NIST SP 800-161
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Acquisition and Procurement
Integrate C-SCRM requirements into acquisition processes including requirements definition, source selection, contracting, and award.
- Acquisition workflow with C-SCRM gates
- Requirements templates with C-SCRM clauses
- Source selection evaluation criteria
- Award documentation
- C-SCRM added late in process
- Source selection ignores C-SCRM
- Templates outdated
Define and enforce baseline security and supply chain requirements for suppliers, tailored to criticality and the nature of products and services provided.
- Supplier security baseline
- Tailoring guide
- Contract clauses enforcing baseline
- Evidence of supplier acceptance
- One-size-fits-all baseline
- No tailoring
- Enforcement only at onboarding
Require prime suppliers to flow down C-SCRM obligations to sub-tier suppliers commensurate with criticality and risk.
- Standard flow-down clauses
- Verification records or attestations
- Sub-tier supplier mapping for critical items
- Audit findings on flow-down
- No verification of flow-down
- Sub-tier mapping absent
- Clauses missing
Components and Services
Verify the authenticity of hardware and software components received, including the use of authorised resellers, signatures, and verification procedures.
- Authorised reseller list
- Verification procedure
- Counterfeit detection and response procedure
- Verification logs
- Procurement from unauthorised channels
- No verification at receipt
- No counterfeit reporting
Obtain and use a software bill of materials for acquired and produced software to support vulnerability management, licence compliance, and provenance tracking.
- SBOM acquisition policy
- Repository of SBOMs
- Vulnerability triage records using SBOM
- Sample SBOMs in standard format
- No SBOM repository
- SBOMs collected but not used
- No format standard
Track the provenance and pedigree of critical components and services throughout the supply chain, supporting decisions on use, retention, and disposal.
- Provenance records for critical components
- Signed pedigree artefacts where applicable
- Lifecycle decision records using provenance
- Audit of provenance completeness
- Provenance not retained
- No pedigree for software builds
- Decisions made without provenance review
Enterprise Governance
Establish an enterprise governance structure for cyber supply chain risk management with executive sponsorship, decision rights, and integration with enterprise risk management.
- C-SCRM governance charter
- Executive sponsor designation
- ERM integration mapping
- Minutes of governance body meetings
- No executive sponsor
- Governance separate from ERM
- Meetings irregular
Maintain a policy framework that defines requirements for cyber supply chain risk management across acquisition, operations, and disposal of systems, components, and services.
- C-SCRM policy
- Standards and procedures referenced
- Lifecycle coverage matrix
- Annual review records
- Policy missing acquisition phase
- No review cadence
- Standards not linked
Develop a C-SCRM strategy and implementation plan that defines goals, scope, roles, milestones, and resources for the programme.
- Strategy document
- Implementation roadmap with dates
- Budget and resource plan
- Progress reports
- Strategy without milestones
- No budget allocated
- Roadmap not updated
Incident and Response
Integrate supply chain considerations into incident response, including supplier notifications, evidence preservation, and coordination across the supply chain.
- Incident response plan with supplier annex
- Supplier coordination playbook
- Evidence preservation procedure
- Lessons learned from supplier-involved incidents
- No supplier annex
- Suppliers not contacted timely
- Evidence not preserved
Operate vulnerability disclosure and response practices that cover acquired components and supplier services, including coordinated disclosure with upstream providers.
- Vulnerability disclosure policy
- Coordinated disclosure records with suppliers
- Triage workflow
- Remediation tracking
- No coordinated disclosure with suppliers
- Triage manual and slow
- Remediation untracked
NIST SP 800-161: Access Control
Supply-chain-tailored access control requirements for systems, components, and supplier interactions.
- Supply-chain-tailored access controls
- Supplier access uncontrolled
Acquisition controls addressing supplier requirements, development practices, and component authenticity.
- Acquisition controls for supplier/dev practices and authenticity
- No acquisition security requirements
Dedicated supply chain risk management controls including the C-SCRM plan, supplier assessments, and component tamper resistance.
- C-SCRM plan, supplier assessments, tamper resistance
- No SR-family controls implemented
Detect, respond to, and recover from incidents that originate in or propagate through the ICT supply chain.
- Supply chain incident detection and response procedures
- No process for supply-chain-origin incidents
Establish and maintain the provenance of systems, components, and data, tracking changes and the chain of custody through the supply chain.
- Provenance and chain-of-custody records for components
- No provenance/traceability for components
NIST SP 800-161: Asset Management
Identify mission-critical functions and components to prioritize ICT supply chain risk management activities and controls.
