NIST SP 800-122
What is NIST SP 800-122?
Guide to Protecting the Confidentiality of Personally Identifiable Information (PII). It comprises 8 controls organised across 8 domains, published by NIST, and applies in the United States.
How NIST SP 800-122 maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains NIST SP 800-122 groups its controls into
Frameworks that share controls with NIST SP 800-122
Each of these has at least one control mapped to a control in NIST SP 800-122. The number is how many NIST SP 800-122 controls are shared, counted from the mapping graph.
Turkey KVKK
6 shared controlsPrivacy Act 1988 (Australia)
6 shared controlsPakistan Personal Data Protection Bill 2023
6 shared controlsBahrain PDPL
6 shared controlsNew Jersey Data Privacy Act
6 shared controlsBarbados Data Protection Act 2019
6 shared controlsGDPR
6 shared controlsSouth Korea PIPA
6 shared controlsWhere NIST SP 800-122 overlaps with the standards you already hold
What NIST SP 800-122 means in your sector
What NIST SP 800-122 means for your job
Questions people ask about NIST SP 800-122
What is NIST SP 800-122?
How many controls does NIST SP 800-122 have?
Where does NIST SP 800-122 apply?
What frameworks does NIST SP 800-122 map to?
How do I get started with NIST SP 800-122 compliance?
Query NIST SP 800-122 programmatically
NIST SP 800-122, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST SP 800-122 API reference and MCP config →How ready are you for NIST SP 800-122?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.