HomeFrameworksDefense, Supply Chain & NIST CatalogueNIST SP 800-161

Framework  Defense, Supply Chain & NIST Catalogue

NIST SP 800-161

NIST Special Publication 800-161 Revision 1, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", is the US federal guide to managing cybersecurity risk that enters through suppliers, products, and services. Revision 1 was issued in May 2022 and reissued with errata as 800-161r1-upd1 on November 1, 2024.

It lays out a C-SCRM program across three levels (enterprise, mission, and system), gives a control overlay drawn from NIST SP 800-53 Revision 5's supply chain (SR) family and related controls, and includes appendices on risk assessment templates and software-related supply chain practices responding to Executive Order 14028.

It is guidance for federal agencies and a reference for everyone else; there is no certification. Organizations following it produce a C-SCRM strategy and policy, a supplier inventory with criticality tiers, supplier risk assessments, contract clauses, and monitoring records, and often use it to satisfy the SR control family in FedRAMP or NIST SP 800-171 work.

AI-compiled
Share
Sponsored
NIST
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with NIST SP 800-161
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Mandatory in substance for US federal agencies through FISMA and OMB direction; voluntary for others. Federal contractors and cloud providers meet its content indirectly through the SR controls in NIST SP 800-53 baselines and FedRAMP.

What the assessor asks to see

C-SCRM strategy, policy, and plan; roles and governance; supplier and product inventory with criticality tiers; supplier risk assessments and due diligence; contractual security requirements; SBOM and provenance records where applicable; monitoring and incident handling for supplier events; disposal and end-of-life procedures.

Assessors

Who assesses NIST SP 800-161

None for the publication itself; SR controls derived from it are assessed within FedRAMP (3PAOs), FISMA (agency assessors), and CMMC (C3PAOs) engagements.

No firm has claimed a NIST SP 800-161 assessor listing yet. Claim yours →

Consultants

Who helps with NIST SP 800-161

Supply chain risk consultancies and third-party risk management platform vendors map their programs to it. Engagements typically build the supplier inventory, criticality model, and assessment questionnaires, and draft the C-SCRM plan.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a NIST SP 800-161 consultant listing yet. Claim yours →

Related reading

  1. NIST SP 800-161 complianceDescribes how the C-SCRM overlay is applied on top of an 800-53 control baseline rather than assessed on its own.Microsoft
  2. Supply chain security: CMMC, NIST 800-171 and NIST 800-161Sorts out how the supply chain guidance relates to the contractor requirements companies are more often asked about.Forvis Mazars

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for NIST SP 800-161

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with NIST SP 800-161

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.