NIST SP 800-161 Rev. 1
Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
Standard Introduction
NIST SP 800-161 Rev. 1 Update 1 is the current NIST guidance for managing cybersecurity risk throughout supply chains. It helps organizations address risks in software, hardware, systems, components, and services by connecting enterprise risk management, mission needs, acquisition, engineering, cybersecurity, operations, and supplier relationships.
The publication organizes C-SCRM across enterprise, mission and business-process, and operational levels. It provides practices for strategy, policy, C-SCRM plans, supplier and product assessments, acquisition requirements, tailored NIST SP 800-53 controls, monitoring, metrics, and response. It is not a certification standard and is voluntary for nonfederal organizations unless another authority or agreement makes particular practices applicable.
Enterprise-Wide Program
Organizes C-SCRM across enterprise, mission and business-process, and operational levels instead of treating supplier risk as an isolated security review.
Acquisition Integration
Connects cybersecurity risk decisions to requirements, market research, source selection, agreements, delivery, operations, and supplier monitoring throughout the acquisition lifecycle.
Controls and Templates
Provides tailored control guidance, risk scenarios, a scoping questionnaire, and templates for strategy, policy, implementation plans, C-SCRM plans, and assessments.
list_alt Core C-SCRM Practices
- Executive governance and risk appetite
- Enterprise, mission/business-process, and operational risk levels
- C-SCRM strategy and implementation plan
- Policies and system- or acquisition-specific C-SCRM plans
- Supplier, product, and service risk assessments
- Cybersecurity requirements in acquisition and agreements
- Tailored NIST SP 800-53 controls and evidence
- Monitoring, metrics, incident learning, and continuous improvement
Who Needs to Comply?
U.S. federal agencies, government contractors, acquisition and procurement teams, cybersecurity and enterprise-risk leaders, system owners, engineers, and organizations worldwide that depend on software, hardware, cloud, managed services, operational technology, or other third-party products and services. Nonfederal use is voluntary unless another law, contract, or procurement requirement makes particular practices applicable.
Key Requirements
Establish Governance and Strategy
Define accountable leadership, risk appetite, roles, resources, a C-SCRM strategy, an implementation plan, and policy aligned with enterprise risk management and mission priorities.
Coordinate Three Risk Levels
Connect enterprise priorities, mission and business-process needs, and operational system decisions so supplier and product risks are escalated, accepted, transferred, avoided, or mitigated by the right authority.
Assess Suppliers, Products, and Services
Scope criticality, threats, vulnerabilities, dependencies, provenance, ownership, location, development and support practices, and potential impact before selection and throughout use.
Integrate C-SCRM into Acquisition
Translate risk decisions into solicitation criteria, evaluation methods, contract language, flow-down obligations, delivery evidence, change notification, incident reporting, and exit or transition provisions.
Select Controls and Evidence
Tailor relevant NIST SP 800-53 controls, including the Supply Chain Risk Management family, and define proportionate evidence for suppliers, products, services, systems, and acquisition contexts.
Monitor and Improve
Track supplier and product changes, vulnerabilities, incidents, performance, exceptions, and residual risk; use metrics, reassessments, exercises, and lessons learned to update decisions and program practices.
Implementation Roadmap
Set governance, scope, and risk criteria
Name an accountable executive and cross-functional C-SCRM program office or equivalent. Define enterprise, mission and business-process, and operational responsibilities; document risk appetite; identify applicable authorities and contracts; and approve a strategy, implementation plan, and policy.
Map dependencies and assess criticality
Inventory critical systems, products, services, suppliers, sub-tier dependencies, data flows, and concentration risks. Use the Table 26 scoping questionnaire or an equivalent method to decide which acquisitions and suppliers need deeper assessment and stronger evidence.
Embed controls in acquisition and operations
Translate risk decisions into market research, solicitation criteria, source selection, agreements, flow-down clauses, acceptance evidence, configuration and change controls, vulnerability and incident reporting, access restrictions, and transition or exit provisions.
Monitor evidence, events, and performance
Track supplier ownership and location changes, product updates, vulnerabilities, incidents, exceptions, control performance, and residual risk. Reassess critical relationships, test response and contingency plans, report metrics to decision-makers, and update requirements from lessons learned.
