Skip to content

Evidence request lists

NIST SP 800-161

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Acquisition and Procurement

SCRM-ACQ-1
Acquisition Process Integration

Integrate C-SCRM requirements into acquisition processes including requirements definition, source selection, contracting, and award.

Artefacts an auditor will ask for
  • Acquisition workflow with C-SCRM gates
  • Requirements templates with C-SCRM clauses
  • Source selection evaluation criteria
  • Award documentation
Where this commonly fails
  • C-SCRM added late in process
  • Source selection ignores C-SCRM
  • Templates outdated
SCRM-ACQ-2
Supplier Security Requirements

Define and enforce baseline security and supply chain requirements for suppliers, tailored to criticality and the nature of products and services provided.

Artefacts an auditor will ask for
  • Supplier security baseline
  • Tailoring guide
  • Contract clauses enforcing baseline
  • Evidence of supplier acceptance
Where this commonly fails
  • One-size-fits-all baseline
  • No tailoring
  • Enforcement only at onboarding
SCRM-ACQ-3
Flow-Down to Sub-Tier Suppliers

Require prime suppliers to flow down C-SCRM obligations to sub-tier suppliers commensurate with criticality and risk.

Artefacts an auditor will ask for
  • Standard flow-down clauses
  • Verification records or attestations
  • Sub-tier supplier mapping for critical items
  • Audit findings on flow-down
Where this commonly fails
  • No verification of flow-down
  • Sub-tier mapping absent
  • Clauses missing

Components and Services

SCRM-COMP-1
Component Authenticity

Verify the authenticity of hardware and software components received, including the use of authorised resellers, signatures, and verification procedures.

Artefacts an auditor will ask for
  • Authorised reseller list
  • Verification procedure
  • Counterfeit detection and response procedure
  • Verification logs
Where this commonly fails
  • Procurement from unauthorised channels
  • No verification at receipt
  • No counterfeit reporting
SCRM-COMP-2
Software Bill of Materials Use

Obtain and use a software bill of materials for acquired and produced software to support vulnerability management, licence compliance, and provenance tracking.

Artefacts an auditor will ask for
  • SBOM acquisition policy
  • Repository of SBOMs
  • Vulnerability triage records using SBOM
  • Sample SBOMs in standard format
Where this commonly fails
  • No SBOM repository
  • SBOMs collected but not used
  • No format standard
SCRM-COMP-3
Provenance and Pedigree Tracking

Track the provenance and pedigree of critical components and services throughout the supply chain, supporting decisions on use, retention, and disposal.

Artefacts an auditor will ask for
  • Provenance records for critical components
  • Signed pedigree artefacts where applicable
  • Lifecycle decision records using provenance
  • Audit of provenance completeness
Where this commonly fails
  • Provenance not retained
  • No pedigree for software builds
  • Decisions made without provenance review

Enterprise Governance

SCRM-GOV-1
C-SCRM Governance Structure

Establish an enterprise governance structure for cyber supply chain risk management with executive sponsorship, decision rights, and integration with enterprise risk management.

Artefacts an auditor will ask for
  • C-SCRM governance charter
  • Executive sponsor designation
  • ERM integration mapping
  • Minutes of governance body meetings
Where this commonly fails
  • No executive sponsor
  • Governance separate from ERM
  • Meetings irregular
SCRM-GOV-2
C-SCRM Policy Framework

Maintain a policy framework that defines requirements for cyber supply chain risk management across acquisition, operations, and disposal of systems, components, and services.

Artefacts an auditor will ask for
  • C-SCRM policy
  • Standards and procedures referenced
  • Lifecycle coverage matrix
  • Annual review records
Where this commonly fails
  • Policy missing acquisition phase
  • No review cadence
  • Standards not linked
SCRM-GOV-3
C-SCRM Strategy and Implementation Plan

Develop a C-SCRM strategy and implementation plan that defines goals, scope, roles, milestones, and resources for the programme.

Artefacts an auditor will ask for
  • Strategy document
  • Implementation roadmap with dates
  • Budget and resource plan
  • Progress reports
Where this commonly fails
  • Strategy without milestones
  • No budget allocated
  • Roadmap not updated

Incident and Response

SCRM-INC-1
Supply Chain Incident Response

Integrate supply chain considerations into incident response, including supplier notifications, evidence preservation, and coordination across the supply chain.

