U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 824 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
CIS PostgreSQL 14 Benchmark (1.2.0) PostgreSQL 14.0
Center for Internet Security (CIS)
01/31/2025 Prose - CIS PostgreSQL 14 Benchmark v1.2.0
CIS PostgreSQL 17 Benchmark (1.0.0) PostgreSQL 17.0
Center for Internet Security (CIS)
01/30/2025 Prose - CIS PostgreSQL 17 Benchmark v1.0.0
Xylok Security Suite 20.x STIG (Ver 1, Rel 1) Xylok Security Suite
Defense Information Systems Agency
01/30/2025 Standalone XCCDF 1.1.4 - Xylok Security Suite 20.x STIG - Ver 1, Rel 1
CIS PostgreSQL 16 Benchmark (1.0.0) PostgreSQL 16.0
Center for Internet Security (CIS)
01/30/2025 Prose - CIS PostgreSQL 16 Benchmark v1.0.0
CIS PostgreSQL 15 Benchmark (1.1.0) PostgreSQL 15.0
Center for Internet Security (CIS)
01/30/2025 Prose - CIS PostgreSQL 15 Benchmark v1.1.0
Microsoft Windows Server 2022 (Ver 2, Rel 3) Microsoft Windows Server 2022
Defense Information Systems Agency
01/30/2025 SCAP 1.3 Content - Microsoft Windows Server 2022 STIG SCAP Benchmark - Ver 2, Rel 2
SCAP 1.3 Content - Microsoft Windows Server 2022 STIG Benchmark - Ver 2, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG for Chef - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG - Ver 2, Rel 3
Apache Server 2.4 UNIX STIG (Y25M01) Apache HTTP Server 2.4.0
Defense Information Systems Agency
01/30/2025 Standalone XCCDF 1.1.4 - Apache Server 2.4 Unix STIG
Microsoft SQL Server 2016 (Y25M01) Microsoft SQL Server 2016
Defense Information Systems Agency
01/30/2025 Standalone XCCDF 1.1.4 - Microsoft SQL Server 2016
Standalone XCCDF 1.1.4 - Microsoft SQL Server 2016 STIG
Microsoft Edge STIG (Ver 2, Rel 2) Microsoft Edge
Defense Information Systems Agency
01/30/2025 SCAP 1.3 Content - Microsoft Edge STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Microsoft Edge STIG Benchmark - Ver 1, Rel 3
GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Microsoft Edge STIG - Ver 2, Rel 2
Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 3) Adobe Acrobat Reader
Defense Information Systems Agency
01/30/2025 SCAP 1.3 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.10.1 Windows
GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 2, Rel 1
Microsoft Office System 2016 STIG (Version 2, Release 4) Microsoft Office 2016
Defense Information Systems Agency
01/30/2025 GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Microsoft Office System 2016 STIG - Ver 2, Rel 4
Oracle HTTP Server 12.1.3 STIG (Version 2, Release 3) Oracle HTTP Server 12.1.3 STIG, Version 1, Release 1
Defense Information Systems Agency
01/30/2025 Standalone XCCDF 1.1.4 - Sunset - Oracle HTTP Server 12.1.3 STIG - Ver 2, Rel 3
MultiFunction Device and Network Printers STIG (Version 2, Release 14) Defense Information Systems Agency
01/30/2025
SUSE Linux Enterprise Server (SLES) 15 STIG for Ansible (Ver 2, Rel 3) SUSE Enterprise Linux 15
Defense Information Systems Agency
01/30/2025 Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 15 for Ansible - Ver 2, Rel 3
Microsoft Windows Server 2016 STIG (Version 2, Release 10) Microsoft Windows Server 2016
Defense Information Systems Agency
01/30/2025 SCAP 1.3 Content - Sunset - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 8
Automated Content - SCC 5.10.1 Windows
GPOs - Group Policy Objects (GPOs) - October 2024
Machine-Readable Format - Sunset - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows Server 2016 STIG - Ver 2, Rel 10
Microsoft Windows 11 STIG (Ver 2, Rel 3) Microsoft Windows 11
Defense Information Systems Agency
01/30/2025 SCAP 1.3 Content - Microsoft Windows 11 STIG SCAP Benchmark - Ver 2, Rel 2
SCAP 1.3 Content - Microsoft Windows 11 STIG Benchmark - Ver 2, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Rev. 4 Sunset - Microsoft Windows 11 STIG - Ver 1, Rel 6
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 2, Rel 2
OneNote 2010 STIG (Version 1, Release 10) Microsoft OneNote 2010
Defense Information Systems Agency
01/30/2025 Standalone XCCDF 1.1.4 - Sunset - Microsoft OneNote 2010 STIG - Ver 1, Rel 10
Microsoft Outlook 2013 STIG (Version 1, Release 14) Microsoft Outlook 2013
Defense Information Systems Agency
01/30/2025 GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Sunset - Microsoft Outlook 2013 STIG - Ver 1, Rel 14
Storage Area Network STIG (Version 2, Release 4) Defense Information Systems Agency
01/30/2025
Microsoft .NET Framework 4 (Version 2, Release 5) Microsoft .NET Framework 4.0
Defense Information Systems Agency
01/30/2025 SCAP 1.2 Content - Microsoft .NET Framework 4 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.10.1 Windows
Standalone XCCDF 1.1.4 - Microsoft .Net Framework 4.0 STIG - Ver 2, Rel 5
* This checklist is still undergoing review for inclusion into the NCP.