National Checklist Program Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 546 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Microsoft Windows Server 2019 (Ver 2, Rel 2) Microsoft Windows Server 2019
Defense Information Systems Agency
05/05/2021 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4 Windows
GPOs - Group Policy Objects (GPOs) - February 2021
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 2
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 2) Microsoft Windows Defender
Defense Information Systems Agency
05/05/2021 SCAP 1.2 Content - Microsoft Windows Defender Antivirus STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4 Windows
GPOs - Group Policy Objects (GPOs) - February 2021
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Antivirus STIG - Ver 2, Rel 2
Windows 10 STIG (Version 2, Release 2) Microsoft Windows 10
Defense Information Systems Agency
05/05/2021 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4 Windows
GPOs - Group Policy Objects (GPOs) - February 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 2, Rel 2
Microsoft Windows Server 2016 STIG (Version 2, Release 2) Microsoft Windows Server 2016
Defense Information Systems Agency
05/05/2021 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4 Windows
GPOs - Group Policy Objects (GPOs) - February 2021
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 2
Windows Server 2012 / 2012 R2 STIG (Version 3, Release 2) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
05/05/2021 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 1
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 1
Automated Content - SCC 5.4 Windows
GPOs - Group Policy Objects (GPOs) - February 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG - Ver 3, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 2
CIS Microsoft SQL Server 2016 Benchmark (1.3.0) Microsoft SQL Server 2016
Center for Internet Security (CIS)
05/04/2021 Prose - CIS Microsoft SQL Server 2016 Benchmark v1.3.0
CIS Microsoft SQL Server 2017 (1.2.0) Microsoft SQL Server 2017
Center for Internet Security (CIS)
05/04/2021 Prose - CIS Microsoft SQL Server 2017 Benchmark v1.2.0
CIS Microsoft SQL Server 2019 (1.2.0) Microsoft SQL Server 2019
Center for Internet Security (CIS)
05/04/2021 Prose - CIS Microsoft SQL Server 2019 Benchmark v1.2.0
Oracle MySQL 8.0 STIG (Ver 1, Rel 1) Oracle MySQL 8.0
Defense Information Systems Agency
05/04/2021 Standalone XCCDF 1.1.4 - Oracle MySQL 8.0 STIG, Ver 1, Rel 1
Citrix Virtual Apps and Desktops (VAD) 7.x STIG (Version 1, Release 1) Citrix StoreFront
Defense Information Systems Agency
05/04/2021 Standalone XCCDF 1.1.4 - Citrix Virtual Apps and Desktops (VAD) 7.x STIG
Cisco ISE STIG (Version 1, Release 1) Cisco Identity Services Engine
Defense Information Systems Agency
04/30/2021 Standalone XCCDF 1.1.4 - Cisco ISE STIG
Canonical Ubuntu 16.04 STIG (Ver 2, Rel 3) Canonical Ubuntu 16.04 LTS (Long Term Support)
Defense Information Systems Agency
04/30/2021 SCAP 1.2 Content - Sunset - Canonical Ubuntu 16.04 LTS STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.4 Ubuntu 16 AMD64
Automated Content - SCC 5.4 Ubuntu 16 i686
Automated Content - SCC 5.4 Ubuntu 18 AMD64
Standalone XCCDF 1.1.4 - Sunset - Canonical Ubuntu 16.04 LTS STIG - Ver 2, Rel 3
Solaris 11 (SPARC and x86) Manual STIG (Version 2, Release 3) Sun Solaris
Defense Information Systems Agency
04/30/2021 SCAP 1.2 Content - Solaris 11 SPARC STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Solaris 11 X86 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4 Solaris 10 i386
Automated Content - SCC 5.4 Solaris 10 SPARC
Automated Content - SCC 5.4 Solaris 11 i386
Automated Content - SCC 5.4 Solaris 11 SPARC
Standalone XCCDF 1.1.4 - Solaris 11 SPARC STIG - Ver 2, Rel 3
Standalone XCCDF 1.1.4 - Solaris 11 x86 STIG - Ver 2, Rel 3
Red Hat 6 STIG (Version 2, Release 2) Red Hat Enterprise Linux 6
Defense Information Systems Agency
04/30/2021 SCAP 1.2 Content - Sunset - Red Hat Enterprise Linux 6 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4 RHEL 6 i686
Automated Content - SCC 5.4 RHEL 6 x86 64
Automated Content - SCC 5.4 RHEL 7/Oracle Linux 7/SLES12 x86 64
Automated Content - SCC 5.4 RHEL 8 x86 64
Standalone XCCDF 1.1.4 - Sunset - Red Hat Enterprise Linux 6 STIG - Ver 2, Rel 2
SUSE Linux Enterprise Server (SLES) 12 STIG (Ver 2, Rel 3) SUSE Linux Enterprise Server 12.0
Defense Information Systems Agency
04/30/2021 SCAP 1.2 Content - Suse Linux Enterrprirse Server 12 STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.4 RHEL 6 i686
Automated Content - SCC 5.4 RHEL 6 x86 64
Automated Content - SCC 5.4 RHEL 7/Oracle Linux 7/SLES12 x86 64
Automated Content - SCC 5.4 RHEL 8 x86 64
Standalone XCCDF 1.1.4 - Suse Linux Enterprise Server (SLES) 12 STIG - Ver 2, Rel 3
Canonical Ubuntu 18.04 LTS for Ansible (Version 2, Release 2) Canonical Ubuntu 18.04 LTS for Ansible
Defense Information Systems Agency
04/30/2021 Automated Content - SCC 5.4 Ubuntu 16 AMD64
Automated Content - SCC 5.4 Ubuntu 16 i686
Automated Content - SCC 5.4 Ubuntu 18 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 18.04 LTS for Ansible STIG - Ver 2, Rel 2
IBM AIX 7.X STIG (Ver 2, Rel 2) IBM AIX 7.1
IBM AIX 7.2
Defense Information Systems Agency
04/30/2021 Standalone XCCDF 1.1.4 - IBM AIX 7.X STIG - Ver 2, Rel 2
zOS ACF2 STIG (Version 6, Release 49) IBM OS390
Defense Information Systems Agency
04/30/2021 Standalone XCCDF 1.1.4 - IBM z/OS STIG
Standalone XCCDF 1.1.4 - z/OS ACF2 Products - Ver 6, Rel 49
zOS TSS STIG (Version 6, Release 49) IBM OS390
Defense Information Systems Agency
04/30/2021 Standalone XCCDF 1.1.4 - IBM z/OS STIG
Standalone XCCDF 1.1.4 - z/OS TSS Products - Ver 6, Rel 49
zOS RACF STIG (Version 6, Release 49) IBM OS390
Defense Information Systems Agency
04/30/2021 Standalone XCCDF 1.1.4 - IBM z/OS STIG
Standalone XCCDF 1.1.4 - z/OS RACF Products - Ver 6, Rel 49
* This checklist is still undergoing review for inclusion into the NCP.