FAQGLOBALNIST SP 800-161 Rev. 1

NIST SP 800-161 Rev. 1 How should teams handle counterfeits under NIST SP 800-161 Rev. 1 supply-chain risk management

A standalone answer for teams deciding how counterfeits should be scoped, evidenced, assigned, and reviewed under NIST SP 800-161 Rev. 1.

Based on public NIST and supplier-risk guidance, this answer provides practical criteria, owner roles, evidence expectations, and review gates for counterfeit-risk handling.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
2

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

spans acquisition, engineering, security, legal, quality, logistics, and C-SCRM. NIST SP 800-161 Rev. 1 Update 1 is voluntary cybersecurity supply-chain guidance for public- and private-sector enterprises; federal departments and agencies also have implementation requirements from other authorities. This page explains how teams can identify counterfeit risk, document evidence, assign ownership, and review the decision when conditions change.

Search this module

Find a question or answer quickly

2 of 2 questions
Question 1

What should teams do about counterfeit risk under NIST SP 800-161 Rev. 1?

Use criticality analysis to identify the systems and components where counterfeit or tampered items could create unacceptable mission, safety, availability, confidentiality, or integrity impact. NIST's SR-11 guidance calls for coordinated anti-counterfeit policies and procedures and, where appropriate, qualified bidder or manufacturer lists and authorized suppliers. SR-11(3) says enterprises should conduct for critical components at a minimum.

Prevention also includes tamper resistance and detection for critical components (SR-9), inspection before use and periodically afterward (SR-10), controlled service and repair (SR-11(2)), and contract flow-down where relevant. The organization must still tailor methods to the item and threat; the publication does not prescribe a single test, universal reporting destination, certification, or fixed inspection frequency for every organization.

Obsolete parts are a common borderline case. NIST's telecommunications example considers an original component that is no longer produced, a costly redesign, and purchases from the . The example uses trained physical inspection, digital imaging, signature and serial or part-number verification, sample electrical testing, design redundancy, and alternative vetted sources. These are illustrative controls, not a universal checklist or proof that every secondary-market item is counterfeit.

When authenticity is in doubt, stop the item from entering or remaining in production until the authorized decision-maker resolves its status. Follow applicable legal, regulatory, contractual, safety, evidence-handling, and reporting procedures rather than assuming that one NIST process fits every sector.

  • Before purchase: record criticality, approved sources, manufacturer and distributor identity, required traceability, inspection or test criteria, and relevant flow-down terms.
  • At receipt and before use: match the delivered item to purchase, part, lot, serial, custody, packaging, signature, inspection, and acceptance records appropriate to the item.
  • On suspicion: segregate the item, prevent installation or further distribution, preserve records and chain of custody when required, investigate related lots and systems, and use the organization's required reporting channel.
  • After disposition: record the authenticity decision, removal or replacement, supplier corrective action, affected inventory and systems, alternative sources, and the updated supplier and continuity risk.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix A, SR-9 through SR-11 cover tamper controls, inspection, component authenticity, coordinated anti-counterfeit procedures, qualified sources, service and repair, and scanning for critical components.

Question 2

What evidence should support counterfeits under NIST SP 800-161 Rev. 1?

Evidence should connect the exact item to its claimed source and verification result and show how suspected or confirmed counterfeits were controlled. A general supplier certificate does not establish the identity of a delivered part when it cannot be matched to the part, lot, serial number, shipment, or other item-level record.

  • Approved-source and supplier due-diligence record; purchase and shipment traceability; part, lot, and serial identifiers.
  • Acceptance, authenticity, tamper, or counterfeit test results and the criteria used.
  • Quarantine, investigation, reporting, disposition, corrective-action, and supplier-risk reassessment records.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix A supports traceable inspection, authenticity, reporting, and disposition evidence for critical components; the acquisition guidance connects product authenticity and risk assessment to purchase and deployment decisions.

