Markdown corpus
The full NIST SP 800-53 Rev 5 catalog and its CSF 2.0 crosswalk, published as plain Markdown documents for language models and agents to fetch directly. Every document is a static file in this site's export: no authentication, no query string, no runtime server, and stable paths you can hard-code.
One document per control, carrying its title, family, baselines, description, discussion, implementation guidance, CSF 2.0 subcategories, and related controls. The {stem} segment is the control id with enhancement parentheses flattened to a hyphen, so AC-2 is published at /md/controls/AC-2.md and AC-2(1) at /md/controls/AC-2-1.md.
One document per control family, listing every member control with a link to its own document. The {code} segment is the family code exactly as the catalog spells it, for example /md/families/AC.md.
One document per CSF 2.0 function, listing the subcategories that belong to it. The {functionId} segment is the function id, for example /md/csf/GV.md.
One document per CSF 2.0 subcategory, naming its parent function and every 800-53 control crosswalked to it. The {subcategoryId} segment is the dotted subcategory id, for example /md/csf/GV.OC-01.md.
Every control, family, CSF function, and CSF subcategory document concatenated into one file, preceded by a table of contents that links to each embedded document by anchor. Fetch this when you want the whole corpus in a single request.
A curated map in the llmstxt.org shape — one title, a short summary, and link sections pointing at the index, the full corpus, and every family and CSF function, with no per-control or per-subcategory entries. Fetch this first, in preference to the other Discovery Map documents, when you want to see the shape of the corpus in one small request before deciding what to read.
The complete corpus content inline — byte-for-byte the same document as /md/full.md, published at the conventional llms-full.txt location. Fetch this instead of llms.txt or the index when you want every control in one response and your client looks for the conventional filename rather than a corpus path.
An exhaustive link table of every published Corpus document, grouped by document type and ordered within each group, including the per-control and per-subcategory documents that llms.txt deliberately leaves out. Fetch this instead of llms.txt when you need to enumerate the corpus exactly rather than skim it, and instead of llms-full.txt when you want addresses rather than content.
The same URL set as XML: one absolute <loc> per Corpus document plus the three text entry points above, with no timestamps. Fetch this instead of the Markdown entry points when you are a crawler consuming the sitemaps.org format rather than a reader.
The crawl policy: a single user-agent group that allows /md/, /llms.txt, and /llms-full.txt, and a Sitemap line pointing at sitemap.xml. Fetch this first, before any of the other four, to confirm the corpus is open to automated retrieval and to discover the sitemap.
Two independent ways to read the same catalog. The Markdown corpus is served from https://nistcontrols.com/md/ and returns text/markdown; the live v1 API is served from https://api.nistcontrols.com/v1 and returns application/json. See the API reference for the endpoint list and response shapes.
Static pre-rendered documents. No authentication, no query string, and no runtime server — every document is a file in the static export.
A read-only, GET-only JSON API where filters are path segments. Prefer it when you want structured fields to parse rather than prose to read.
Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.