Skip to main content
Category: NIST Standards & Publications

FIPS 200

Also known as: FIPS 200, Federal Information Processing Standard 200, Minimum Security Requirements for Federal Information and Information Systems
Simply put

FIPS 200 is a U.S. government standard, issued by NIST and approved in March 2006, that sets the minimum security requirements federal agencies must meet to protect their information and information systems. It identifies broad security-related areas that agencies must address and points to a risk-based approach for choosing the specific safeguards. Because it is a Federal Information Processing Standard, it establishes a mandatory baseline rather than optional guidance for the systems within its scope.

Formal definition

FIPS 200, Minimum Security Requirements for Federal Information and Information Systems (March 2006), is a Federal Information Processing Standard issued by NIST that specifies minimum security requirements for federal information and information systems across seventeen security-related areas. It establishes a risk-based process for selecting the security controls necessary to satisfy those minimum requirements, and in most implementations agencies apply it together with the companion control catalog to determine appropriate safeguards. As of the applicable revision, practitioners should confirm scope against current authoritative text: FIPS 200 governs federal information and information systems (generally federal civilian systems under FISMA) and does not by itself address the tailoring, contractual, or agency-specific implementation details that a reader must verify against the current official publication. National security systems and CUI-specific or DoD-specific obligations may be governed by separate authorities.

Why it matters

FIPS 200 matters because it establishes a mandatory security baseline, not optional advice. As a Federal Information Processing Standard issued by NIST and approved in March 2006, it obligates federal agencies within its scope to address minimum security requirements across seventeen security-related areas rather than leaving those decisions entirely to individual discretion. This gives compliance officers, ISSMs, and authorizing officials a common floor against which systems can be measured, which is foundational to the risk management activities that follow.

Because FIPS 200 points to a risk-based process for selecting security controls, it is typically applied alongside the companion control catalog to determine which specific safeguards satisfy the minimum requirements. Practitioners should understand that meeting FIPS 200 is about establishing and documenting an appropriate control baseline, not a one-time checkbox: compliance with a minimum standard is not the same as being secure, and the standard itself does not resolve the tailoring and implementation choices an agency must make and justify.

Scope discipline is essential when relying on FIPS 200. It generally governs federal information and information systems, most commonly federal civilian systems under FISMA. National security systems, CUI-specific obligations, and DoD-specific requirements may be governed by separate authorities, so treating FIPS 200 as automatically satisfying those distinct regimes would be a mistake. Readers should confirm scope, applicability, and current requirements against the official publication and any governing agency guidance.

Who it's relevant to

Compliance Officers and ISSMs
Those responsible for meeting federal security requirements use FIPS 200 as the mandatory minimum baseline for systems within its scope, addressing the seventeen security-related areas and documenting the risk-based selection of controls. They should treat it as a floor to build on rather than evidence that a system is fully secure.
Authorizing Officials
AOs rely on FIPS 200 as part of the basis for determining whether a system meets minimum security requirements before making authorization decisions. They should confirm that the applied controls satisfy the standard and remember that authorization is distinct from, and broader than, meeting a minimum baseline.
Government Contractors and Auditors
Contractors supporting federal information systems and auditors assessing them use FIPS 200 to understand the required minimum security areas and the risk-based control selection process. They should verify applicability to the specific system type and confirm whether separate authorities govern national security systems, CUI, or DoD-specific obligations, since FIPS 200 alone does not address those.

Inside FIPS 200

Minimum Security Requirements
FIPS 200, issued by NIST, establishes minimum security requirements for federal information and information systems across a set of security-related areas, generally spanning management, operational, and technical topics.
Security Requirement Areas
The standard organizes its minimum requirements into families of related areas (such as access control, awareness and training, audit and accountability, and incident response) that align conceptually with the control families later detailed in NIST SP 800-53.
Mandatory Federal Standard
As a Federal Information Processing Standard, FIPS 200 is mandatory for federal agencies operating information systems under FISMA, subject to any applicable statutory and agency-specific provisions. Its binding scope centers on federal civilian and other in-scope federal systems rather than national security systems, which may follow separate authorities.
Relationship to Risk Categorization
FIPS 200 works in conjunction with FIPS 199, which addresses security categorization of information and systems by impact level. FIPS 200 directs agencies to select an appropriate baseline of security controls to meet the minimum requirements based on that categorization.
Link to NIST SP 800-53
FIPS 200 requires agencies to meet its minimum requirements by applying controls; NIST SP 800-53, maintained by NIST, provides the detailed catalog and baselines used to satisfy those requirements. The applicable content depends on the current revision, which the reader should verify against official sources.

