U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 829 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 3) Adobe Acrobat Reader
Defense Information Systems Agency
03/31/2025 SCAP 1.3 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - January 2025
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 2, Rel 1
Big Sur Guidance (Revision 7.0) Apple macOS 11.0 (Big Sur)
NIST, macOS Security Compliance Project
04/30/2024 SCAP 1.3 Content - Big Sur Guidance Revision 7.0
Canonical Ubuntu 18.04 LTS STIG (Ver 2, Rel 15) Canonical Ubuntu Linux 18.04 LTS
Defense Information Systems Agency
03/31/2025 SCAP 1.3 Content - Sunset - Canonical Ubuntu 18.04 LTS STIG Benchmark - Ver 2, Rel 12
SCAP 1.2 Content - Sunset - Canonical Ubuntu 18.04 LTS STIG Benchmark - Ver 2, Rel 11
Automated Content - SCC 5.10.2 Ubuntu 18/20 AMD64
Automated Content - SCC 5.10.2 Ubuntu 20/Raspios-bulleye Aarch64
Automated Content - SCC 5.10.2 Ubuntu 22 AMD64
Standalone XCCDF 1.1.4 - Sunset - Canonical Ubuntu 18.04 LTS STIG - Ver 2, Rel 15
Canonical Ubuntu 20.04 LTS STIG (Ver 2, Rel 3) Canonical Ubuntu 20.04 LTS
Defense Information Systems Agency
04/09/2025 SCAP 1.3 Content - Canonical Ubuntu 20.04 LTS STIG SCAP Benchmark - Ver 2, Rel 3
SCAP 1.2 Content - Sunset - Canonical Ubuntu 20.04 LTS STIG Benchmark - Ver 1, Rel 9
Automated Content - SCC 5.10.2 Ubuntu 18/20 AMD64
Automated Content - SCC 5.10.2 Ubuntu 20/Raspios-bulleye Aarch64
Automated Content - SCC 5.10.2 Ubuntu 22 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 20.04 LTS STIG for Ansible - Ver 1, Rel 11
Standalone XCCDF 1.1.4 - Canonical Ubuntu 20.04 LTS STIG - Ver 2, Rel 2
Canonical Ubuntu 22.04 LTS STIG (Ver 2, Rel 4) Canonical Ubuntu 22.04 LTS
Defense Information Systems Agency
04/25/2025 SCAP 1.3 Content - Canonical Ubuntu 22.04 LTS STIG SCAP Benchmark - Ver 2, Rel 3
Standalone XCCDF 1.1.4 - Canonical Ubuntu 22.04 LTS STIG - Ver 2, Rel 4
Catalina Guidance (Revision 6) Apple OS X 10.15
NIST, macOS Security Compliance Project
03/18/2022 SCAP 1.3 Content - Catalina Guidance
Cisco IOS Router STIG (Y25M01) Cisco IOS
Defense Information Systems Agency
04/11/2025 SCAP 1.3 Content - Cisco IOS XE Router NDM STIG Benchmark - Ver 3, Rel 2
SCAP 1.3 Content - Cisco IOS XE Router RTR STIG Benchmark - Ver 3, Rel 2
Standalone XCCDF 1.1.4 - Cisco IOS XE Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XR Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XE Router NDM RTR STIG for Ansible - Ver 2, Rel 3
Google Chrome Browser STIG for Windows (Version 2, Release 10) Google Chrome 33
Defense Information Systems Agency
03/31/2025 SCAP 1.3 Content - Google Chrome STIG Benchmark - Ver 2, Rel 10
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - January 2025
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 10
Kubernetes STIG (Ver 2, Rel 3) Kubernetes
Defense Information Systems Agency
04/09/2025 SCAP 1.3 Content - Kubernetes STIG SCAP Benchmark - Ver 2, Rel 3
SCAP 1.2 Content - Sunset - Kubernetes STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Kubernetes STIG - Ver 2, Rel 3
Microsoft .NET Framework 4 (Version 2, Release 6) Microsoft .NET Framework 4.0
Defense Information Systems Agency
04/16/2025 SCAP 1.3 Content - Microsoft DotNet Framework 4.0 STIG SCAP Benchmark - Ver 2, Rel 6
Automated Content - SCC 5.10.2 Windows
Standalone XCCDF 1.1.4 - Microsoft DotNet Framework 4.0 STIG - Ver 2, Rel 6
Microsoft Edge STIG (Ver 2, Rel 2) Microsoft Edge
Defense Information Systems Agency
