WorkflowGLOBALNIST SP 800-161 Rev. 1

NIST SP 800-161 Rev. 1 C-SCRM Governance Checklist

Assign each C-SCRM decision to the right risk-management level, name an accountable owner, and retain evidence that direction, execution, escalation, and review are working.

Tailor this checklist to the enterprise's structure, mission, risk appetite, resources, contracts, and applicable requirements. SP 800-161 is guidance and does not prescribe one governance structure.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this checklist to connect enterprise direction to mission and business-process decisions and operational execution. NIST SP 800-161 Rev. 1 was published in May 2022 and Update 1 includes changes through 1 November 2024. It uses three risk-management levels and an iterative Frame, Assess, Respond, and Monitor process. The checklist is an implementation aid, not a NIST certification test or a substitute for binding law, policy, or contract terms.

Section 1

C-SCRM governance checklist

Complete each check at the level that owns the decision. Level 1 sets enterprise direction and boundaries; Level 2 tailors them to missions and business processes; Level 3 applies them to systems, products, services, suppliers, and acquisition actions. Smaller organizations may combine roles, but should still keep decision authority and escalation clear.

NIST allows centralized, decentralized, and hybrid operating models. A program management office may provide shared services, templates, assessments, training, and reporting, but accountable leaders and risk owners retain their assigned decisions.

  • 1 | Set direction | Owner: executive leadership and the | Verify: strategy, policy, risk appetite and tolerance, priorities, constraints, governance model, resources, and escalation authority are approved. Evidence: approved strategy, policy, charter, high-level implementation plan, budget decisions, and meeting records.
  • 2 | Assign decisions | Owner: executive sponsor or delegated governance body | Verify: acquisition, mission, system, engineering, cybersecurity, legal, privacy, HR, continuity, incident, supplier-management, assessment, and risk-acceptance responsibilities are assigned across Levels 1, 2, and 3. Evidence: decision-rights or RACI matrix, delegations, charters, and reporting paths.
  • 3 | Prioritize scope | Owner: mission/business-process and system owners, supported by acquisition and specialists | Verify: critical missions, systems, suppliers, services, products, components, data flows, access, locations, and sub-tier dependencies are tied to risk scenarios. Evidence: inventories, dependency maps, criticality analysis, supplier risk assessments, and documented assumptions.
  • 4 | Tailor and implement | Owner: mission/business-process, acquisition, and system owners | Verify: enterprise direction is translated into specific requirements, selected and tailored controls, acquisition criteria, contract terms, system-level plans, monitoring, and response procedures. Evidence: requirements traceability, solicitations, contracts, control selections, plans of action and milestones, and current C-SCRM plans.
  • 5 | Monitor and feed back | Owner: the owner of each plan or control, with governance oversight | Verify: supplier, system, threat, vulnerability, incident, assessment, performance, and mission changes trigger review at the proper level. Evidence: monitoring results, reassessments, escalations, accepted risks, corrective actions, and revisions to strategy, policy, requirements, or plans.
Section 2

Decision points for C-SCRM program governance

Record the decision, the level that owns it, the evidence considered, the remaining uncertainty, and the person authorized to approve or escalate it. A document owner is not automatically the risk owner.

Use enterprise policy for common direction, mission/business-process plans for tailored priorities and dependencies, and operational plans for system- and acquisition-specific controls. When a decision exceeds delegated risk tolerance, send it upward with the evidence and response options.

  • Is this an enterprise-wide issue, a mission or business process issue, or an operational system issue?
  • Does the issue require a strategy, policy, implementation plan, or system-level plan?
  • What are the critical suppliers, products, services, and components that need extra scrutiny?
  • Should the response accept, avoid, mitigate, share, or transfer risk, and which authority may approve the remaining risk?
Section 3

Evidence fields for C-SCRM program governance

Retain enough evidence to reconstruct why a decision was made and whether it was carried out. Match retention, access, marking, and disclosure controls to the sensitivity of supplier and assessment information.

Review frequency should follow enterprise policy, contract terms, risk, and change. SP 800-161 calls operational plans living documents and says they should be reviewed and refreshed periodically, but it does not set one universal interval.