Artefacts an auditor will ask for
  • Incident response plan with supplier annex
  • Supplier coordination playbook
  • Evidence preservation procedure
  • Lessons learned from supplier-involved incidents
Where this commonly fails
  • No supplier annex
  • Suppliers not contacted timely
  • Evidence not preserved
SCRM-INC-2
Vulnerability Disclosure and Response in Supply Chain

Operate vulnerability disclosure and response practices that cover acquired components and supplier services, including coordinated disclosure with upstream providers.

Artefacts an auditor will ask for
  • Vulnerability disclosure policy
  • Coordinated disclosure records with suppliers
  • Triage workflow
  • Remediation tracking
Where this commonly fails
  • No coordinated disclosure with suppliers
  • Triage manual and slow
  • Remediation untracked

NIST SP 800-161: Access Control

SP800-161-CONTROLS-AC
ICT SCRM Control Family: Access Control

Supply-chain-tailored access control requirements for systems, components, and supplier interactions.

Artefacts an auditor will ask for
  • Supply-chain-tailored access controls
Where this commonly fails
  • Supplier access uncontrolled
SP800-161-CONTROLS-SA
ICT SCRM Control Family: System and Services Acquisition

Acquisition controls addressing supplier requirements, development practices, and component authenticity.

Artefacts an auditor will ask for
  • Acquisition controls for supplier/dev practices and authenticity
Where this commonly fails
  • No acquisition security requirements
SP800-161-CONTROLS-SR
ICT SCRM Control Family: Supply Chain Risk Management

Dedicated supply chain risk management controls including the C-SCRM plan, supplier assessments, and component tamper resistance.

Artefacts an auditor will ask for
  • C-SCRM plan, supplier assessments, tamper resistance
Where this commonly fails
  • No SR-family controls implemented
SP800-161-INCIDENT
Supply Chain Incident Management

Detect, respond to, and recover from incidents that originate in or propagate through the ICT supply chain.

Artefacts an auditor will ask for
  • Supply chain incident detection and response procedures
Where this commonly fails
  • No process for supply-chain-origin incidents
SP800-161-PROVENANCE
Provenance and Traceability

Establish and maintain the provenance of systems, components, and data, tracking changes and the chain of custody through the supply chain.

Artefacts an auditor will ask for
  • Provenance and chain-of-custody records for components
Where this commonly fails
  • No provenance/traceability for components

NIST SP 800-161: Asset Management

SP800-161-CRITICALITY
Criticality Analysis

Identify mission-critical functions and components to prioritize ICT supply chain risk management activities and controls.

Artefacts an auditor will ask for
  • Criticality analysis of functions and components
Where this commonly fails
  • Critical components not identified
SP800-161-FOUND-PRACTICES
Foundational ICT SCRM Practices

Implement foundational practices such as a C-SCRM program, supplier relationships, and integration with enterprise risk management as a basis for the controls.

Artefacts an auditor will ask for
  • C-SCRM program and ERM integration evidence
Where this commonly fails
  • No formal C-SCRM program
SP800-161-MONITOR
Risk Process: Monitor

Monitor ICT supply chain risk over time, including changes to suppliers, products, and the threat environment, and the effectiveness of responses.

Artefacts an auditor will ask for
  • Ongoing supplier/product/threat monitoring records
Where this commonly fails
  • No continuous supply chain monitoring
SP800-161-RESPOND
Risk Process: Respond

Select and implement courses of action (accept, avoid, mitigate, share, or transfer) to address identified ICT supply chain risks.

Artefacts an auditor will ask for
  • Documented risk responses (mitigate/accept/avoid/transfer)
Where this commonly fails
  • Identified risks without response decisions
SP800-161-SUPPLIER
Supplier Relationship Management

Establish and manage agreements, requirements, and oversight of suppliers, developers, system integrators, and external service providers.

Artefacts an auditor will ask for
  • Supplier agreements, requirements, and oversight records
Where this commonly fails
  • No supplier security requirements or oversight

NIST SP 800-161: Information Security Policies

SP800-161-ASSESS
Risk Process: Assess

Identify and evaluate ICT supply chain threats, vulnerabilities, likelihood, and impact to determine supply chain risk.

Artefacts an auditor will ask for
  • Supply chain threat/vulnerability/impact assessments
Where this commonly fails
  • No supply chain risk assessment
SP800-161-FRAME
Risk Process: Frame

Establish the context and assumptions for ICT supply chain risk decisions, including constraints, risk tolerance, and priorities.

Artefacts an auditor will ask for
  • Documented C-SCRM risk context, constraints, and tolerance
Where this commonly fails
  • Risk framing undocumented
SP800-161-TIER1
Multitiered Risk: Tier 1 (Organization)

Establish organization-wide ICT SCRM governance, strategy, risk appetite, and policy at the organization tier.

