Framework Defense, Supply Chain & NIST Catalogue
NIST SP 800-161
NIST Special Publication 800-161 Revision 1, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", is the US federal guide to managing cybersecurity risk that enters through suppliers, products, and services. Revision 1 was issued in May 2022 and reissued with errata as 800-161r1-upd1 on November 1, 2024.
It lays out a C-SCRM program across three levels (enterprise, mission, and system), gives a control overlay drawn from NIST SP 800-53 Revision 5's supply chain (SR) family and related controls, and includes appendices on risk assessment templates and software-related supply chain practices responding to Executive Order 14028.
It is guidance for federal agencies and a reference for everyone else; there is no certification. Organizations following it produce a C-SCRM strategy and policy, a supplier inventory with criticality tiers, supplier risk assessments, contract clauses, and monitoring records, and often use it to satisfy the SR control family in FedRAMP or NIST SP 800-171 work.
help
Who has to comply
Mandatory in substance for US federal agencies through FISMA and OMB direction; voluntary for others. Federal contractors and cloud providers meet its content indirectly through the SR controls in NIST SP 800-53 baselines and FedRAMP.
What the assessor asks to see
C-SCRM strategy, policy, and plan; roles and governance; supplier and product inventory with criticality tiers; supplier risk assessments and due diligence; contractual security requirements; SBOM and provenance records where applicable; monitoring and incident handling for supplier events; disposal and end-of-life procedures.
Assessors
Who assesses NIST SP 800-161
None for the publication itself; SR controls derived from it are assessed within FedRAMP (3PAOs), FISMA (agency assessors), and CMMC (C3PAOs) engagements.
No firm has claimed a NIST SP 800-161 assessor listing yet. Claim yours →
Consultants
Who helps with NIST SP 800-161
Supply chain risk consultancies and third-party risk management platform vendors map their programs to it. Engagements typically build the supplier inventory, criticality model, and assessment questionnaires, and draft the C-SCRM plan.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a NIST SP 800-161 consultant listing yet. Claim yours →
Software
Tools for NIST SP 800-161
Tools that name this framework in their own material.
Related reading
- NIST SP 800-161 complianceDescribes how the C-SCRM overlay is applied on top of an 800-53 control baseline rather than assessed on its own.Microsoft
- Supply chain security: CMMC, NIST 800-171 and NIST 800-161Sorts out how the supply chain guidance relates to the contractor requirements companies are more often asked about.Forvis Mazars
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for NIST SP 800-161
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with NIST SP 800-161
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.