  • Decision record: scope, risk scenario, assumptions, constraints, applicable requirement, options considered, selected response, residual risk, approver, and date.
  • Implementation record: accountable owner, requirement or control, evidence artifact, covered system or supplier, version and period, storage location, validation method, and result.
  • Exception record: gap, affected mission or system, compensating control, corrective action, due date, escalation status, and authorized risk acceptance where applicable.
  • Review record: scheduled cadence plus triggers for supplier ownership or location changes, product updates, new sub-tiers, vulnerabilities, incidents, control failure, contract change, or changed mission criticality.
Primary sources

References and citations

doi.org
Referenced sections
  • Section 2.3.4 describes the operational C-SCRM plan as a living reference for continuous monitoring; Appendix E explains safeguarding and records-management considerations for federal supply chain risk assessment records.
"C-SCRM plans are intended to be referenced regularly and should be reviewed and refreshed periodically"
Related guides

Explore more topics

How should teams handle counterfeits under NIST SP 800-161 Rev. 1 supply-chain risk management?
Prioritize critical items, use traceable sources, verify authenticity and tamper protection, quarantine suspected counterfeits, and reassess affected risk.
How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?
Identify critical suppliers through mission dependency, component importance, access, concentration, substitutability, and potential impact, not spend alone.
How should teams handle monitoring under NIST SP 800-161 Rev. 1 supply-chain risk management?
Run risk-based supplier monitoring with scheduled revalidation, event triggers, operating signals, escalation thresholds, corrective action, and evidence.
How should teams handle provenance under NIST SP 800-161 Rev. 1 supply-chain risk management?
Collect and verify traceable origin, build, dependency, custody, authenticity, and change evidence for critical systems, components, software, and data.
How should teams handle supplier incidents under NIST SP 800-161 Rev. 1 supply-chain risk management?
Coordinate supplier incidents through joint triage, evidence preservation, containment, recovery, contract communication, corrective action, and reassessment.
How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?
Choose and document whether to accept, avoid, mitigate, share, or transfer supply-chain risk, with authority, actions, residual risk, and review triggers.
How should teams handle tiering under NIST SP 800-161 Rev. 1 supply-chain risk management?
Build supplier risk categories that drive assurance treatment while keeping them distinct from SP 800-161 risk-management levels and CSF Tiers.
NIST SP 800-161 Rev. 1 C-SCRM Governance Guide
Design NIST SP 800-161 Rev. 1 C-SCRM governance across the enterprise, mission/business-process, and operational levels with accountable roles and feedback loops.
NIST SP 800-161 Rev. 1 Contract and Monitoring Controls
Translate C-SCRM risk decisions into supplier clauses, subcontractor flow-down, evidence delivery, revalidation, monitoring, incident, continuity, and exit terms.
NIST SP 800-161 Rev. 1 Criticality Analysis Guide
Identify mission-critical functions, systems, components, products, services, suppliers, and single-source dependencies so C-SCRM effort follows potential impact.
NIST SP 800-161 Rev. 1 FAQ: practical implementation questions
NIST SP 800-161 Rev. 1 answers with cited implementation steps, decision criteria, and evidence guidance.
NIST SP 800-161 Rev. 1 implementation playbook
Build a tailored C-SCRM program with strategy, policy, plans, assessments, acquisition controls, monitoring, and evidence across NIST's three risk-management levels.
NIST SP 800-161 Rev. 1 Provenance and SBOM Supplier Controls
Use provenance, SBOM, build integrity, authenticity, and supplier evidence together to manage software and component risk under NIST SP 800-161 Rev. 1.
NIST SP 800-161 Rev. 1 supplier assessment evidence: risk-based records and evaluation criteria
Choose and validate supplier evidence based on criticality, risk, contract requirements, source reliability, freshness, and proof of operating effectiveness.
NIST SP 800-161 Rev. 1 Supplier Risk Tiering
Group suppliers by mission dependency and cyber risk, then tie each category to proportionate due diligence, evidence, contracts, monitoring, and response.
NIST SP 800-161 Rev. 1 vs DORA ICT third-party risk: practical side-by-side comparison
Compare NIST SP 800-161 Rev. 1 and DORA ICT third-party risk with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-161 Rev. 1 vs ISO/IEC 27036 supplier relationships: practical side-by-side comparison
Compare NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-161 Rev. 1: workflow for collecting and validating C-SCRM supplier evidence
A risk-based NIST SP 800-161 supplier evidence workflow from relationship scope and criticality through request, validation, decision, remediation, and monitoring.
Which contract controls should teams define under NIST SP 800-161 Rev. 1?
Translate supplier risk into measurable security, flow-down, evidence, monitoring, incident, continuity, remediation, and exit clauses under SP 800-161.