Skip to main content
Category: Classified Information Management

Committee on National Security Systems Instruction No. 1253

Also known as: CNSSI 1253, CNSSI No. 1253, CNSS Instruction 1253, Security Categorization and Control Selection for National Security Systems
Simply put

CNSSI 1253 is a government instruction that explains how to categorize the sensitivity of national security systems and select the security controls needed to protect them. It applies specifically to national security systems rather than ordinary federal civilian systems, which follow separate guidance. In practice, it serves as the counterpart to the categorization method used for non-national-security systems.

Formal definition

CNSSI 1253, titled 'Security Categorization and Control Selection for National Security Systems,' is issued by the Committee on National Security Systems (CNSS). It establishes the security categorization methodology and control selection process for national security systems (NSS), serving as the NSS counterpart to FIPS 199, which addresses security categorization for other-than-national-security systems. As reflected in NIST's glossary, categorization methodologies for NSS are described in CNSSI 1253 while FIPS 199 governs non-NSS. The instruction is generally used alongside NIST SP 800-53 control catalogs and includes overlays (for example, a classified information overlay) that tailor controls for specific NSS contexts. Practitioners should verify the current revision, applicable overlays, and the precise categorization and control-selection procedures against the authoritative CNSS-published text, as this entry does not cover implementation, contractual, or authorization specifics.

Why it matters

National security systems face a threat environment and consequence profile distinct from ordinary federal civilian systems, and the way an organization categorizes those systems drives every subsequent protection decision. CNSSI 1253 matters because it provides the categorization methodology and control selection process purpose-built for national security systems (NSS), serving as the NSS counterpart to FIPS 199, which addresses categorization for other-than-national-security systems. Getting the categorization right determines which controls are selected and how systems are protected, so applying the wrong methodology to an NSS can misalign controls with the actual sensitivity and mission risk of the system.

A common and consequential mistake is treating FIPS 199 and CNSSI 1253 as interchangeable. As reflected in NIST's glossary, categorization methodologies for NSS are described in CNSSI 1253, while FIPS 199 governs non-NSS. These are separate authorities with separate scopes, and defaulting to the civilian approach for a national security system can result in an inappropriate baseline. Because CNSSI 1253 is generally used alongside NIST SP 800-53 control catalogs and includes overlays that tailor controls for specific NSS contexts, the categorization step is not a paperwork formality but the foundation that shapes the entire control set.

It is also important to remember that categorization and control selection are early steps, not the end of the process. Selecting controls under CNSSI 1253 is not the same as assessing them, and neither is equivalent to obtaining an authorization to operate. Compliance with a categorization and selection methodology does not by itself establish that a system is secure or authorized; those outcomes depend on assessment, authorization, and ongoing continuous monitoring against the current authoritative text.

Who it's relevant to

Information System Security Managers and Engineers for NSS
Personnel responsible for categorizing and protecting national security systems rely on CNSSI 1253 to determine the correct categorization and to select an appropriate control set, typically alongside NIST SP 800-53. They should confirm which overlays apply, including any classified information overlay, against the current CNSS-published text.
Security Control Assessors
Cybersecurity and information security professionals responsible for the assessment of controls need to understand how controls were selected under CNSSI 1253 for NSS. It is worth emphasizing that assessment is distinct from selection and from authorization; assessing controls does not by itself confer an authority to operate.
Authorizing Officials and Risk Executives
Those making risk-based authorization decisions for national security systems depend on categorization and control selection carried out under CNSSI 1253. They should treat categorization as a foundation for, not a substitute for, assessment, authorization, and continuous monitoring, and should verify that the correct methodology (CNSSI 1253 for NSS rather than FIPS 199 for non-NSS) was applied.
Government Departments, Agencies, and Contractors Handling NSS
Federal government departments and organizations operating or supporting national security systems use CNSSI 1253 as the governing categorization and control-selection guidance for those systems. Because scope boundaries between NSS and other-than-NSS matter, they should confirm whether a given system qualifies as an NSS before applying this instruction rather than FIPS 199.

Inside CNSSI 1253

Categorization Guidance for National Security Systems
CNSSI 1253, issued by the Committee on National Security Systems (CNSS), provides guidance for categorizing national security systems (NSS) and selecting associated security controls. It serves a role for NSS analogous to what FIPS 199 and NIST SP 800-53 baselines serve for non-NSS federal information systems.
Confidentiality, Integrity, and Availability Categorization
Rather than using a single 'high water mark' overall impact level, CNSSI 1253 generally directs that the three security objectives (confidentiality, integrity, and availability) be assessed and categorized independently, allowing more granular impact determinations for national security systems.
Security Control Baselines and Overlays for NSS
The instruction identifies control baselines drawn from NIST SP 800-53 and incorporates the concept of overlays to tailor control selections to specific NSS communities, missions, or technologies. Practitioners should verify the applicable revision, as baselines change across NIST SP 800-53 revisions and corresponding CNSS updates.
Relationship to the Risk Management Framework
CNSSI 1253 supports the categorize and select steps of the Risk Management Framework (RMF) as applied to national security systems, complementing NIST RMF guidance while addressing the distinct requirements of the NSS community.
Scope Limited to National Security Systems
The document applies to systems that meet the statutory definition of national security systems. It is not the governing categorization authority for federal civilian systems under FISMA (which use FIPS 199 and FIPS 200) or, by itself, for the categorization of Controlled Unclassified Information in non-NSS contexts.