Primary sources

References and citations

doi.org
Referenced sections
  • Appendix A supports traceable inspection, authenticity, reporting, and disposition evidence for critical components; the acquisition guidance connects product authenticity and risk assessment to purchase and deployment decisions.
"identifying, assessing, and mitigating cybersecurity risks"
Related guides

Explore more topics

How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?
Identify critical suppliers through mission dependency, component importance, access, concentration, substitutability, and potential impact, not spend alone.
How should teams handle monitoring under NIST SP 800-161 Rev. 1 supply-chain risk management?
Run risk-based supplier monitoring with scheduled revalidation, event triggers, operating signals, escalation thresholds, corrective action, and evidence.
How should teams handle provenance under NIST SP 800-161 Rev. 1 supply-chain risk management?
Collect and verify traceable origin, build, dependency, custody, authenticity, and change evidence for critical systems, components, software, and data.
How should teams handle supplier incidents under NIST SP 800-161 Rev. 1 supply-chain risk management?
Coordinate supplier incidents through joint triage, evidence preservation, containment, recovery, contract communication, corrective action, and reassessment.
How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?
Choose and document whether to accept, avoid, mitigate, share, or transfer supply-chain risk, with authority, actions, residual risk, and review triggers.
How should teams handle tiering under NIST SP 800-161 Rev. 1 supply-chain risk management?
Build supplier risk categories that drive assurance treatment while keeping them distinct from SP 800-161 risk-management levels and CSF Tiers.
NIST SP 800-161 Rev. 1 C-SCRM Governance Checklist
A NIST SP 800-161 Rev. 1 checklist for assigning C-SCRM decisions across enterprise, mission/business-process, and operational levels.
NIST SP 800-161 Rev. 1 C-SCRM Governance Guide
Design NIST SP 800-161 Rev. 1 C-SCRM governance across the enterprise, mission/business-process, and operational levels with accountable roles and feedback loops.
NIST SP 800-161 Rev. 1 Contract and Monitoring Controls
Translate C-SCRM risk decisions into supplier clauses, subcontractor flow-down, evidence delivery, revalidation, monitoring, incident, continuity, and exit terms.
NIST SP 800-161 Rev. 1 Criticality Analysis Guide
Identify mission-critical functions, systems, components, products, services, suppliers, and single-source dependencies so C-SCRM effort follows potential impact.
NIST SP 800-161 Rev. 1 FAQ: practical implementation questions
NIST SP 800-161 Rev. 1 answers with cited implementation steps, decision criteria, and evidence guidance.
NIST SP 800-161 Rev. 1 implementation playbook
Build a tailored C-SCRM program with strategy, policy, plans, assessments, acquisition controls, monitoring, and evidence across NIST's three risk-management levels.
NIST SP 800-161 Rev. 1 Provenance and SBOM Supplier Controls
Use provenance, SBOM, build integrity, authenticity, and supplier evidence together to manage software and component risk under NIST SP 800-161 Rev. 1.
NIST SP 800-161 Rev. 1 supplier assessment evidence: risk-based records and evaluation criteria
Choose and validate supplier evidence based on criticality, risk, contract requirements, source reliability, freshness, and proof of operating effectiveness.
NIST SP 800-161 Rev. 1 Supplier Risk Tiering
Group suppliers by mission dependency and cyber risk, then tie each category to proportionate due diligence, evidence, contracts, monitoring, and response.
NIST SP 800-161 Rev. 1 vs DORA ICT third-party risk: practical side-by-side comparison
Compare NIST SP 800-161 Rev. 1 and DORA ICT third-party risk with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-161 Rev. 1 vs ISO/IEC 27036 supplier relationships: practical side-by-side comparison
Compare NIST SP 800-161 Rev. 1 and ISO/IEC 27036 supplier relationships with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-161 Rev. 1: workflow for collecting and validating C-SCRM supplier evidence
A risk-based NIST SP 800-161 supplier evidence workflow from relationship scope and criticality through request, validation, decision, remediation, and monitoring.
Which contract controls should teams define under NIST SP 800-161 Rev. 1?
Translate supplier risk into measurable security, flow-down, evidence, monitoring, incident, continuity, remediation, and exit clauses under SP 800-161.