OS/iPad OS 15 STIG (Ver 1, Rel 3) Apple OS/iPad OS 15
Defense Information Systems Agency
08/06/2022 Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 15 STIG - Ver 1, Rel 3
Microsoft Outlook 2013 STIG (Version 1, Release 13) Microsoft Outlook 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Outlook 2013 STIG - Ver 1, Rel 13
Microsoft Windows Server 2016 STIG (Version 2, Release 3) Microsoft Windows Server 2016
Defense Information Systems Agency
08/06/2022 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.5 Windows
GPOs - Group Policy Objects (GPOs) - July 2022
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 4
Infopath 2013 STIG (Version 1, Release 5) Microsoft Infopath 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft InfoPath 2013 STIG - Ver 1, Rel 5
Visio 2013 STIG (Version 1, Release 4) Microsoft Visio 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Visio 2013 STIG - Ver 1, Rel 4
Adobe Acrobat Professional DC Continuous Track STIG (Ver 2, Rel 1) Adobe Acrobat Pro DC Continuous Track
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Adobe Acrobat Professional DC Continuous Track STIG - Ver 2, Rel 1
Microsoft Windows 2012 and 2012 R2 DC STIG (Ver 3, Rel 3) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
08/06/2022 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 3
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 3
Automated Content - SCC 5.5 Windows
GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG- Ver 3, Rel 4
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 4
Lync 2013 STIG (Version 1, Release 4) Microsoft Lync 2013
Defense Information Systems Agency
08/06/2022 GPOs - Group Policy Objects (GPOs) - July 2022
Standalone XCCDF 1.1.4 - Microsoft Lync 2013 STIG - Ver 1, Rel 4
* This checklist is still undergoing review for inclusion into the NCP.