Common questions

Answers to the questions practitioners most commonly ask about FIPS 200.

Does meeting FIPS 200 mean my system satisfies all federal security requirements?
No. FIPS 200 establishes minimum security requirements for federal information and information systems, but compliance with it is not the same as achieving security or satisfying every applicable obligation. FIPS 200 works in conjunction with the control catalog in NIST SP 800-53, which agencies use to select and implement controls, and it is one input into the broader Risk Management Framework process rather than a standalone assurance of a secure or fully authorized system. Readers should confirm the full set of requirements applicable to their system category and mission against current authoritative sources.
Is FIPS 200 the document that lists the specific security controls I need to implement?
Not exactly. FIPS 200 specifies minimum security requirements across security-related areas but does not itself provide the detailed catalog of individual controls. The specific controls are found in NIST SP 800-53, which agencies use to meet the minimum requirements FIPS 200 establishes. Treating FIPS 200 as the control catalog conflates the two publications; FIPS 200 generally sets the mandatory requirement and directs the use of NIST SP 800-53 for control selection. Verify the current revision of each publication for applicable details.
Which systems fall under the scope of FIPS 200?
FIPS 200 generally applies to federal information and information systems, with the notable exclusion of national security systems as defined in applicable law and policy. Federal civilian agency systems typically fall within its scope, while classified and national security systems are subject to separate authorities. DoD systems, CUI handling, and state, local, tribal, and territorial obligations may follow distinct or additional frameworks. Readers should confirm scope applicability for their specific system category against current official sources.
How does FIPS 200 relate to FIPS 199 in practice?
In most implementations, FIPS 199 is applied first to categorize an information system based on the potential impact (low, moderate, or high) to confidentiality, integrity, and availability. That categorization then informs how the minimum security requirements in FIPS 200 are met, generally through selection of an appropriately scoped baseline of controls from NIST SP 800-53. The two standards are typically used in sequence during the categorization and control selection steps. Consult the current text of each standard to confirm how they apply to your system.
Where does FIPS 200 fit within the Risk Management Framework?
FIPS 200 generally supports the categorization and control selection activities within the Risk Management Framework by establishing minimum security requirements that inform the selection of controls from NIST SP 800-53. It is one component of a broader process that also includes implementation, assessment, authorization, and continuous monitoring. Because the RMF is described in separate NIST guidance and may be tailored by individual agencies, readers should verify how their organization integrates FIPS 200 into its RMF process.
Can an agency tailor how it meets the minimum requirements in FIPS 200?
FIPS 200 establishes minimum requirements that must be met, but the manner of meeting them generally allows for tailoring through the control selection and tailoring guidance associated with NIST SP 800-53. Agencies may adjust baselines based on the system categorization and mission needs, subject to applicable policy. Tailoring does not waive the minimum requirements themselves. Readers should confirm the permissible scope of tailoring and any agency-specific interpretations against the current authoritative publications.

Common misconceptions

FIPS 200 is a detailed control catalog that tells you exactly which controls to implement.
FIPS 200 states minimum security requirements at a high level. The detailed controls and baselines used to meet those requirements are found in NIST SP 800-53, not in FIPS 200 itself. The two documents are complementary and should not be treated as interchangeable.
FIPS 200 applies uniformly to all systems, including DoD, classified, and state or local systems.
FIPS 200 is a federal standard tied primarily to FISMA-governed federal systems. National security systems, classified systems under separate authorities, and state, local, tribal, and territorial systems may follow different requirements. Practitioners should confirm which authority governs their specific system.
Meeting the FIPS 200 minimum requirements means a system is secure or fully compliant.
Satisfying minimum requirements is a baseline, not a guarantee of security, and compliance is not equivalent to security. Requirements are generally satisfied through tailored control selection, ongoing assessment, and continuous monitoring rather than a one-time exercise.

Best practices

Use FIPS 200 together with FIPS 199 by first categorizing the system by impact level, then applying the minimum security requirements to that categorization.
Rely on the current revision of NIST SP 800-53 for the detailed controls and baselines needed to satisfy FIPS 200 requirements, and verify you are working from the applicable revision.
Confirm which governing authority applies to your system before assuming FIPS 200 controls, since defense, national security, and non-federal systems may follow different requirements.
Treat the minimum requirements as a starting baseline and apply appropriate tailoring rather than assuming the baseline alone fully addresses your system's risk.
Document how each minimum requirement area is met and revisit that mapping as revisions to the underlying standards and control catalog are released.
Distinguish between meeting minimum compliance requirements and achieving effective security, and support both through ongoing assessment and continuous monitoring.