U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 825 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Entra ID - SCuBA (1.5) Microsoft Azure Active Directory
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Machine-Readable Format - Microsoft Entra ID - GitHub
Prose - Microsoft Entra ID - SCuBA
Microsoft Power Platform - SCuBA (1.5.0) Microsoft Power Apps
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Machine-Readable Format - Microsoft Power Platform - GitHub
Prose - Microsoft Power Platform
Microsoft Exchange Online - SCuBA (1.5.0) Microsoft Exchange Online
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Machine-Readable Format - Microsoft Exchange Online - GitHub Markdown
Prose - Microsoft Exchange Online
Microsoft Defender for Office 365 - SCuBA (1.5.0) Microsoft Windows Defender
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Prose - CISA GitHub for ScubaGear - MSFT Defender
Prose - Microsoft Defender for Office 365
Microsoft Power BI - SCuBA (1.5.0) Microsoft Power Apps
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Machine-Readable Format - Microsoft Power BI GitHub Mark down
Prose - Microsoft Power BI
SharePoint and OneDrive - SCuBA (1.5.0) Microsoft OneDrive
Microsoft SharePoint Online
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Machine-Readable Format - Microsoft SharePoint & OneDrive GitHub
Prose - Microsoft SharePoint & OneDrive
Microsoft Teams - SCuBA (1.5.0) Microsoft Teams
Cybersecurity and Infrastructure Security Agency (CISA)
03/27/2025 Machine-Readable Format - Microsoft Teams GitHub
Prose - Microsoft Teams
Dell OS10 Switch STIG (Y24M12) Dell SmartFabric OS10
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Dell OS10 Switch STIG
HPE Aruba Networking AOS STIG (Y24M10) HPE ArubaOS
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - HPE Aruba Networking AOS STIG
CIS PostgreSQL 17 Benchmark (1.0.0) PostgreSQL 17.0
Center for Internet Security (CIS)
03/24/2025 Prose - CIS PostgreSQL 17 Benchmark v1.0.0
F5 BIG-IP TMOS STIG (Y24M09) F5 BIG-IP Access Policy Manager (APM)
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - F5 BIG-IP TMOS STIG
Ivanti EPMM Server STIG (Ver 3, Rel 1) Ivanti Endpoint Manager Mobile (EPMM)
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Ivanti EPMM Server STIG - Ver 3, Rel 1
Zebra Android 13 STIG (Y24M12) Google Android 13
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Zebra Android 13 STIG
MongoDB 7.x STIG (Ver 1, Rel 1) MongoDB 7.0.0
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - MongoDB 7.x STIG - Ver 1, Rel 1
CloudLinux AlmaLinux OS 9 STIG (Ver 1, Rel 1) AlmaLinux OS 9
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - CloudLinux AlmaLinux OS 9 STIG - Ver 1, Rel 1
Microsoft Intune Desktop STIG (Ver 1, Rel 1) Microsoft Intune
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Microsoft Intune Desktop STIG - Ver 1, Rel 1
HYCU Protg STIG (Ver 1, Rel 1) HYCU Protoge
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - HYCU Protg STIG - Ver 1, Rel 1
Apple iOS/iPadOS 18 STIG (Ver 1, Rel 2) Apple iPadOS 18.0
Apple iPhone OS 18.0
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 18 STIG - Ver 1, Rel 2
Dragos Platform 2.x STIG (Ver 1, Rel 2) Dragos Platform
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Dragos Platform 2.x STIG - Ver 1, Rel 2
Anduril NixOS STIG (Ver 1, Rel 1) Anduril NixOS
Defense Information Systems Agency
03/24/2025 Standalone XCCDF 1.1.4 - Anduril NixOS STIG - Ver 1, Rel 1
* This checklist is still undergoing review for inclusion into the NCP.