NIST 800-53 REV 5 • ASSESSMENT, AUTHORIZATION, AND MONITORING
CA-4 — Security Certification
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
This control has been withdrawn and incorporated into CA-2 (Control Assessments). Security certification activities are now handled as part of the broader assessment process.
Example 1: Instead of a separate certification step, include certification-level rigor in your CA-2 assessment plan by using NIST SP 800-53A assessment procedures.
Example 2: Use your organization's eMASS or GRC platform to track the assessment and authorization workflow in one unified process rather than treating certification separately.