Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant controls (AC, IA, AU/SI)
NIST SP 800-53 Rev 5 (Release 5.2.0) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 21 IAM-relevant controls
NIST SP 800-53 Rev 5 is current; the latest patch is Release 5.2.0 (August 2025), which addressed secure software-update controls (no IAM impact). Release 5.1.1 added IA-13 (identity providers and authorization servers), included here. Rev 4 was withdrawn in 2021; no Rev 6 timeline is set.
The IAM-relevant control families — Access Control (AC), Identification and Authentication (IA), and the access-related Audit (AU) and System Monitoring (SI-4) controls. This is NOT a full 800-53 mapping: the other families and most enhancements are out of scope here. Baselines (Low/Moderate/High) and control selection live in NIST SP 800-53B and your RMF process.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
NIST SP 800-53 has no certification; controls are implemented and assessed under the Risk Management Framework (SP 800-37), with assessment procedures in SP 800-53A and authorization by your authorizing official. SimpliKeys can support specific controls when appropriately configured, but it cannot make a system '800-53 compliant.' The IAM detail is largely in the control enhancements — check those individually. Treat every 'Supports' as 'capability provided when appropriately configured.'
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Establish, activate, modify, review, disable and remove system accounts across their lifecycle.
What SimpliKeys does
Governs the full account lifecycle for every identity from one platform — creating, modifying, reviewing, disabling (including auto-disable on inactivity) and removing accounts.
Customer responsibility & notes
Customer connects the identity sources and sets lifecycle rules; SimpliKeys provisions, de-provisions and reviews accounts. Specific enhancements (e.g., automated audit actions) are configured by the customer.
Enforce approved authorizations for access to the system and its resources.
What SimpliKeys does
Is the access-enforcement point: authenticates each request and enforces approved authorizations by policy across the environment.
Customer responsibility & notes
Customer places SimpliKeys in the access path for all in-scope resources, including legacy systems.
Separate individual duties to reduce the risk of malevolent activity without collusion.
What SimpliKeys does
Enforces access by policy, so it can block a role from accessing an application where that access would itself breach a separation-of-duties rule.
Customer responsibility & notes
SimpliKeys enforces SoD at the access-to-application layer. SoD within an application (conflicting transactions or actions) is the application's function unless SimpliKeys is fed application-level data and configured for it.
Allow only the access necessary for users and processes to accomplish assigned tasks.
What SimpliKeys does
Enforces least-privilege access by role and policy for every identity, with privileged access brokered and recorded like any other.
Customer responsibility & notes
Customer designs the least-privilege model; SimpliKeys enforces it, including any elevation / just-in-time workflow the customer configures.
Limit consecutive invalid logon attempts and act (e.g., lock) when the limit is exceeded.
What SimpliKeys does
Limits invalid authentication attempts and locks accounts by policy.
Customer responsibility & notes
Customer sets the attempt threshold and lockout duration to its baseline.
Initiate a session/device lock after a period of inactivity, retained until the user re-authenticates.
What SimpliKeys does
Locks the sessions it manages after a configurable idle period and requires re-authentication to resume.
Customer responsibility & notes
SimpliKeys locks the sessions it manages; OS/endpoint screen-lock is a separate endpoint control the customer owns.
Automatically terminate a user session after defined conditions or trigger events.
What SimpliKeys does
Terminates sessions automatically on the conditions configured, and shuts down a compromised session immediately.
Customer responsibility & notes
Customer configures the termination triggers (inactivity, risk events).
Authorize, monitor and control remote access to the system.
What SimpliKeys does
Authenticates, brokers, monitors and records remote access under one policy.
Customer responsibility & notes
Customer integrates SimpliKeys with the remote-access path (VPN/ZTNA) so all remote sessions are brokered and monitored.
Uniquely identify and authenticate organizational users and associate identities with processes.
What SimpliKeys does
Uniquely identifies and authenticates organizational users with strong authentication from a configurable spectrum of factors, including phishing-resistant FIDO2/passkeys.
Customer responsibility & notes
Customer selects the factor types; MFA enhancements (privileged / non-privileged) are configured to the applicable baseline.
Uniquely identify and authenticate devices before establishing a connection.
