Checklist Repository
The National Checklist Program (NCP), defined by the NIST
SP 800-70, is the U.S. government repository of publicly available
security checklists (or benchmarks) that provide detailed low level
guidance on setting the security configuration of operating systems
and applications.
NCP provides metadata and links to checklists of various formats
including checklists that conform to the Security
Content Automation Protocol (SCAP). SCAP enables validated
security products to automatically perform configuration checking
using NCP checklists. For more information relating to the NCP please
visit the information page or
the glossary of terms.
Search for Checklists using the fields below. The keyword
search will search across the name, and summary.
There are 878
matching records. Displaying matches 81 through 100.
| Name (Version) |
Target |
Authority |
Last Modified |
Resources |
| Microsoft Windows 10 STIG (Version 3, Release 7) |
Microsoft Windows 10
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Sunset-Microsoft Windows 10 STIG SCAP Benchmark - Ver 3, Rel 7
Automated Content - SCC 5.14 Windows
GPOs - Group Policy Objects (GPOs) - January 2026
Intune Policies - Intune Policy - January 2026
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows 10 STIG - Ver 2, Rel 9
Standalone XCCDF 1.1.4 - Sunset-Microsoft Windows 10 STIG - Ver 3, Rel 6
|
| Microsoft Windows 11 STIG (Ver 2, Rel 7) |
Microsoft Windows 11
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Microsoft Windows 11 STIG SCAP Benchmark - Ver 2, Rel 7
Automated Content - SCC 5.14 Windows
GPOs - Group Policy Objects (GPOs) - January 2026
Intune Policies - Intune Policy - January 2026
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 2, Rel 6
|
| Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 7) |
Microsoft Windows Defender
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Microsoft Defender Antivirus STIG SCAP Benchmark - Ver 2, Rel 7
Automated Content - SCC 5.14 Windows
GPOs - Group Policy Objects (GPOs) - January 2026
Intune Policies - Intune Policy - January 2026
Standalone XCCDF 1.1.4 - Microsoft Defender Antivirus STIG - Ver 2, Rel 7
|
| Microsoft Windows Server 2016 STIG (Version 2, Release 10) |
Microsoft Windows Server 2016
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Sunset - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 8
Automated Content - SCC 5.14 Windows
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows Server 2016 STIG - Ver 2, Rel 10
|
| Microsoft Windows Server 2019 (Ver 3, Rel 7) |
Microsoft Windows Server 2019
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Microsoft Windows Server 2019 STIG SCAP Benchmark Ver 3, Rel 7
Automated Content - SCC 5.14 Windows
GPOs - Group Policy Objects (GPOs) - January 2026
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 3, Rel 7
|
| Microsoft Windows Server 2022 (Ver 2, Rel 7) |
Microsoft Windows Server 2022
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Microsoft Windows Server 2022 STIG SCAP Benchmark - Ver 2, Rel 7
Automated Content - SCC 5.14 Windows
GPOs - Group Policy Objects (GPOs) - January 2026
Standalone XCCDF 1.1.4 - Windows Server 2022 STIG with Ansible - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG for Chef - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG - Ver 2, Rel 7
|
| Monterey Guidance (Revision 6.0) |
Apple macOS 12.0 (Monterey)
|
NIST, macOS Security Compliance Project
|
06/06/2025 |
SCAP 1.3 Content - Monterey Guidance Revision 6.0
|
| Mozilla Firefox STIG (Version 6, Release 6) |
Mozilla Firefox
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Mozilla Firefox for Linux STIG SCAP Benchmark - Ver 6, Rel 6
SCAP 1.3 Content - Mozilla Firefox for Windows STIG SCAP Benchmark - Ver 6, Rel 7
Automated Content - SCC 5.14 Windows
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Automated Content - SCC 5.14 Ubuntu 18/20 AMD64
Automated Content - SCC 5.14 Ubuntu 20/Raspios-bulleye Aarch64
Automated Content - SCC 5.14 Ubuntu 22/24 AMD64
Automated Content - SCC 5.14 Ubuntu 22/24 ARM64
GPOs - Group Policy Objects (GPOs) - January 2026
Intune Policies - Intune Policy - January 2026
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 7
|
| NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) |
Red Hat Enterprise Linux 7.0 Red Hat Enterprise Linux 7.1 Red Hat Enterprise Linux 7.2 Red Hat Enterprise Linux 7.3 Red Hat Enterprise Linux 7.4 Red Hat Enterprise Linux 7.5 Red Hat Enterprise Linux 7.6 Red Hat Enterprise Linux 7.7
|
Red Hat
|