Common questions

Answers to the questions practitioners most commonly ask about CNSSI 1253.

Does CNSSI 1253 replace or supersede NIST SP 800-53?
No. CNSSI 1253, issued by the Committee on National Security Systems (CNSS), does not replace NIST SP 800-53. Instead, it works alongside it, providing guidance on how to apply the NIST SP 800-53 control catalog and the categorization process to national security systems (NSS). NIST maintains the underlying control catalog, while CNSSI 1253 addresses how those controls and baselines are selected and tailored for the NSS context. Confirm the applicable revisions of both documents against current authoritative sources, as they are updated on separate cycles.
Can I use FIPS 199 and the standard NIST categorization approach directly for a national security system?
Not without accounting for the differences CNSSI 1253 introduces. For national security systems, CNSSI 1253 generally provides a categorization approach that differs from the FIPS 199 method used for federal civilian systems, including how confidentiality, integrity, and availability are treated. Rather than assuming the civilian approach transfers directly, practitioners working on NSS should follow the categorization and baseline guidance in CNSSI 1253. Verify the specifics against the current version of the instruction, as tailoring and categorization details may change across revisions.
How do I determine whether a system falls under CNSSI 1253 in the first place?
CNSSI 1253 applies to national security systems, so the threshold question is whether a given system meets the definition of an NSS under the governing authorities. This determination is generally made based on the system's mission, the information it processes, and applicable statutory and policy definitions rather than on a single technical attribute. Because misclassifying a system can lead to applying the wrong control selection process, coordinate this determination with your authorizing official and relevant governing authorities, and confirm against current official definitions.
How does CNSSI 1253 fit into the Risk Management Framework (RMF) process for NSS?
CNSSI 1253 is generally used during the categorization and control selection steps of the RMF as applied to national security systems. It informs how a system is categorized and which security control baseline is selected before controls are implemented, assessed, and authorized. It does not by itself produce an authorization; assessment and authorization remain distinct downstream activities performed under the applicable RMF process and the authorizing official's decision. Confirm how your organization integrates CNSSI 1253 into its specific RMF implementation.
Does following CNSSI 1253 tailoring guidance mean my system is fully compliant and secure?
No. Applying the categorization and control selection guidance in CNSSI 1253 supports a defensible control baseline, but selection and tailoring are only part of the process. Controls still must be implemented, assessed, and authorized, and authorization is time-bound and subject to continuous monitoring rather than permanent. Compliance with a control selection process should not be equated with achieving effective security; both must be evaluated on an ongoing basis against the system's actual risk posture.
Where should I go to confirm the correct control baselines and overlays when using CNSSI 1253?
Practitioners should work from the current authoritative CNSS-issued version of CNSSI 1253 together with the applicable revision of the NIST SP 800-53 control catalog, since baselines and overlays can change across revisions. Organization-specific or mission-specific overlays may also apply and can affect which controls are selected. Because agency interpretation and tailoring may differ, coordinate baseline and overlay decisions with your authorizing official and verify all details against the current official documents rather than relying on prior versions or secondary summaries.

Common misconceptions

CNSSI 1253 is the same as, or interchangeable with, FIPS 199 and NIST SP 800-53.
CNSSI 1253 is issued by the CNSS specifically for national security systems and draws on the NIST control catalog, but it applies a categorization approach tailored to NSS. FIPS 199 and NIST SP 800-53 are NIST publications; conflating the issuing bodies and their scope is a common error an expert would correct. Confirm the current authoritative text of each before relying on it.
CNSSI 1253 requires a single overall impact level using the high water mark, like FIPS 199 categorization.
For national security systems, CNSSI 1253 generally provides for categorizing confidentiality, integrity, and availability independently rather than collapsing them into one overall impact value. Verify the exact methodology against the applicable revision of the instruction.
CNSSI 1253 applies to all federal information systems.
Its scope is national security systems. Federal civilian systems are categorized under FISMA using FIPS 199/200, and CUI or DoD-specific obligations may follow separate authorities. Do not assume CNSSI 1253 governs a system without first confirming it qualifies as an NSS.

Best practices

Confirm that a system meets the statutory definition of a national security system before applying CNSSI 1253, and use the appropriate civilian or CUI authorities where the system falls outside NSS scope.
Categorize confidentiality, integrity, and availability independently as the instruction generally directs, and document the rationale for each objective's impact determination.
Verify which revision of CNSSI 1253 and which corresponding NIST SP 800-53 revision apply, since control baselines and tailoring guidance change across updates.
Apply relevant overlays to tailor control baselines to the specific mission, community, or technology rather than relying on an untailored baseline.
Coordinate categorization decisions with the authorizing official and RMF process, treating categorization as an input to authorization rather than as authorization itself.
Cross-check all control selections, baselines, and categorization outcomes against the current official CNSS and NIST source documents before finalizing, and do not assume interchangeability with FISMA or FedRAMP requirements.