NIST 800-53 REV 5 • ASSESSMENT, AUTHORIZATION, AND MONITORING

CA-4Security Certification

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

This control has been withdrawn and incorporated into CA-2 (Control Assessments). Security certification activities are now handled as part of the broader assessment process.

Example 1: Instead of a separate certification step, include certification-level rigor in your CA-2 assessment plan by using NIST SP 800-53A assessment procedures.

Example 2: Use your organization's eMASS or GRC platform to track the assessment and authorization workflow in one unified process rather than treating certification separately.