How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?
Identify the mission, business process, system, data, facility, or safety function that depends on the supplier. Then assess the supplied product or service, the consequence and time to unacceptable harm if it fails or is compromised, access and change authority, concentration and sub-tier dependencies, recovery time, and whether a qualified alternative can replace it in time. A small specialist, open-source maintainer, cloud subprocessor, or sole manufacturer can be critical even when direct spend is low.
NIST SP 800-161 Rev. 1 Update 1 says to maintain a current inventory of supplier relationships, contracts, products, and services and map them into organization-defined strategic groupings. It gives strategic/innovative, mission-critical, sustaining, and standard/non-essential as examples. The mapping should focus analysis on suppliers of the greatest strategic or operational importance and identify products and services that need greater confidence in risk mitigation, including .
Criticality and supplier risk answer different questions. Criticality measures the importance of the dependency and potential impact; the supplier risk assessment considers threats, vulnerabilities, likelihood, existing assurance, and other context. A well-controlled supplier may remain critical, while a non-critical supplier can still present risk that requires action.
- Inventory the supplier, contract, product or service, supported functions and systems, data and access, responsible owner, key sub-tiers, and known alternatives.
- Document the criticality rationale: maximum credible impact, time to unacceptable harm, recovery and replacement time, substitutability, concentration, and cross-enterprise use.
- Use the result to set due diligence, assurance evidence, contract language, inspection, monitoring, incident coordination, contingency planning, and approval authority.
- Reassess after material changes to the dependency, supplier, ownership, location, product, service, access, sub-tier chain, incident history, threat conditions, or available alternatives.
Section 3.1.1 supports a current supplier inventory, organization-defined groupings, priority for suppliers of strategic or operational importance, and analysis of single-source exposure.