02/27/2025 SCAP 1.3 Content - Microsoft Edge STIG Benchmark - Ver 2, Rel 2
GPOs - Group Policy Objects (GPOs) - January 2025
Standalone XCCDF 1.1.4 - Microsoft Edge STIG - Ver 2, Rel 2
Microsoft Office 365 ProPlus STIG (Ver 3, Rel 3) Microsoft Office 365 ProPlus
Defense Information Systems Agency
04/09/2025 SCAP 1.3 Content - Microsoft Office 365 ProPlus STIG SCAP Benchmark - Ver 3, Rel 4
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - January 2025
Standalone XCCDF 1.1.4 - Rev. 4 Sunset - Microsoft Office 365 ProPlus STIG - Ver 2, Rel 12
Standalone XCCDF 1.1.4 - Microsoft Office 365 ProPlus STIG - Ver 3, Rel 3
Microsoft Windows 10 STIG (Version 3, Release 4) Microsoft Windows 10
Defense Information Systems Agency
04/09/2025 SCAP 1.3 Content - Microsoft Windows 10 STIG SCAP Benchmark - Ver 3, Rel 4
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - January 2025
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 3, Rel 4
Microsoft Windows 11 STIG (Ver 2, Rel 3) Microsoft Windows 11
Defense Information Systems Agency
04/09/2025 SCAP 1.3 Content - Microsoft Windows 11 STIG SCAP Benchmark - Ver 2, Rel 4
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Rev. 4 Sunset - Microsoft Windows 11 STIG - Ver 1, Rel 6
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 2, Rel 3
Microsoft Windows Server 2016 STIG (Version 2, Release 10) Microsoft Windows Server 2016
Defense Information Systems Agency
03/31/2025 SCAP 1.3 Content - Sunset - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 8
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - January 2025
Machine-Readable Format - Sunset - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows Server 2016 STIG - Ver 2, Rel 10
Microsoft Windows Server 2019 (Ver 3, Rel 4) Microsoft Windows Server 2019
Defense Information Systems Agency
04/10/2025 SCAP 1.3 Content - Microsoft Windows Server 2019 STIG SCAP Benchmark Ver 3, Rel 4
Automated Content - SCC 5.10.2 Windows
GPOs - Group Policy Objects (GPOs) - January 2025
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 3, Rel 4
Microsoft Windows Server 2022 (Ver 2, Rel 4) Microsoft Windows Server 2022
Defense Information Systems Agency
04/09/2025 SCAP 1.3 Content - Microsoft Windows Server 2022 STIG SCAP Benchmark - Ver 2, Rel 4
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG for Chef - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG - Ver 2, Rel 4
Monterey Guidance (Revision 6.0) Apple macOS 12.0 (Monterey)
NIST, macOS Security Compliance Project
04/30/2024 SCAP 1.3 Content - Monterey Guidance Revision 6.0
Mozilla Firefox STIG (Version 6, Release 6) Mozilla Firefox
Defense Information Systems Agency
04/11/2025 SCAP 1.3 Content - Mozilla Firefox for Linux STIG SCAP Benchmark - Ver 6, Rel 5
SCAP 1.3 Content - Mozilla Firefox for Windows STIG SCAP Benchmark - Ver 6, Rel 6
Automated Content - SCC 5.10.2 Windows
Automated Content - SCC 5.10.2 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.10.2 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.10.2 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.10.2 RHEL 9/Oracle Linux 9 x86 64
GPOs - Group Policy Objects (GPOs) - January 2025
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 5
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 6
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat Enterprise Linux 7.7
Red Hat
08/30/2024 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
* This checklist is still undergoing review for inclusion into the NCP.