FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
17of17items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
How should teams handle counterfeits under NIST SP 800-161 Rev. 1 supply-chain risk management?

What should teams do about counterfeit risk under NIST SP 800-161 Rev. 1?

Use criticality analysis to identify the systems and components where counterfeit or tampered items could create unacceptable mission, safety, availability, confidentiality, or integrity impact. NIST's SR-11 guidance calls for coordinated anti-counterfeit policies and procedures and, where appropriate, qualified bidder or manufacturer lists and authorized suppliers. SR-11(3) says enterprises should conduct anti-counterfeit scanning for critical components at a minimum.

Prevention also includes tamper resistance and detection for critical components (SR-9), inspection before use and periodically afterward (SR-10), controlled service and repair (SR-11(2)), and contract flow-down where relevant. The organization must still tailor methods to the item and threat; the publication does not prescribe a single test, universal reporting destination, certification, or fixed inspection frequency for every organization.

Obsolete parts are a common borderline case. NIST's telecommunications example considers an original component that is no longer produced, a costly redesign, and purchases from the secondary market. The example uses trained physical inspection, digital imaging, signature and serial or part-number verification, sample electrical testing, design redundancy, and alternative vetted sources. These are illustrative controls, not a universal checklist or proof that every secondary-market item is counterfeit.

When authenticity is in doubt, stop the item from entering or remaining in production until the authorized decision-maker resolves its status. Follow applicable legal, regulatory, contractual, safety, evidence-handling, and reporting procedures rather than assuming that one NIST process fits every sector.

  • Before purchase: record criticality, approved sources, manufacturer and distributor identity, required traceability, inspection or test criteria, and relevant flow-down terms.
  • At receipt and before use: match the delivered item to purchase, part, lot, serial, custody, packaging, signature, inspection, and acceptance records appropriate to the item.
  • On suspicion: segregate the item, prevent installation or further distribution, preserve records and chain of custody when required, investigate related lots and systems, and use the organization's required reporting channel.
  • After disposition: record the authenticity decision, removal or replacement, supplier corrective action, affected inventory and systems, alternative sources, and the updated supplier and continuity risk.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix A, SR-9 through SR-11 cover tamper controls, inspection, component authenticity, coordinated anti-counterfeit procedures, qualified sources, service and repair, and scanning for critical components.

How should teams handle counterfeits under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support counterfeits under NIST SP 800-161 Rev. 1?

Evidence should connect the exact item to its claimed source and verification result and show how suspected or confirmed counterfeits were controlled. A general supplier certificate does not establish the identity of a delivered part when it cannot be matched to the part, lot, serial number, shipment, or other item-level record.

  • Approved-source and supplier due-diligence record; purchase and shipment traceability; part, lot, and serial identifiers.
  • Acceptance, authenticity, tamper, or counterfeit test results and the criteria used.
  • Quarantine, investigation, reporting, disposition, corrective-action, and supplier-risk reassessment records.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix A supports traceable inspection, authenticity, reporting, and disposition evidence for critical components; the acquisition guidance connects product authenticity and risk assessment to purchase and deployment decisions.

How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?

How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?

Identify the mission, business process, system, data, facility, or safety function that depends on the supplier. Then assess the supplied product or service, the consequence and time to unacceptable harm if it fails or is compromised, access and change authority, concentration and sub-tier dependencies, recovery time, and whether a qualified alternative can replace it in time. A small specialist, open-source maintainer, cloud subprocessor, or sole manufacturer can be critical even when direct spend is low.

NIST SP 800-161 Rev. 1 Update 1 says to maintain a current inventory of supplier relationships, contracts, products, and services and map them into organization-defined strategic groupings. It gives strategic/innovative, mission-critical, sustaining, and standard/non-essential as examples. The mapping should focus analysis on suppliers of the greatest strategic or operational importance and identify products and services that need greater confidence in risk mitigation, including single-source exposure.

Criticality and supplier risk answer different questions. Criticality measures the importance of the dependency and potential impact; the supplier risk assessment considers threats, vulnerabilities, likelihood, existing assurance, and other context. A well-controlled supplier may remain critical, while a non-critical supplier can still present risk that requires action.

  • Inventory the supplier, contract, product or service, supported functions and systems, data and access, responsible owner, key sub-tiers, and known alternatives.
  • Document the criticality rationale: maximum credible impact, time to unacceptable harm, recovery and replacement time, substitutability, concentration, and cross-enterprise use.
  • Use the result to set due diligence, assurance evidence, contract language, inspection, monitoring, incident coordination, contingency planning, and approval authority.
  • Reassess after material changes to the dependency, supplier, ownership, location, product, service, access, sub-tier chain, incident history, threat conditions, or available alternatives.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 3.1.1 supports a current supplier inventory, organization-defined groupings, priority for suppliers of strategic or operational importance, and analysis of single-source exposure.