- Criticality analysis of functions and components
- Critical components not identified
Implement foundational practices such as a C-SCRM program, supplier relationships, and integration with enterprise risk management as a basis for the controls.
- C-SCRM program and ERM integration evidence
- No formal C-SCRM program
Monitor ICT supply chain risk over time, including changes to suppliers, products, and the threat environment, and the effectiveness of responses.
- Ongoing supplier/product/threat monitoring records
- No continuous supply chain monitoring
Select and implement courses of action (accept, avoid, mitigate, share, or transfer) to address identified ICT supply chain risks.
- Documented risk responses (mitigate/accept/avoid/transfer)
- Identified risks without response decisions
Establish and manage agreements, requirements, and oversight of suppliers, developers, system integrators, and external service providers.
- Supplier agreements, requirements, and oversight records
- No supplier security requirements or oversight
NIST SP 800-161: Information Security Policies
Identify and evaluate ICT supply chain threats, vulnerabilities, likelihood, and impact to determine supply chain risk.
- Supply chain threat/vulnerability/impact assessments
- No supply chain risk assessment
Establish the context and assumptions for ICT supply chain risk decisions, including constraints, risk tolerance, and priorities.
- Documented C-SCRM risk context, constraints, and tolerance
- Risk framing undocumented
Establish organization-wide ICT SCRM governance, strategy, risk appetite, and policy at the organization tier.
- Organization-wide C-SCRM strategy, policy, and risk appetite
- No organization-level C-SCRM governance
Integrate ICT SCRM into mission and business process design, including the criticality of functions and the acquisition strategy.
- C-SCRM integrated into mission/business process and acquisition
- Supply chain risk not considered in process design
Apply ICT SCRM controls to individual information systems and their components across the system development lifecycle.
- C-SCRM controls applied to systems and components
- System-level supply chain controls absent
Programme Measurement
Measure C-SCRM programme effectiveness using defined metrics and report results to governance bodies and executive sponsors at defined cadence.
- Metric catalogue with definitions
- Sample reports
- Governance meeting minutes referencing metrics
- Improvement actions tracked
- Only output metrics tracked
- No improvement actions
- Reports not seen by sponsors
Resilience
Plan and prepare for disruption of critical supply chains through alternates, stockpiles, contractual recovery commitments, and exercised recovery procedures.
- Continuity plan for critical supply chains
- Alternate source identification
- Stockpile or buffer inventory levels
- Tabletop exercise reports
- No alternates identified
- Exercises not run
- Buffer levels guessed
Participate in supply chain information sharing with sector partners, government, and industry communities to improve collective awareness and response.
- ISAC or community memberships
- Sharing activity logs
- Records of action taken on shared intel
- Reciprocal sharing examples
- Member but not active
- No reciprocal sharing
- Intel received but not acted on
Risk Management
Perform supply chain risk assessments at enterprise, mission, and system levels that consider threats, vulnerabilities, likelihood, impact, and concentration risk.
- Risk assessment methodology
- Assessment reports at three tiers
- Concentration risk analysis
- Treatment decisions
- Only system-level assessments
- No concentration analysis
- Methodology undocumented
Identify critical systems, components, services, and suppliers whose compromise would significantly impact mission and prioritise C-SCRM controls accordingly.
- Criticality methodology
- List of critical components, services, and suppliers
- Prioritised control catalogue for critical items
- Annual re-evaluation records
- No methodology
- Critical inventory incomplete
- Controls not differentiated for critical items
Supplier Management
Conduct due diligence on suppliers prior to award and at defined intervals, including security posture, ownership, foreign influence, and operational practices.
- Due diligence questionnaire
- Ownership and beneficial ownership analysis
- Periodic review schedule and results
- Risk-based supplier scores
- Due diligence only at onboarding
- Beneficial ownership not assessed
- No risk scoring
Continuously monitor suppliers using a combination of attestations, evidence reviews, external signals, and incident notifications.
- Monitoring procedure
- External signal feeds in use
- Alert response playbook
- Sample monitoring records
- Monitoring only via annual questionnaire
- No alert response
- External signals not subscribed
Track supplier performance against security and C-SCRM obligations and manage issues to closure with documented escalation paths.
- Supplier scorecards
- Issue register with status and owners
- Escalation procedure
- Closure records
- Issues never closed
- No escalation path
- Performance not measured
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-161 framework page.