verified_user
Standardful
Homechevron_rightStandardschevron_rightNIST SP 800-161 Rev. 1
Final (Guidance; Update 1)International Standardupdate Standard Updated: November 2024fact_check Fact checked: Oct 6, 2026

NIST SP 800-161 Rev. 1

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

apartmentPublishing Organization:National Institute of Standards and Technology (NIST)

Standard Introduction

NIST SP 800-161 Rev. 1 Update 1 is the current NIST guidance for managing cybersecurity risk throughout supply chains. It helps organizations address risks in software, hardware, systems, components, and services by connecting enterprise risk management, mission needs, acquisition, engineering, cybersecurity, operations, and supplier relationships.

The publication organizes C-SCRM across enterprise, mission and business-process, and operational levels. It provides practices for strategy, policy, C-SCRM plans, supplier and product assessments, acquisition requirements, tailored NIST SP 800-53 controls, monitoring, metrics, and response. It is not a certification standard and is voluntary for nonfederal organizations unless another authority or agreement makes particular practices applicable.

account_tree

Enterprise-Wide Program

Organizes C-SCRM across enterprise, mission and business-process, and operational levels instead of treating supplier risk as an isolated security review.

shopping_cart

Acquisition Integration

Connects cybersecurity risk decisions to requirements, market research, source selection, agreements, delivery, operations, and supplier monitoring throughout the acquisition lifecycle.

fact_check

Controls and Templates

Provides tailored control guidance, risk scenarios, a scoping questionnaire, and templates for strategy, policy, implementation plans, C-SCRM plans, and assessments.

list_alt Core C-SCRM Practices

  • Executive governance and risk appetite
  • Enterprise, mission/business-process, and operational risk levels
  • C-SCRM strategy and implementation plan
  • Policies and system- or acquisition-specific C-SCRM plans
  • Supplier, product, and service risk assessments
  • Cybersecurity requirements in acquisition and agreements
  • Tailored NIST SP 800-53 controls and evidence
  • Monitoring, metrics, incident learning, and continuous improvement

Who Needs to Comply?

groups

U.S. federal agencies, government contractors, acquisition and procurement teams, cybersecurity and enterprise-risk leaders, system owners, engineers, and organizations worldwide that depend on software, hardware, cloud, managed services, operational technology, or other third-party products and services. Nonfederal use is voluntary unless another law, contract, or procurement requirement makes particular practices applicable.

Key Requirements

1

Establish Governance and Strategy

Define accountable leadership, risk appetite, roles, resources, a C-SCRM strategy, an implementation plan, and policy aligned with enterprise risk management and mission priorities.

2

Coordinate Three Risk Levels

Connect enterprise priorities, mission and business-process needs, and operational system decisions so supplier and product risks are escalated, accepted, transferred, avoided, or mitigated by the right authority.

3

Assess Suppliers, Products, and Services

Scope criticality, threats, vulnerabilities, dependencies, provenance, ownership, location, development and support practices, and potential impact before selection and throughout use.

4

Integrate C-SCRM into Acquisition

Translate risk decisions into solicitation criteria, evaluation methods, contract language, flow-down obligations, delivery evidence, change notification, incident reporting, and exit or transition provisions.

5

Select Controls and Evidence

Tailor relevant NIST SP 800-53 controls, including the Supply Chain Risk Management family, and define proportionate evidence for suppliers, products, services, systems, and acquisition contexts.

6

Monitor and Improve

Track supplier and product changes, vulnerabilities, incidents, performance, exceptions, and residual risk; use metrics, reassessments, exercises, and lessons learned to update decisions and program practices.

Implementation Roadmap

1
Phase 1schedule Duration: 2–6 weeks

Set governance, scope, and risk criteria

Name an accountable executive and cross-functional C-SCRM program office or equivalent. Define enterprise, mission and business-process, and operational responsibilities; document risk appetite; identify applicable authorities and contracts; and approve a strategy, implementation plan, and policy.

2
Phase 2schedule Duration: 4–10 weeks

Map dependencies and assess criticality

Inventory critical systems, products, services, suppliers, sub-tier dependencies, data flows, and concentration risks. Use the Table 26 scoping questionnaire or an equivalent method to decide which acquisitions and suppliers need deeper assessment and stronger evidence.

3
Phase 3schedule Duration: 6–16 weeks

Embed controls in acquisition and operations

Translate risk decisions into market research, solicitation criteria, source selection, agreements, flow-down clauses, acceptance evidence, configuration and change controls, vulnerability and incident reporting, access restrictions, and transition or exit provisions.

4
Phase 4schedule Duration: Ongoing

Monitor evidence, events, and performance

Track supplier ownership and location changes, product updates, vulnerabilities, incidents, exceptions, control performance, and residual risk. Reassess critical relationships, test response and contingency plans, report metrics to decision-makers, and update requirements from lessons learned.

Compliance Checklist

0 / 12

checklist Governance and program design

checklist Assessment and acquisition

checklist Monitoring and evidence

NIST SP 800-161 and Related References

Use these references together according to the decision, control, or evidence layer you need.