How should teams handle critical suppliers under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support critical suppliers under NIST SP 800-161 Rev. 1?

Keep the evidence tied to the supplier inventory and the dependency being rated. A reviewer should be able to reconstruct why the supplier was classified as critical or non-critical, which assumptions were used, who approved the result, and which treatment changed because of it.

Do not infer low criticality from low spend, a successful questionnaire, or the existence of a contract. Record unresolved sub-tier visibility and alternative-source assumptions instead of treating missing information as evidence of low dependency.

  • Dated relationship inventory and dependency map showing the supplier, supplied item or service, supported functions and systems, access, data, locations, and sub-tiers.
  • Criticality decision showing the category, criteria, supporting facts, impact and recovery assumptions, alternative-source analysis, owner, reviewer, and approval date.
  • Treatment record linking the category to contract terms, evidence requests, monitoring, incident participation, continuity actions, and risk authority.
  • Review history showing material changes, exceptions, reclassification decisions, and the evidence used for each decision.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 3.1.1 connects supplier inventory and mapping to prioritization, contract tailoring, and evaluation criteria; Appendix G supports documented criticality, impact, and risk decisions.

How should teams handle monitoring under NIST SP 800-161 Rev. 1 supply-chain risk management?

How should teams monitor suppliers under SP 800-161?

Start from a documented baseline: the supplier and supplied product or service, supported mission and systems, criticality, access, data, sub-tier dependencies, contract requirements, assessed risks, accepted exceptions, and expected controls. Without that baseline, a new signal cannot be evaluated against the original decision.

NIST's Monitor step separates three questions. Compliance monitoring asks whether processes and supplied products or services meet established requirements. Effectiveness monitoring asks whether the requirements produce the intended risk result. Change monitoring looks for conditions that require different controls or a new risk decision.

Use both regular reviews and off-cycle triggers. NIST leaves the interval to the enterprise. Relevant signals can include vulnerabilities, incidents, failed controls, stale evidence, ownership or location changes, subcontractor changes, product updates, service degradation, end-of-life notices, supply concentration, and geopolitical or environmental changes. Define who evaluates each signal and who can require remediation, invoke continuity measures, accept residual risk, suspend use, or exit. A supplier's passing score at onboarding does not remain current when the product, threat, dependency, or evidence changes.

  • Set a review interval from criticality, assurance needs, risk conditions, contract terms, and the useful life of the evidence; do not present one annual cadence as NIST's universal rule.
  • Assign a source, owner, evaluation rule, threshold, and response for each signal rather than collecting feeds that nobody is responsible for reviewing.
  • Revalidate supplier adherence and record the evidence, exceptions, corrective actions, effectiveness result, and current residual-risk decision.
  • Route significant changes into system risk, mission or business risk, enterprise reporting, acquisition decisions, the C-SCRM plan, and contingency planning.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix G, Task 4-2 distinguishes monitoring compliance, effectiveness, and change, requires organization-set review intervals and off-cycle triggers, and feeds monitoring results back into C-SCRM plans.

How should teams handle monitoring under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support monitoring under NIST SP 800-161 Rev. 1?

Evidence should show the monitored scope, expected supplier behavior, signals received, evaluation, decision, owner, and follow-up. A dashboard, subscription, or annual questionnaire proves that data can be collected; it does not prove that someone evaluated the signal or changed the risk treatment when needed.

  • Supplier and dependency inventory linked to systems, missions, data, access, and criticality.
  • Monitoring plan with signals, sources, thresholds, cadence, event triggers, owner, and escalation route.
  • Assessment, vulnerability, performance, incident, contract-revalidation, and corrective-action records.
  • Current residual-risk decision and evidence that material findings reached the enterprise, mission/business, or operational authority with power to act.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix G requires ongoing monitoring, documented review intervals and off-cycle triggers, updated risk assessments, reporting to decision-makers, and integration of Monitor outputs into the C-SCRM plan.

How should teams handle provenance under NIST SP 800-161 Rev. 1 supply-chain risk management?

What provenance should teams collect

NIST's SR-4 guidance says provenance should be documented for systems, system components, and associated data throughout the system development life cycle. Choose the depth from criticality, threat, vulnerability, impact, and the decision the evidence must support.

For hardware, useful evidence can include the manufacturer and authorized distribution path, part, lot, and serial identifiers, chain of custody, transport and storage records, service and repair history, authenticity or acceptance tests, and tamper inspection. For software, it can include source repository and build identity, dependencies, signed releases, hashes, build or source attestations, and a software bill of materials (SBOM). For associated data, record the source, collection or creation process, transformations, custodians, integrity protection, and version or time period needed for the decision.