08/30/2024 |
SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
|
| NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.50) |
Red Hat Enterprise Linux 8.0 Red Hat Enterprise Linux 8.1 Red Hat Enterprise Linux 8.2
|
Red Hat
|
08/30/2024 |
SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 8.x
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
|
| NIST National Checklist for Red Hat OpenShift Container Platform 3.x (content v0.1.48) |
Red Hat OpenShift Container Platform 3.10 Red Hat OpenShift Container Platform 3.11 Red Hat OpenShift Container Platform 3.5 Red Hat OpenShift Container Platform 3.6 Red Hat OpenShift Container Platform 3.7 Red Hat OpenShift Container Platform 3.8 Red Hat OpenShift Container Platform 3.9
|
Red Hat
|
10/26/2020 |
SCAP 1.3 Content - NIST National Checklist for Red Hat OpenShift Container Platform 3.x
Machine-Readable Format - OpenControl-formatted NIST 800-53/FISMA Applicability Guide for OpenShift 3.x
|
| NIST National Checklist for Red Hat Virtualization Host 4.x (content v0.1.48) |
Red Hat Virtualization Host 4.3
|
Red Hat
|
10/26/2020 |
SCAP 1.3 Content - NIST National Checklist for Red Hat Virtualization Host 4.x
Ansible Playbook - [DRAFT] DISA STIG for Red Hat Virtualization Host (RHVH)
Ansible Playbook - VPP - Protection Profile for Virtualization v. 1.0 for Red Hat Virtualization Hypervisor (RHVH)
Machine-Readable Format - OpenControl-formatted NIST 800-53 responses for Red Hat Virtualization Host 4.x
|
| Oracle Linux 7 STIG (Ver 3, Rel 4) |
Oracle Linux 7
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Sunset - Oracle Linux 7 STIG Benchmark - Ver 3, Rel 3
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Sunset - Oracle Linux 7 STIG - Ver 3, Rel 5
|
| Oracle Linux 9 STIG (Ver 1, Rel 3) |
Oracle Linux 9.0
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Oracle Linux 9 STIG SCAP Benchmark - Ver 1, Rel 2
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Oracle Linux 9 STIG - Ver 1, Rel 4
Standalone XCCDF 1.1.4 - Oracle Linux 9 STIG for Ansible - Ver 1, Rel 4
Standalone XCCDF 1.1.4 - Oracle Linux 9 STIG for Chef - Ver 1, Rel 4
|
| Red Hat Enterprise Linux 7 STIG (Ver 3, Rel 15) |
Red Hat Enterprise Linux 7.0
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Sunset - Red Hat Enterprise Linux 7 STIG Benchmark - Ver 3, Rel 15
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Sunset - Red Hat Enterprise Linux 7 STIG for Ansible - Ver 3, Rel 14
Standalone XCCDF 1.1.4 - Sunset - Red Hat Enterprise Linux 7 STIG - Ver 3, Rel 15
Standalone XCCDF 1.1.4 - Sunset - Red Hat Enterprise Linux 7 STIG for Chef - Ver 3, Rel 8
|
| Red Hat Enterprise Linux 9 (Ver 2, Rel 7) |
Red Hat Enterprise Linux 9.0
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Sunset - Red Hat Enterprise Linux 9 Benchmark - Ver 1, Rel 1
SCAP 1.3 Content - Red Hat Enterprise Linux 9 STIG SCAP Benchmark - Ver 2, Rel 7
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 9 STIG - Ver 2, Rel 7
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 9 STIG for Ansible- Ver 2, Rel 7
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 9 STIG for Chef - Ver 2, Rel 7
|
| Sonoma Guidance (Revision 4.0) |
Apple macOS 14.0
|
NIST, macOS Security Compliance Project
|
07/09/2025 |
SCAP 1.3 Content - Sonoma Guidance, Revision 4.0
|
| SUSE Linux Enterprise Server (SLES) 12 STIG (Ver 3, Rel 4) |
SUSE Linux Enterprise Server 12.0
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Sunset - SUSE Linux Enterprise Server 12 STIG Benchmark - Ver 3, Rel 4
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 12 STIG - Ver 3, Rel 4
|
| Tri-Lab Operating System Stack (TOSS) 4 STIG Benchmark (Ver 2, Rel 5) |
Tri-Lab Operating System Stack (TOSS)
|
Defense Information Systems Agency
|
02/13/2026 |
SCAP 1.3 Content - Tri-Lab Operating System Stack (TOSS) 4 STIG SCAP Benchmark - Ver 2, Rel 5
Automated Content - SCC 5.14 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.14 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 Aarch64
Automated Content - SCC 5.14 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Tri-Lab Operating System Stack (TOSS) 4 STIG - Ver 2, Rel 4
|
| United States Government Configuration Baseline for Claroty CTD 5.x (checklist v0.1) |
Claroty CTD 5.x
|
Mission IT
|
04/03/2026 |
SCAP 1.3 Content - United States Government Configuration Baseline fo
Reference Link - NIST 800-53 Rev5 Control Mappings
Reference Link - DOD SRG and DOD STIG Control Mappings
|
* This checklist is still undergoing review for
inclusion into the NCP.