U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 612 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
VMware vSphere 7.0 STIG (Y23M03) VMware vSphere 7.0
Defense Information Systems Agency
05/26/2023 Standalone XCCDF 1.1.4 - VMware vSphere 7.0 STIG
FedRAMP Moderate for Red Hat OpenStack Platform 13 (v1) Red Hat OpenStack Platform 13.0
Red Hat
05/22/2023 Security Template - NIST 800-53 Control Applicability Guide for Red Hat OpenStack Platform 13
Security Template - FedRAMP Moderate Template SSP for Red Hat OpenStack Platform 13
Kubernetes STIG (Ver 1, Rel 9) Kubernetes
Defense Information Systems Agency
05/19/2023 SCAP 1.2 Content - Kubernetes STIG Benchmark - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Kubernetes STIG - Ver 1, Rel 9
Cisco IOS Switch STIG (Y23M06) Cisco IOS
Cisco IOS XE
Cisco NX-OS
Defense Information Systems Agency
05/19/2023 Standalone XCCDF 1.1.4 - Cisco IOS XE Switch STIG
Standalone XCCDF 1.1.4 - Cisco IOS Switch STIG
Standalone XCCDF 1.1.4 - Cisco NX OS Switch STIG
Juniper Router STIG (Y23M06) Juniper JunOS
Defense Information Systems Agency
05/19/2023 Standalone XCCDF 1.1.4 - Juniper Router STIG
Cisco ISE STIG (Y23M06) Cisco Identity Services Engine
Defense Information Systems Agency
05/19/2023 Standalone XCCDF 1.1.4 - Cisco ISE STIG
Cisco IOS Router STIG (Y23M06) Cisco IOS
Defense Information Systems Agency
05/19/2023 SCAP 1.3 Content - Cisco IOS-XE Router NDM STIG Benchmark - Ver 1, Rel 7
SCAP 1.3 Content - Cisco IOS-XE Router RTR STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Cisco IOS XE Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XR Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XE Router NDM RTR STIG for Ansible - Ver 2, Rel 3
Standalone XCCDF 1.1.4 - Cisco IOS XE Router STIG for Ansible - Ver 2, Rel 1
Cisco ASA STIG (Y23M06) Cisco ASA
Defense Information Systems Agency
05/19/2023 Standalone XCCDF 1.1.4 - Cisco ASA STIG
Microsoft Windows Server 2022 (Ver 1, Rel 3) Microsoft Windows Server 2022
Defense Information Systems Agency
05/19/2023 SCAP 1.2 Content - Microsoft Windows Server 2022 STIG Benchmark - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG for Chef - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG - Ver 1, Rel 3
Microsoft Windows Server 2019 (Ver 2, Rel 7) Microsoft Windows Server 2019
Defense Information Systems Agency
05/19/2023 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 4
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 7
Microsoft Windows 11 STIG (Ver 1, Rel 4) Microsoft Windows 11
Defense Information Systems Agency
05/19/2023 SCAP 1.2 Content - Microsoft Windows 11 STIG Benchmark - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 1, Rel 4
Microsoft Windows 10 STIG (Version 2, Release 7) Microsoft Windows 10
Defense Information Systems Agency
05/19/2023 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 2, Rel 8
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 2, Rel 7
Microsoft SQL Server 2016 STIG (Y23M04) Microsoft SQL Server 2016
Defense Information Systems Agency
05/10/2023 Standalone XCCDF 1.1.4 - MS SQL Server 2016 STIG
Active Directory Domain STIG (Ver 3, Rel 3) Microsoft Active Directory
Defense Information Systems Agency
05/10/2023 Standalone XCCDF 1.1.4 - Active Directory Domain STIG - Ver 3, Rel 3
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 4) Microsoft Windows Defender
Defense Information Systems Agency
05/10/2023 SCAP 1.2 Content - Microsoft Defender Antivirus STIG Benchmark - Ver 2, Rel 4
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Standalone XCCDF 1.1.4 - Microsoft Defender Antivirus STIG - Ver 2, Rel 4
Microsoft Windows 2012 and 2012 R2 STIG (Ver 3, Rel 6) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
05/10/2023 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 5
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 5
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG - Ver 3, Rel 6
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 6
Microsoft Windows Server 2016 STIG (Version 2, Release 6) Microsoft Windows Server 2016
Defense Information Systems Agency
05/10/2023 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 4
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 6
Windows Firewall STIG and Advanced Security STIG (Ver 2, Rel 1) windows firewall
Defense Information Systems Agency
05/10/2023 SCAP 1.2 Content - Microsoft Windows Firewall STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Standalone XCCDF 1.1.4 - Microsoft Windows Firewall STIG and Advanced Security STIG - Ver 2, Rel 1
Apple iOS/iPadOS 16 STIG (Ver 1, Rel 2) Apple iOS/iPadOS 16
Defense Information Systems Agency
05/02/2023 Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 16 STIG - Ver 1, Rel 2
Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 2) Adobe Acrobat Reader
Defense Information Systems Agency
05/01/2023 SCAP 1.2 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - April 2023
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 2, Rel 1
* This checklist is still undergoing review for inclusion into the NCP.