Artefacts an auditor will ask for
  • Organization-wide C-SCRM strategy, policy, and risk appetite
Where this commonly fails
  • No organization-level C-SCRM governance
SP800-161-TIER2
Multitiered Risk: Tier 2 (Mission/Business Process)

Integrate ICT SCRM into mission and business process design, including the criticality of functions and the acquisition strategy.

Artefacts an auditor will ask for
  • C-SCRM integrated into mission/business process and acquisition
Where this commonly fails
  • Supply chain risk not considered in process design
SP800-161-TIER3
Multitiered Risk: Tier 3 (Information Systems)

Apply ICT SCRM controls to individual information systems and their components across the system development lifecycle.

Artefacts an auditor will ask for
  • C-SCRM controls applied to systems and components
Where this commonly fails
  • System-level supply chain controls absent

Programme Measurement

SCRM-MEAS-1
C-SCRM Metrics and Reporting

Measure C-SCRM programme effectiveness using defined metrics and report results to governance bodies and executive sponsors at defined cadence.

Artefacts an auditor will ask for
  • Metric catalogue with definitions
  • Sample reports
  • Governance meeting minutes referencing metrics
  • Improvement actions tracked
Where this commonly fails
  • Only output metrics tracked
  • No improvement actions
  • Reports not seen by sponsors

Resilience

SCRM-RES-1
Supply Chain Resilience and Continuity

Plan and prepare for disruption of critical supply chains through alternates, stockpiles, contractual recovery commitments, and exercised recovery procedures.

Artefacts an auditor will ask for
  • Continuity plan for critical supply chains
  • Alternate source identification
  • Stockpile or buffer inventory levels
  • Tabletop exercise reports
Where this commonly fails
  • No alternates identified
  • Exercises not run
  • Buffer levels guessed
SCRM-RES-2
Supply Chain Information Sharing

Participate in supply chain information sharing with sector partners, government, and industry communities to improve collective awareness and response.

Artefacts an auditor will ask for
  • ISAC or community memberships
  • Sharing activity logs
  • Records of action taken on shared intel
  • Reciprocal sharing examples
Where this commonly fails
  • Member but not active
  • No reciprocal sharing
  • Intel received but not acted on

Risk Management

SCRM-RM-1
Supply Chain Risk Assessment

Perform supply chain risk assessments at enterprise, mission, and system levels that consider threats, vulnerabilities, likelihood, impact, and concentration risk.

Artefacts an auditor will ask for
  • Risk assessment methodology
  • Assessment reports at three tiers
  • Concentration risk analysis
  • Treatment decisions
Where this commonly fails
  • Only system-level assessments
  • No concentration analysis
  • Methodology undocumented
SCRM-RM-2
Criticality Analysis

Identify critical systems, components, services, and suppliers whose compromise would significantly impact mission and prioritise C-SCRM controls accordingly.

Artefacts an auditor will ask for
  • Criticality methodology
  • List of critical components, services, and suppliers
  • Prioritised control catalogue for critical items
  • Annual re-evaluation records
Where this commonly fails
  • No methodology
  • Critical inventory incomplete
  • Controls not differentiated for critical items

Supplier Management

SCRM-SUP-1
Supplier Due Diligence

Conduct due diligence on suppliers prior to award and at defined intervals, including security posture, ownership, foreign influence, and operational practices.

Artefacts an auditor will ask for
  • Due diligence questionnaire
  • Ownership and beneficial ownership analysis
  • Periodic review schedule and results
  • Risk-based supplier scores
Where this commonly fails
  • Due diligence only at onboarding
  • Beneficial ownership not assessed
  • No risk scoring
SCRM-SUP-2
Continuous Supplier Monitoring

Continuously monitor suppliers using a combination of attestations, evidence reviews, external signals, and incident notifications.

Artefacts an auditor will ask for
  • Monitoring procedure
  • External signal feeds in use
  • Alert response playbook
  • Sample monitoring records
Where this commonly fails
  • Monitoring only via annual questionnaire
  • No alert response
  • External signals not subscribed
SCRM-SUP-3
Supplier Performance and Issue Management

Track supplier performance against security and C-SCRM obligations and manage issues to closure with documented escalation paths.

Artefacts an auditor will ask for
  • Supplier scorecards
  • Issue register with status and owners
  • Escalation procedure
  • Closure records
Where this commonly fails
  • Issues never closed
  • No escalation path
  • Performance not measured
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-161 framework page.