NIST SP 800-161 Rev 1
What is NIST SP 800-161 Rev 1?
NIST SP 800-161 Rev 1 Cybersecurity Supply Chain Risk Management Practices.. It comprises 191 controls organised across 20 domains, published by NIST, and applies in the United States.
How NIST SP 800-161 Rev 1 maps to other frameworks
All 191 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 20 domains NIST SP 800-161 Rev 1 groups its controls into
Frameworks that share controls with NIST SP 800-161 Rev 1
Each of these has at least one control mapped to a control in NIST SP 800-161 Rev 1. The number is how many NIST SP 800-161 Rev 1 controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap NIST SP 800-161 Rev 1
Where NIST SP 800-161 Rev 1 overlaps with the standards you already hold
Where to get trained on NIST SP 800-161 Rev 1
2 courses in the catalogue cover NIST SP 800-161 Rev 1 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
Training more than one person? Ten seats of any course is $1,490 on a single licence, against $199 a seat bought one at a time.
What an auditor will ask you for
All 191 NIST SP 800-161 Rev 1 controls, each with what it requires, the artefacts an auditor will ask you for, and where it commonly fails. Free to read, nothing to fill in.
Read the NIST SP 800-161 Rev 1 evidence request listWhat NIST SP 800-161 Rev 1 means in your sector
What NIST SP 800-161 Rev 1 means for your job
Questions people ask about NIST SP 800-161 Rev 1
What is NIST SP 800-161 Rev 1?
How many controls does NIST SP 800-161 Rev 1 have?
Where does NIST SP 800-161 Rev 1 apply?
What frameworks does NIST SP 800-161 Rev 1 map to?
How do I get started with NIST SP 800-161 Rev 1 compliance?
Query NIST SP 800-161 Rev 1 programmatically
NIST SP 800-161 Rev 1, its 191 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST SP 800-161 Rev 1 API reference and MCP config →What NIST SP 800-161 Rev 1 requires, control by control
Each page carries the requirement text for one NIST SP 800-161 Rev 1 control and what an assessor expects to see as evidence.
- AC-1 Policy and Procedures
- AC-17 Remote Access
- AC-18 Wireless Access
- AC-19 Access Control for Mobile Devices
- AC-2 Account Management
- AC-20 Use of External Systems
- AC-21 Information Sharing
- AC-22 Publicly Accessible Content
- AC-23 Data Mining Protection
- AC-24 Access Control Decisions
How much of another standard NIST SP 800-161 Rev 1 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- NIST SP 800-161 Rev 1 to APEC Cross-Border Privacy Rules (CBPR) System crosswalk
- NIST SP 800-161 Rev 1 to APRA CPS 230 Operational Risk Management crosswalk
- NIST SP 800-161 Rev 1 to APRA CPS 234 crosswalk
- AWS Well-Architected Security Pillar to NIST SP 800-161 Rev 1 crosswalk
- NIST SP 800-161 Rev 1 to Azure Security Benchmark crosswalk
- C5 (Germany) to NIST SP 800-161 Rev 1 crosswalk
- NIST SP 800-161 Rev 1 to CFTC System Safeguards (17 CFR 37, 38, 39, 49) crosswalk
- NIST SP 800-161 Rev 1 to CIS Controls v8 crosswalk
How ready are you for NIST SP 800-161 Rev 1?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.