Compliance Checklist
checklist Governance and program design
checklist Assessment and acquisition
checklist Monitoring and evidence
NIST SP 800-161 and Related References
Use these references together according to the decision, control, or evidence layer you need.
| Reference | Primary purpose | Document type | Practical role |
|---|---|---|---|
| NIST SP 800-161 Rev. 1 Update 1 | Manage cybersecurity risk across supply chains | Federal guidance; voluntary for nonfederal use unless separately required | C-SCRM governance, acquisition, assessment, controls, and monitoring |
| NIST IR 8536 | Connect manufacturing pedigree and provenance records | Voluntary technical guidance | Traceability events, links, selective disclosure, and ecosystem design |
| NIST CSF 2.0 | Manage organization-wide cybersecurity outcomes | Voluntary cybersecurity framework | Executive outcomes and profiles, including supply-chain governance |
| NIST SP 800-53 Rev. 5 | Provide security and privacy controls | Control catalog | Control selection and tailoring, including the SR control family |
| ISO 28000:2022 | Manage security risks in supply chains | Certifiable management-system requirements | Organization-level supply-chain security management system |
Common Misconceptions
NIST SP 800-161 is only for federal procurement teams.
The guidance addresses executives, enterprise risk, mission owners, acquisition, cybersecurity, engineering, operations, and suppliers; nonfederal organizations may also adopt it voluntarily.
Sending every supplier the same security questionnaire is a complete C-SCRM program.
A defensible program uses risk-based scoping, multiple evidence sources, acquisition controls, product and service analysis, ongoing monitoring, response planning, and accountable risk decisions.
Implementing the publication produces a NIST certification.
NIST does not certify organizations against SP 800-161. Organizations may assess implementation internally or independently, but any contractual or regulatory assurance has a separate basis.
A supplier that passed onboarding does not need further review.
Ownership, locations, sub-tier dependencies, products, vulnerabilities, threats, and services change. Critical relationships require event-driven and periodic reassessment throughout their lifecycle.
Penalties & Enforcement
NIST SP 800-161 Rev. 1 is guidance, not a certification scheme, and it does not itself create fines or a universal compliance mandate. Federal statutes, OMB policy, acquisition rules, contract clauses, sector regulation, and customer requirements may independently require C-SCRM outcomes or evidence; consequences must be evaluated under those separate authorities.
Frequently Asked Questions
What is the current version of NIST SP 800-161?
expand_more
The current publication is NIST SP 800-161 Rev. 1 Update 1, published as an update on 1 November 2024. It retains the May 2022 revision and incorporates changes recorded in Appendix K. The NIST publication page is the authoritative place to check for later errata or updates.
Who should use NIST SP 800-161 Rev. 1?
expand_more
It was written for federal organizations and their supply-chain stakeholders, but NIST permits voluntary use by other organizations. It is useful to executives, enterprise-risk teams, acquisition and procurement staff, cybersecurity teams, system owners, engineers, legal teams, and suppliers that manage risk from software, hardware, cloud, operational technology, and services.
Is NIST SP 800-161 mandatory or certifiable?
expand_more
The publication is guidance and has no certification program. It does not itself impose a universal mandate. A federal policy, acquisition regulation, contract clause, sector rule, or customer agreement may separately require particular C-SCRM practices or evidence, so organizations must map the guidance to their own authorities.
How does SP 800-161 differ from NIST IR 8536?
expand_more
SP 800-161 provides the organization-wide program, risk-management, acquisition, control, and assessment practices for cybersecurity supply-chain risk. NIST IR 8536 focuses more narrowly on interoperable manufacturing traceability records, provenance links, and selective disclosure. Traceability evidence can support a broader SP 800-161 program, but it does not replace it.
How does SP 800-161 relate to NIST CSF 2.0 and SP 800-53?
expand_more
NIST CSF 2.0 expresses high-level cybersecurity outcomes, including supply-chain outcomes in Govern. SP 800-53 supplies a catalog of security and privacy controls, including the Supply Chain Risk Management family. SP 800-161 explains how to organize, tailor, and apply those outcomes and controls across C-SCRM governance, acquisition, systems, suppliers, products, and services.
What are the three organizational levels in the guidance?
expand_more
Level 1 is the enterprise level, where leadership sets strategy, risk appetite, policy, and resources. Level 2 is the mission and business-process level, where teams translate enterprise priorities into capability and portfolio decisions. Level 3 is the operational level, where system, product, service, and supplier risks are assessed and controlled. Information and decisions must flow in both directions.
What evidence should an auditor or buyer expect?
expand_more
Useful evidence includes an approved strategy, implementation plan and policy; scoped risk assessments; criticality criteria; acquisition requirements and contract clauses; supplier and product assessments; tailored controls; decision and exception records; incident and change notifications; remediation tracking; metrics; reassessment results; and management review. Evidence should be proportionate to risk rather than identical for every supplier.
Official Documentation
Official PDF for NIST SP 800-161 Rev. 1
Official publication or summary for NIST SP 800-161 Rev. 1
Official online resource
National Institute of Standards and Technology (NIST) guidance and reference material
Implementation toolkit
Templates, guidance, or companion resources for NIST SP 800-161 Rev. 1