U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 841 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Cisco ACI (Y25M05) Cisco Application Centric Infrastructure (ACI)
Defense Information Systems Agency
07/21/2025 Standalone XCCDF 1.1.4 - U_Cisco_ACI_Y25M05_STIG
Microsoft SQL Server 2022 (Ver 1, Rel 1) Microsoft SQL Server 2022
Defense Information Systems Agency
07/21/2025 Standalone XCCDF 1.1.4 - Microsoft SQL Server 2022 STIG - Ver 1,Rel 1
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.61-91) IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
07/21/2025 ZIP - Vanguard z/OS RACF Checklist 6.61/91 XML version
ZIP - Vanguard z/OS RACF Checklist 6.61/91 PDF version
Oracle Linux 9 STIG (Ver 1, Rel 1) Oracle Linux 9.0
Defense Information Systems Agency
07/21/2025 Standalone XCCDF 1.1.4 - Oracle Linux 9 STIG - Ver 1, Rel 1
Apple iOS/iPadOS 18 STIG (Ver 1, Rel 4) Apple iPadOS 18.0
Apple iPhone OS 18.0
Defense Information Systems Agency
07/14/2025 Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 18 STIG - Ver 1, Rel 4
iOS/iPadOS 18 Guidance (Revision 2.0) Apple iPhone OS 18.0
NIST, macOS Security Compliance Project
07/09/2025 ZIP - iOS/iPadOS 18 Guidance, Revision 2.0
visionOS 2.0 Guidance (Revision 2.0) Apple VisionOS 2.0
NIST, macOS Security Compliance Project
07/09/2025 ZIP - visionOS 2.0 Guidance, Revision 2.0
Sonoma Guidance (Revision 4.0) Apple macOS 14.0
NIST, macOS Security Compliance Project
07/09/2025 SCAP 1.3 Content - Sonoma Guidance, Revision 4.0
Sequoia Guidance (Revision 2.0) Apple MacOS 15.0
NIST, macOS Security Compliance Project
07/09/2025 SCAP 1.3 Content - Sequoia Guidance, Revision 2.0
Ventura Guidance (Revision 6.0) Apple macOS 13.0 (Ventura)
NIST, macOS Security Compliance Project
07/09/2025 SCAP 1.3 Content - Ventura Guidance, Revision 6.0
iOS/iPadOS 17 Guidance (Revision 4.0) Apple iOS 17.0
NIST, macOS Security Compliance Project
07/09/2025 ZIP - iOS/iPadOS 17 Guidance, Revision 4
iOS/iPadOS 16 Guidance (Revision 4.0) Apple iOS/iPadOS 16
NIST, macOS Security Compliance Project
07/09/2025 ZIP - iOS/iPadOS 16 Guidance, Revision 4.0
CIS Ubuntu Linux 24.04 LTS STIG Benchmark (1.0.0) Canonical Ubuntu 24.04 LTS
Center for Internet Security (CIS)
07/09/2025 Prose - CIS Ubuntu Linux 24.04 LTS STIG Benchmark v1.0.0
CIS SUSE Linux Enterprise 12 Benchmark (3.2.1) SUSE Linux Enterprise Server 12.0
Center for Internet Security (CIS)
07/09/2025 Prose - CIS SUSE Linux Enterprise 12 Benchmark v3.2.1
CIS Ubuntu Linux 22.04 LTS STIG Benchmark (1.0.0) Canonical Ubuntu 22.04 LTS
Center for Internet Security (CIS)
07/09/2025 Prose - CIS Ubuntu Linux 22.04 LTS STIG Benchmark v1.0.0
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.62-94) IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
07/08/2025 ZIP - Vanguard z/OS RACF Checklist 6.62/94 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.62/94 XML version
CIS PostgreSQL 16 Benchmark (1.1.0) PostgreSQL 16.0
Center for Internet Security (CIS)
07/08/2025 Prose - CIS PostgreSQL 16 Benchmark v1.1.0
Ubuntu Linux 20.04 LTS Benchmark (3.0.0) Canonical Ubuntu 20.04 LTS
Center for Internet Security (CIS)
07/07/2025 Prose - CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0
CIS PostgreSQL 15 Benchmark (1.2.0) PostgreSQL 15.0
Center for Internet Security (CIS)
07/07/2025 Prose - CIS PostgreSQL 15 Benchmark v1.2.0
Samsung Android 15 BYOAD STIG (Y25M04) Samsung Android 15.0
Defense Information Systems Agency
07/07/2025 Standalone XCCDF 1.1.4 - Samsung Android 15 BYOAD STIG
* This checklist is still undergoing review for inclusion into the NCP.