National Checklist Program Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 542 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Canonical Ubuntu 16.04 STIG (Ver 2, Rel 2) Canonical Ubuntu 16.04 LTS (Long Term Support)
Defense Information Systems Agency
04/12/2021 SCAP 1.2 Content - Canonical Ubuntu 16.04 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4 Ubuntu 16 AMD64
Automated Content - SCC 5.4 Ubuntu 16 i686
Automated Content - SCC 5.4 Ubuntu 18 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 16.04 LTS STIG - Ver 2, Rel 2
Canonical Ubuntu 20.04 LTS STIG (Ver 1, Rel 1) Canonical Ubuntu Linux 20.04 (Long-term Support)
Defense Information Systems Agency
04/09/2021 Standalone XCCDF 1.1.4 - Canonical Ubuntu 20.04 LTS STIG - Ver 1, Rel 1
Suse Linux Enterprise Server (SLES) 15 STIG (Version 1, Release 1) SUSE Enterprise Linux 15
Defense Information Systems Agency
04/07/2021 Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 15 STIG - Ver 1, Rel 1
Citrix Virtual Apps and Desktops (VAD) 7.x STIG (Version 1, Release 1) Citrix StoreFront
Defense Information Systems Agency
03/31/2021 Standalone XCCDF 1.1.4 - Citrix Virtual Apps and Desktops (VAD) 7.x STIG
Oracle MySQL 8.0 STIG (Ver 1, Rel 1) Oracle MySQL 8.0
Defense Information Systems Agency
03/30/2021 Standalone XCCDF 1.1.4 - Oracle MySQL 8.0 STIG, Ver 1, Rel 1
CIS PostgreSQL 13 Benchmark (1.0.0) PostgreSQL 12
Center for Internet Security (CIS)
03/29/2021 Prose - CIS PostgreSQL 13 Benchmark v1.0.0
Big Sur Guidance (Revision 2) Apple macOS 11.0 (Big Sur)
NIST, macOS Security Compliance Project
03/29/2021 SCAP 1.3 Content - Big Sur Guidance
Catalina Guidance (Revision 3) Apple OS X 10.15
NIST, macOS Security Compliance Project
03/29/2021 SCAP 1.3 Content - Catalina Guidance
Microsoft Edge STIG (Ver 1, Rel 1) Microsoft Edge
Defense Information Systems Agency
03/23/2021 Standalone XCCDF 1.1.4 - Microsoft Edge STIG - Ver 1, Rel 1
CIS IBM AIX 5.3 - AIX 6.1 Benchmark (1.1.0) IBM AIX 5.3
IBM AIX 6.1
Center for Internet Security (CIS)
03/16/2021 Prose - CIS IBM AIX 5.3 - AIX 6.1 Benchmark 1.1.0
Vanguard Compliance Manager z/OS RACF ACF2 TSS Checklist for completing a manual SRR Audit for Stig (6.43) IBM z/OS Version 2, Release 2
IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
03/11/2021 ZIP - Vanguard z/OS RACF Checklist 6.43 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.43 XML version
ZIP - Vanguard z/OS RACF Checklist 6.43 PDF version for ACF2
ZIP - Vanguard z/OS RACF Checklist 6.43 PDF version for TSS
ZIP - Vanguard z/OS RACF Checklist 6.43 XML version for ACF2
ZIP - Vanguard z/OS RACF Checklist 6.43 XML version for TSS
Canonical Ubuntu 18.04 LTS for Ansible (Version 2, Release 1) Canonical Ubuntu 18.04 LTS for Ansible
Defense Information Systems Agency
03/11/2021 Standalone XCCDF 1.1.4 - Canonical Ubuntu 18.04 LTS for Ansible
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.47-8.1) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
03/10/2021 ZIP - Vanguard z/OS RACF Checklist 6.47/8.1 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.47/8.1 XML version
Infoblox 8.x Domain Name System (DNS) STIG (Version 1, Release 1) Infoblox 8.x Domain Name System (DNS)
Defense Information Systems Agency
03/04/2021 Standalone XCCDF 1.1.4 - Infoblox 8.x DNS STIG - Ver 1, Rel 1
CIS PostgreSQL 12 Benchmark (1.0.0) PostgreSQL 12
Center for Internet Security (CIS)
03/04/2021 Prose - CIS PostgreSQL 12 Benchmark v1.0.0
Microsoft Windows Server 2019 (Ver 2, Rel 1) Microsoft Windows Server 2019
Defense Information Systems Agency
03/03/2021 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 1
GPOs - Group Policy Objects (GPOs) - February 2021
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 1
Honeywell Android 9.x STIG (Version 1, Release 1) Google Android 9.x
Defense Information Systems Agency
03/03/2021 Standalone XCCDF 1.1.4 - Honeywell Android 9.x STIG
Windows Server 2012 / 2012 R2 STIG (Version 3, Release 1) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
03/01/2021 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 1
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 1
GPOs - Group Policy Objects (GPOs) - February 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG - Ver 3, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 1
Microsoft Office System 2013 STIG (Version 2, Release 1) Office System 2013
Defense Information Systems Agency
03/01/2021 GPOs - Group Policy Objects (GPOs) - February 2021
Standalone XCCDF 1.1.4 - Microsoft Office System 2013 STIG - Ver 2, Rel 1
Google Chrome Browser STIG for Windows (Version 2, Release 2) Google Chrome 33
Defense Information Systems Agency
03/01/2021 SCAP 1.2 Content - Google Chrome for Windows STIG Benchmark - Ver 2, Rel 2
GPOs - Group Policy Objects (GPOs) - February 2021
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 2
* This checklist is still undergoing review for inclusion into the NCP.