NIST SP 800-161 Rev. 1Free Resource

NIST SP 800-161 Rev. 1 Cybersecurity supply chain risk management implementation hub

NIST SP 800-161 Rev. 1 defines cybersecurity supply chain risk management () as the systematic process for managing exposure to cyber risk throughout a supply chain and choosing appropriate responses. It covers risk from suppliers, their sub-tiers, and the products and services an enterprise acquires or uses, including IT, operational technology, IoT, software, hardware, cloud services, and related support. Start with enterprise direction, tailor it for missions and business processes, then apply it to systems, acquisitions, contracts, monitoring, and incident response.

By Sorena AIUpdated 2026No signup required
Quick scan
C-SCRM
C-SCRM implementation playbook
Build strategy, policy, plans, assessments, controls, and feedback loops across all three risk-management levels.
Contract + monitoring controls
Practical controls for supplier agreements, delivery, and continuous oversight.
Supplier risk tiering
Tiering logic and depth model for assessments and evidence cadence.

A practical order is to establish governance, inventory supplier relationships and other acquisition paths, identify critical dependencies, assess risk, tailor controls and contract terms where an agreement exists, then monitor changes and revise the decision when evidence changes. Open source software, internal shared services, and repurposed products still need even when no procurement creates a supplier contract.

Key dates
C-SCRM
Focused
Suppliers
Tiered
Contracts
Agreed
Evidence
Auditable
What this artifact helps you do
Integrate C-SCRM into risk governance
Set enterprise strategy and policy, tailor them at Level 2 for missions and business processes, and document Level 3 system plans and controls.
Run supplier assurance with depth
Map supplier relationships and critical dependencies, then set due diligence, evidence, contract, and monitoring depth based on risk.
Check whether controls work
Revalidate supplier adherence, monitor material changes, track corrective action, and route residual risk to the authorized decision-maker.
Tier
Contract
Monitor
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 24, 2026

The publication is NIST guidance, not a certification or a law by itself. Revision 1 was published in May 2022, and Update 1 includes changes through November 1, 2024. It addresses cyber risk in product and service supply chains, not every commercial, quality, logistics, or financial aspect of supply chain risk management. Federal agencies must apply any separate statutes, policies, acquisition rules, and FedRAMP requirements that govern their use case. Nongovernmental organizations may adopt and tailor the guidance voluntarily or because a contract, customer requirement, or internal policy incorporates it.

Recommended reading path

Move from C-SCRM governance to operating evidence

New to SP 800-161? Begin with the implementation and governance guides. Then identify critical dependencies, set supplier-assurance depth, translate decisions into acquisition, contract, and lifecycle controls, and finish with monitoring, response, and framework comparisons. Use the applicable law, policy, acquisition rule, contract, or internal mandate to determine which recommendations are binding in your case.

1

Start here: model and governance

Understand what the publication covers, how the three risk-management levels interact, and which program artifacts establish accountable governance.

3

Collect evidence and set controls

Define supplier evidence, provenance, SBOM, contract, flow-down, revalidation, and monitoring expectations that match the assessed risk.

4

Compare approaches and answer focused questions

Keep SP 800-161 guidance distinct from legal or certification obligations, and use the FAQs for specific operational decisions.

Next step

Turn the guidance into an operating C-SCRM process

Assign each decision, evidence request, review, and corrective action to an owner. Keep the source, scope, status, approval, and supporting records with the work.

What this unlocks
  • Scope work by supplier relationship, product, service, system, mission, or control owner.
  • Turn selected guidance into tasks, evidence requests, risk decisions, and review checkpoints.
  • Keep documents, evidence, exceptions, and control records connected to the decision they support.
  • Reassess when a supplier, dependency, threat, vulnerability, incident, or authoritative requirement changes.