ReferencePrimary purposeDocument typePractical role
NIST SP 800-161 Rev. 1 Update 1Manage cybersecurity risk across supply chainsFederal guidance; voluntary for nonfederal use unless separately requiredC-SCRM governance, acquisition, assessment, controls, and monitoring
NIST IR 8536Connect manufacturing pedigree and provenance recordsVoluntary technical guidanceTraceability events, links, selective disclosure, and ecosystem design
NIST CSF 2.0Manage organization-wide cybersecurity outcomesVoluntary cybersecurity frameworkExecutive outcomes and profiles, including supply-chain governance
NIST SP 800-53 Rev. 5Provide security and privacy controlsControl catalogControl selection and tailoring, including the SR control family
ISO 28000:2022Manage security risks in supply chainsCertifiable management-system requirementsOrganization-level supply-chain security management system

Common Misconceptions

cancel
Myth

NIST SP 800-161 is only for federal procurement teams.

check_circle
Reality

The guidance addresses executives, enterprise risk, mission owners, acquisition, cybersecurity, engineering, operations, and suppliers; nonfederal organizations may also adopt it voluntarily.

cancel
Myth

Sending every supplier the same security questionnaire is a complete C-SCRM program.

check_circle
Reality

A defensible program uses risk-based scoping, multiple evidence sources, acquisition controls, product and service analysis, ongoing monitoring, response planning, and accountable risk decisions.

cancel
Myth

Implementing the publication produces a NIST certification.

check_circle
Reality

NIST does not certify organizations against SP 800-161. Organizations may assess implementation internally or independently, but any contractual or regulatory assurance has a separate basis.

cancel
Myth

A supplier that passed onboarding does not need further review.

check_circle
Reality

Ownership, locations, sub-tier dependencies, products, vulnerabilities, threats, and services change. Critical relationships require event-driven and periodic reassessment throughout their lifecycle.

Penalties & Enforcement

warning

NIST SP 800-161 Rev. 1 is guidance, not a certification scheme, and it does not itself create fines or a universal compliance mandate. Federal statutes, OMB policy, acquisition rules, contract clauses, sector regulation, and customer requirements may independently require C-SCRM outcomes or evidence; consequences must be evaluated under those separate authorities.

Frequently Asked Questions

What is the current version of NIST SP 800-161?

expand_more

The current publication is NIST SP 800-161 Rev. 1 Update 1, published as an update on 1 November 2024. It retains the May 2022 revision and incorporates changes recorded in Appendix K. The NIST publication page is the authoritative place to check for later errata or updates.

Who should use NIST SP 800-161 Rev. 1?

expand_more

It was written for federal organizations and their supply-chain stakeholders, but NIST permits voluntary use by other organizations. It is useful to executives, enterprise-risk teams, acquisition and procurement staff, cybersecurity teams, system owners, engineers, legal teams, and suppliers that manage risk from software, hardware, cloud, operational technology, and services.

Is NIST SP 800-161 mandatory or certifiable?

expand_more

The publication is guidance and has no certification program. It does not itself impose a universal mandate. A federal policy, acquisition regulation, contract clause, sector rule, or customer agreement may separately require particular C-SCRM practices or evidence, so organizations must map the guidance to their own authorities.

How does SP 800-161 differ from NIST IR 8536?

expand_more

SP 800-161 provides the organization-wide program, risk-management, acquisition, control, and assessment practices for cybersecurity supply-chain risk. NIST IR 8536 focuses more narrowly on interoperable manufacturing traceability records, provenance links, and selective disclosure. Traceability evidence can support a broader SP 800-161 program, but it does not replace it.

How does SP 800-161 relate to NIST CSF 2.0 and SP 800-53?

expand_more

NIST CSF 2.0 expresses high-level cybersecurity outcomes, including supply-chain outcomes in Govern. SP 800-53 supplies a catalog of security and privacy controls, including the Supply Chain Risk Management family. SP 800-161 explains how to organize, tailor, and apply those outcomes and controls across C-SCRM governance, acquisition, systems, suppliers, products, and services.

What are the three organizational levels in the guidance?

expand_more

Level 1 is the enterprise level, where leadership sets strategy, risk appetite, policy, and resources. Level 2 is the mission and business-process level, where teams translate enterprise priorities into capability and portfolio decisions. Level 3 is the operational level, where system, product, service, and supplier risks are assessed and controlled. Information and decisions must flow in both directions.

What evidence should an auditor or buyer expect?

expand_more

Useful evidence includes an approved strategy, implementation plan and policy; scoped risk assessments; criticality criteria; acquisition requirements and contract clauses; supplier and product assessments; tailored controls; decision and exception records; incident and change notifications; remediation tracking; metrics; reassessment results; and management review. Evidence should be proportionate to risk rather than identical for every supplier.

Official Documentation

View All

Implementation Timeline

new_releases
April 2015
The first edition of NIST SP 800-161 is published
update
5 May 2022
Revision 1 expands enterprise-wide C-SCRM guidance and supersedes the 2015 edition
fact_check
1 November 2024
Update 1 becomes the current publication and records its changes in Appendix K
assignment
2 December 2025
NIST releases a fillable version of the Table 26 C-SCRM assessment scoping questionnaire

Related Categories