NIST SP 800-161 Rev. 1 Cybersecurity supply chain risk management implementation hub
NIST SP 800-161 Rev. 1 defines cybersecurity supply chain risk management () as the systematic process for managing exposure to cyber risk throughout a supply chain and choosing appropriate responses. It covers risk from suppliers, their sub-tiers, and the products and services an enterprise acquires or uses, including IT, operational technology, IoT, software, hardware, cloud services, and related support. Start with enterprise direction, tailor it for missions and business processes, then apply it to systems, acquisitions, contracts, monitoring, and incident response.
A practical order is to establish governance, inventory supplier relationships and other acquisition paths, identify critical dependencies, assess risk, tailor controls and contract terms where an agreement exists, then monitor changes and revise the decision when evidence changes. Open source software, internal shared services, and repurposed products still need even when no procurement creates a supplier contract.
The publication is NIST guidance, not a certification or a law by itself. Revision 1 was published in May 2022, and Update 1 includes changes through November 1, 2024. It addresses cyber risk in product and service supply chains, not every commercial, quality, logistics, or financial aspect of supply chain risk management. Federal agencies must apply any separate statutes, policies, acquisition rules, and FedRAMP requirements that govern their use case. Nongovernmental organizations may adopt and tailor the guidance voluntarily or because a contract, customer requirement, or internal policy incorporates it.
Move from C-SCRM governance to operating evidence
New to SP 800-161? Begin with the implementation and governance guides. Then identify critical dependencies, set supplier-assurance depth, translate decisions into acquisition, contract, and lifecycle controls, and finish with monitoring, response, and framework comparisons. Use the applicable law, policy, acquisition rule, contract, or internal mandate to determine which recommendations are binding in your case.
Start here: model and governance
Understand what the publication covers, how the three risk-management levels interact, and which program artifacts establish accountable governance.
Prioritize suppliers and dependencies
Use criticality and supplier-risk decisions to focus limited assurance resources on the products, services, components, and relationships that matter most.
Collect evidence and set controls
Define supplier evidence, provenance, SBOM, contract, flow-down, revalidation, and monitoring expectations that match the assessed risk.
Compare approaches and answer focused questions
Keep SP 800-161 guidance distinct from legal or certification obligations, and use the FAQs for specific operational decisions.
Turn the guidance into an operating C-SCRM process
Assign each decision, evidence request, review, and corrective action to an owner. Keep the source, scope, status, approval, and supporting records with the work.
- Scope work by supplier relationship, product, service, system, mission, or control owner.
- Turn selected guidance into tasks, evidence requests, risk decisions, and review checkpoints.
- Keep documents, evidence, exceptions, and control records connected to the decision they support.
- Reassess when a supplier, dependency, threat, vulnerability, incident, or authoritative requirement changes.