U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 410 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Cisco ACI (Y25M05) Cisco Application Centric Infrastructure (ACI)
Defense Information Systems Agency
07/21/2025 Standalone XCCDF 1.1.4 - U_Cisco_ACI_Y25M05_STIG
Microsoft SQL Server 2022 (Ver 1, Rel 1) Microsoft SQL Server 2022
Defense Information Systems Agency
07/21/2025 Standalone XCCDF 1.1.4 - Microsoft SQL Server 2022 STIG - Ver 1,Rel 1
Oracle Linux 9 STIG (Ver 1, Rel 1) Oracle Linux 9.0
Defense Information Systems Agency
07/21/2025 Standalone XCCDF 1.1.4 - Oracle Linux 9 STIG - Ver 1, Rel 1
Apple iOS/iPadOS 18 STIG (Ver 1, Rel 4) Apple iPadOS 18.0
Apple iPhone OS 18.0
Defense Information Systems Agency
07/14/2025 Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 18 STIG - Ver 1, Rel 4
Samsung Android 15 BYOAD STIG (Y25M04) Samsung Android 15.0
Defense Information Systems Agency
07/07/2025 Standalone XCCDF 1.1.4 - Samsung Android 15 BYOAD STIG
Honeywell Android 13 STIG (Y25M04) Google Android 13
Defense Information Systems Agency
07/07/2025 Standalone XCCDF 1.1.4 - Honeywell Android 13 STIG
Microsoft Entra ID STIG (Ver 1, Rel 1) Microsoft Entra ID
Defense Information Systems Agency
06/30/2025 Standalone XCCDF 1.1.4 - Microsoft Entra ID STIG Ver 1, Rel 1
Microsoft Windows 11 STIG (Ver 2, Rel 3) Microsoft Windows 11
Defense Information Systems Agency
06/11/2025 SCAP 1.3 Content - Microsoft Windows 11 STIG SCAP Benchmark - Ver 2, Rel 4
Intune Policies - Intune Policy - April 2025
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Rev. 4 Sunset - Microsoft Windows 11 STIG - Ver 1, Rel 6
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 2, Rel 3
Microsoft Windows 10 STIG (Version 3, Release 4) Microsoft Windows 10
Defense Information Systems Agency
06/10/2025 SCAP 1.3 Content - Microsoft Windows 10 STIG SCAP Benchmark - Ver 3, Rel 4
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - April 2025
Intune Policies - Intune Policy - April 2025
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 3, Rel 4
Microsoft Windows Server 2019 (Ver 3, Rel 4) Microsoft Windows Server 2019
Defense Information Systems Agency
06/10/2025 SCAP 1.3 Content - Microsoft Windows Server 2019 STIG SCAP Benchmark Ver 3, Rel 4
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - April 2025
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 3, Rel 4
Microsoft Windows Server 2022 (Ver 2, Rel 4) Microsoft Windows Server 2022
Defense Information Systems Agency
06/10/2025 SCAP 1.3 Content - Microsoft Windows Server 2022 STIG SCAP Benchmark - Ver 2, Rel 4
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG for Chef - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG - Ver 2, Rel 4
Tanium 7.0 STIG (Ver 2, Rel 1) Tanium 7.0
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - Tanium 7.0 STIG - Ver 2, Rel 1
Oracle WebLogic Server 12c STIG (Ver 2, Rel 2) Oracle Weblogic Server
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - Oracle WebLogic Server 12c STIG - Ver 2, Rel 2
Microsoft SCOM STIG (Ver 1, Rel 1) Microsoft SCOM
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - Microsoft SCOM STIG - Ver 1, Rel 2
McAfee Application Control STIG (Ver 1, Rel 4) McAfee Application Control 7.0.0
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - McAfee Application Control 7.x STIG - Ver 1, Rel 4
IBM Aspera Platform 4.2 STIG (Ver 1, Rel 3) IBM Aspera Platform
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - IBM Aspera Platform 4.2 STIG - Ver 1, Rel 3
F5 BIG-IP STIG (Y25M01) F5 BIG-IP Access Policy Manager (APM)
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - F5 BIG-IP STIG
Apple macOS 13 STIG (Ver 1, Rel 5) Apple macOS 13.0 (Ventura)
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - Apple macOS 13 (Ventura) STIG - Ver 1, Rel 5
Apache 2.2 STIG - Windows (Version 1, Release 13) Apache HTTP Server 2.2
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - Apache 2.2 STIG Windows - Ver 1, Rel 13
Apache 2.2 STIG - UNIX (Version 1, Release 11) Apache HTTP Server 2.2
Defense Information Systems Agency
06/02/2025 Standalone XCCDF 1.1.4 - Sunset - Apache 2.2 STIG UNIX - Ver 1, Rel 11
* This checklist is still undergoing review for inclusion into the NCP.