NIST SP 800-53 Rev 5
IA - Identification and Authentication

NIST SP 800-53 Rev 5 NIST800-IA-7: IA-7 Cryptographic Module Authentication

Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 227 controls across 100 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 4 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • IA-7 Cryptographic Module Authentication
  • SA-4(10) Use of Approved PIV Products
  • SC-28(1) Cryptographic Protection

FedRAMP Moderate · 4 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • IA-7 Cryptographic Module Authentication
  • SA-4(10) Use of Approved PIV Products
  • SC-28(1) Cryptographic Protection

ISO/IEC 23837:2023 · 4 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-13 Authentication and password management
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • 29115-7.4 Level of Assurance 4 (LoA4)

ISO/SAE 21434 · 4 controls

  • ISO21434-13 Authentication and password management
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-19 Certificate management
  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO 27799:2025 · 3 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-16 Transmission security and encryption
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • QRCM-1.2 Quantum-Vulnerable Identification
  • QRCM-3.1 Hybrid Solution Deployment (2025-2030)
  • QRCM-4.2 TLS 1.3 Adoption

PCI DSS 4.0 · 3 controls

  • 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood
  • 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication
  • 3.7.7 3.7.7 Prevent unauthorized substitution of keys

BSI IT-Grundschutz · 2 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-08 Cryptographic protection of data

CMMC 2.0 · 2 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO 27701:2019 · 2 controls

  • 6.7 Cryptography
  • 6.7.1 Cryptographic controls

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.1 Secure Device Design
  • 27400-6.2 Device Identity and Authentication
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

NIST SP 800-190 · 2 controls

  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 2 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts

PTES · 2 controls

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • PTESPHASE-3 Threat Modeling
  • SHAREASSESS-2 Access Control, Identity, Authentication
  • SHAREASSESS-3 Network Security, Endpoint, Data Protection

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SIGSTORE-3 Sigstore for Containers and Artifacts (Cosign)

South Korea ISMS-P · 2 controls

  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-SYS-02 Encryption Implementation
  • US-ITAR-EAR-DS-01 Technical Data Protection
  • US-ITAR-EAR-DS-02 Cloud and Storage
  • VP-2 Holder Binding
  • W3CVCDM-4 Accessibility, Internationalization, Security
  • AMLCTF-35 Identity Verification Standard

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASBv3-DP-8 Ensure security of key and certificate repository

Bahrain PDPL · 1 control

C5 (Germany) · 1 control

  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • DSO-3 Data Access Management
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO 27001:2022 · 1 control

  • 8.24 Use of cryptography

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • IA-7 IA-7 Cryptographic Module Authentication
  • IA-7 IA-7 Cryptographic Module Authentication
  • IA-7 IA-7 Cryptographic Module Authentication

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGOB-3 API Security Standards, mTLS, and Encryption

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

  • PCI-P2PE-09 Encryption and key management

PCI PIN Security · 1 control

  • PCI-PIN-09 Encryption and key management

PCI SSF · 1 control

  • PCI-SSF-09 Encryption and key management

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • SOC-CY-C2 Encryption and Data Protection
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization

Saudi Arabia PDPL · 1 control

  • SA-PDPL-13 Encryption of personal data
  • IM8-CLD.2 Cloud Security Controls
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-2 Consumer Rights
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IA - Identification and Authentication

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-IA-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 227 it maps to, and the evidence behind each claim, over MCP and REST.