What SimpliKeys does
Identifies and authenticates devices as first-class identities, managing their credentials and authenticating the device before access is granted.
Customer responsibility & notes
Customer enrolls in-scope devices and issues their credentials; SimpliKeys authenticates them alongside human and other non-human identities.
Assign identifiers, prevent reuse, and disable identifiers as needed.
What SimpliKeys does
Issues unique identifiers across the identity lifecycle, prevents reuse, and disables identifiers when no longer needed.
Customer responsibility & notes
Customer defines identifier policy and how shared/generic identifiers are handled.
Manage authenticators (passwords, tokens, certificates, keys): issuance, content, protection and rotation.
What SimpliKeys does
Issues, protects and rotates authenticators, holding credentials and secrets in a vault with strong cryptography.
Customer responsibility & notes
Customer sets password content rules and certificate/key handling to its baseline.
Uniquely identify and authenticate non-organizational users or processes acting on their behalf.
What SimpliKeys does
Uniquely identifies and authenticates external and federated users (SAML/OIDC) and the processes acting for them.
Customer responsibility & notes
Customer configures the federation trusts and the assurance level required for external identities.
Require users to re-authenticate when defined circumstances or conditions occur.
What SimpliKeys does
Steps up and re-authenticates within a session when risk rises or a more sensitive activity begins, pulling an additional factor such as FIDO2 or biometric at that moment.
Customer responsibility & notes
Customer defines the re-authentication triggers (privilege/role change, timeout, sensitive action).
Proof the identity of users before issuing credentials, to a defined assurance level.
What SimpliKeys does
Binds credentials to proofed identities and applies context, ingesting proofing results via API.
Customer responsibility & notes
SimpliKeys binds credentials to proofed identities and applies context. The proofing / identity verification itself is performed by an integrated identity-verification service or the authoritative source (e.g., HR), whose result SimpliKeys ingests via API.
Issue, convey and verify identity assertions and access tokens, and manage their lifecycle (added in Release 5.1.1).
What SimpliKeys does
Acts as the identity provider and authorization server: issues, conveys and verifies identity assertions and access tokens, and manages their lifecycle.
Customer responsibility & notes
Customer configures the assertion/token signing, verification and trust to its standard.
Identify the event types the system logs, and log them.
What SimpliKeys does
Records identity and access events — every action on the network by any identity — with session, device, location and keystroke detail, and forwards them to SIEM.
Customer responsibility & notes
Customer confirms the identity/access event types it needs are captured; broader system events may use other sources.
Ensure audit records contain the required content (what, when, where, source, outcome, identity).
What SimpliKeys does
Records rich identity/access events with user, device, location, timestamp and outcome.
Customer responsibility & notes
Customer confirms SimpliKeys records include every required content element before relying on them as audit evidence.
Review and analyze audit records for inappropriate or unusual activity and report findings.
What SimpliKeys does
Analyzes identity/access records with behavioural analytics and surfaces unusual activity in real time.
Customer responsibility & notes
SimpliKeys performs the automated analysis and detection; the formal review process, frequency and reporting responsibilities are organisational and remain the customer's.
Provide audit-record generation for the defined event types on system components.
What SimpliKeys does
Generates audit records for identity and access events across the components it fronts.
Customer responsibility & notes
Customer confirms coverage across in-scope components; some components may log independently of SimpliKeys.
Monitor the system to detect attacks, indicators of potential attacks, and unauthorized activity.
What SimpliKeys does
Monitors all actions taken by any identity on the network — person, non-human identity or AI agent — with behavioural analytics, and responds immediately to a compromised session.
Customer responsibility & notes
Strong fit for identity-centric monitoring; broader network, host and application monitoring uses additional tooling.
Mapping reflects NIST SP 800-53 Rev 5 (Release 5.2.0) base controls as understood in mid-2026, reviewed control-by-control with SimpliKeys. Control text is paraphrased; official text is public-domain at csrc.nist.gov. 'Supports' = capability provided when appropriately configured; the customer configures and operates its deployment, selects enhancements via its 800-53B baseline, and assesses controls under the RMF. Much IAM detail is in the control enhancements — check those individually.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo