National Checklist Program Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 530 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Microsoft Windows Server 2016 STIG (Version 2, Release 1) Microsoft Windows Server 2016
Defense Information Systems Agency
12/03/2020 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 1
GPOs - Group Policy Objects (GPOs) - November 2020
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 1
Windows Server 2012 / 2012 R2 STIG (Version 3, Release 1) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
12/03/2020 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 1
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 1
GPOs - Group Policy Objects (GPOs) - November 2020
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG - Ver 3, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 1
Microsoft Windows Server 2019 (Ver 2, Rel 1) Microsoft Windows Server 2019
Defense Information Systems Agency
12/03/2020 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 1
GPOs - Group Policy Objects (GPOs) - November 2020
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 1
Microsoft One Drive for Business 2016 STIG (Version 2, Release 1) Microsoft One Drive for Business 2016
Defense Information Systems Agency
12/03/2020 Standalone XCCDF 1.1.4 - Microsoft OneDrive - Ver 2, Rel 1
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 1) Microsoft Windows Defender
Defense Information Systems Agency
12/03/2020 SCAP 1.2 Content - Microsoft Windows Defender Antivirus STIG Benchmark - Ver 2, Rel 1
GPOs - Group Policy Objects (GPOs) - November 2020
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Antivirus STIG - Ver 2, Rel 1
Windows 10 STIG (Version 2, Release 1) Microsoft Windows 10
Defense Information Systems Agency
12/03/2020 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 2, Rel 1
GPOs - Group Policy Objects (GPOs) - November 2020
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 2, Rel 1
Oracle JRE 8 Windows STIG (Version 1, Release 5) Oracle JRE 8 for Windows
Defense Information Systems Agency
12/02/2020 Standalone XCCDF 1.1.4 - Sunset - Oracle JRE 8 Windows STIG - Ver 1, Rel 5
Oracle JRE 8 UNIX STIG (Ver 1, Rel 3) Oracle JRE for UNIX
Defense Information Systems Agency
12/02/2020 Standalone XCCDF 1.1.4 - Sunset - Oracle JRE 8 UNIX STIG - Ver 1, Rel 3
FedRAMP Moderate for Red Hat OpenStack Platform 13 (v1) Red Hat OpenStack Platform 13.0
Red Hat
12/01/2020 Security Template - NIST 800-53 Control Applicability Guide for Red Hat OpenStack Platform 13
Security Template - FedRAMP Moderate Template SSP for Red Hat OpenStack Platform 13
FedRAMP Low for Red Hat Ansible Tower 3.2.x (v1) Red Hat Ansible Tower 3.2.0
Red Hat Ansible Tower 3.2.1
Red Hat Ansible Tower 3.2.2
Red Hat Ansible Tower 3.2.3
Red Hat Ansible Tower 3.2.4
Red Hat Ansible Tower 3.2.5
Red Hat Ansible Tower 3.2.6
Red Hat
12/01/2020 Security Template - NIST 800-53 Control Applicability Guide for Red Hat Ansible Tower 3.2.x
Security Template - FedRAMP Template for Red Hat Ansible Tower 3.x
Prose - Section 508 Voluntary Product Accessibility Template (VPAT) and Web Content Accessibility Guidelines (WCAG) 2.0 for Ansible Tower
CIS Oracle Database 19c Benchmark (1.0.0) Oracle Database 19c
Center for Internet Security (CIS)
11/30/2020 Prose - CIS Oracle Database Server 19c Benchmark v1.0.0
ISEC7 Sphere STIG (Ver 2, Rel 1) ISEC7 Sphere
Defense Information Systems Agency
11/30/2020 Standalone XCCDF 1.1.4 - ISEC7 Sphere STIG - Ver 2, Rel 1
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.44/71,6.45/72 and 6.46/73) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
11/20/2020 ZIP - Vanguard z/OS RACF Checklist 6.44/7.1 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.45/7.2 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.46/7.3 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.44/7.1 XML version
ZIP - Vanguard z/OS RACF Checklist 6.45/7.2 XML version
ZIP - Vanguard z/OS RACF Checklist 6.46/7.3 XML version
Vanguard Compliance Manager z/OS RACF Checklist for completing a automated SRR Audit for Stig (6.44/71,6.45/72 and 6.46/73) IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
11/20/2020 ZIP - Vanguard z/OS RACF Checklist 6.44-6.46/7.1-7.3(For Z/OS V2R4 release)
Juniper SRX Services Gateway (SG) STIG (Ver 2, Rel 1) Juniper SRX Services Gateway (SG)
Defense Information Systems Agency
11/20/2020 Standalone XCCDF 1.1.4 - Juniper SRX SG STIG for Ansible - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Juniper SRX SG STIG
Canonical Ubuntu 18.04 LTS STIG (Ver 2, Rel 1) Canonical Ubuntu Linux 18.04 LTS
Defense Information Systems Agency
11/20/2020 SCAP 1.2 Content - Canonical Ubuntu 18.04 STIG Benchmark - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Canonical Ubuntu 18.04 LTS STIG - Ver 2, Rel 1
Catalina Guidance (Revision 2) Apple OS X 10.15
NIST, macOS Security Compliance Project
11/16/2020 SCAP 1.3 Content - Catalina Guidance
Samsung SDS EMM STIG (Ver 1, Rel 1) Samsung SDS EMM
Defense Information Systems Agency
11/13/2020 Standalone XCCDF 1.1.4 - Samsung SDS EMM STIG - Ver 1, Rel 1
Apple OS/iPad OS 14 STIG (Ver 1, Rel 1) Apple iPad OS/iOS 14.0
Defense Information Systems Agency
11/13/2020 Standalone XCCDF 1.1.4 - Apple OS/iPad OS 14 STIG - Ver 1, Rel 1
Google Android 11 STIG (version 1, release 1) Google Android 11.0
Defense Information Systems Agency
11/13/2020 Standalone XCCDF 1.1.4 - Google Android 11 STIG
* This checklist is still undergoing review for inclusion into the NCP.