Bind the evidence to the exact product, component, release, build, or data set being accepted. Verify signatures and hashes with trusted reference information where applicable. Record gaps and uncertainty: a supplier statement may inform a decision, but it does not provide the same assurance as evidence whose identity, integrity, and relationship to the delivered item can be independently checked.

  • Specify the covered item, required provenance fields, evidence format, signature or verification method, delivery point, retention, and treatment of missing or unverifiable data.
  • Validate provenance before acceptance and after material supplier, component, build, distribution, service, repair, or maintenance changes.
  • Use SBOM data as a complementary input to vulnerability management, supplier assessment, and response. NIST explicitly warns against treating an SBOM as a substitute for those capabilities.
  • Escalate a broken chain, failed verification, unexpected component, or unexplained build difference according to the item's criticality and the risk decision it affects.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix A, SR-4 covers life-cycle provenance and explains the role and limits of SBOMs; the audit guidance addresses identity binding, chain of custody, and traceable supply-chain events.

How should teams handle provenance under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support provenance under NIST SP 800-161 Rev. 1?

Keep the evidence attached to the exact item and version accepted. The record should let a reviewer reconstruct the claimed origin, authorized path, changes, custody, verification, exceptions, and approval decision. Preserve the verification inputs as well as the result; a bare status of 'verified' does not show what was checked.

  • Product/component/release identity, version, supplier, manufacturer or developer, and authorized distribution path.
  • SBOM, build or source attestation, signature/hash verification, custody records, authenticity tests, and inspection results as applicable.
  • Known provenance gaps, affected risk decisions, compensating checks, accountable approver, and reassessment trigger.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix A, SR-4 and the audit-control guidance support item-linked provenance, SBOM use and limits, identity binding, chain of custody, traceable changes, and retained verification records.

How should teams handle supplier incidents under NIST SP 800-161 Rev. 1 supply-chain risk management?

How should teams handle supplier incidents under NIST SP 800-161 Rev. 1 supply-chain risk management?

NIST SP 800-161 Rev. 1 Update 1 says contracts and contract management should define vulnerability, incident, and business-disruption reporting and the parties' roles in response, corrective action, and recovery. Its SR-8 guidance also addresses notification agreements within the supply chain for critical products or services.

NIST SP 800-61 Rev. 3 supplies the incident-response structure: reports are validated, categorized, prioritized, and escalated; investigations establish what happened and preserve records; response activities are coordinated with internal and external stakeholders; incidents are contained and eradicated; and recovery is verified before normal operation is confirmed.

The organization remains responsible for its own decision. A supplier's statement that an incident is contained does not establish the scope or safety of the customer's environment. Determine which product versions, services, credentials, data, systems, customers, and sub-tier providers are affected, then decide what independent validation is needed. If the report remains unconfirmed, preserve that uncertainty, apply proportionate interim controls, and set the next decision time instead of treating silence as closure.

  • Validate and scope: confirm the event, supplier relationship, affected products or services and versions, customer exposure, severity, urgency, and known uncertainty.
  • Coordinate: assign an incident lead and owners for supplier communication, legal and regulatory review, business continuity, technical response, and executive decisions.
  • Notify and share: follow the current legal, regulatory, policy, contractual, and information-sharing rules for content, recipient, channel, timing, and updates.
  • Preserve and analyze: retain incident data, metadata, supplier notices, logs, tickets, images, versions, decisions, and investigation actions with integrity, provenance, and chain of custody when appropriate.
  • Contain, eradicate, and recover: isolate or suspend affected connections or components as authorized, remove persistence and exploited weaknesses, verify restoration assets, and confirm recovery criteria before normal operation.
  • Follow through: document root cause and lessons, track supplier corrective action, reassess criticality and residual risk, and update contracts, monitoring, architecture, inventories, and contingency plans when needed.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 3.1.2 covers contractual reporting and response roles for vulnerabilities, incidents, and business disruptions; Appendix A includes notification agreements and incident-response control guidance.

How should teams handle supplier incidents under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support supplier incidents under NIST SP 800-161 Rev. 1?

Use the evidence-preservation procedures and retention rules in the incident-response plan. NIST SP 800-61 Rev. 3 says incident data and metadata should be collected with their integrity and provenance preserved, while recognizing that formal chain-of-custody handling may not be necessary for every incident.

For a supplier incident, preserve enough evidence to support scope, containment, notification, recovery, and follow-up decisions. Record what the supplier reported, what the organization independently observed, where the accounts differ, what remains unknown, and who accepted any decision made with incomplete information.

  • Scope record: supplier, relationship, product or service and version, affected assets and data, time window, indicators, severity, assumptions, and unresolved questions.
  • Evidence record: original supplier notices, logs, tickets, images, alerts, decisions, investigation actions, access controls, retention, integrity checks, and chain of custody when appropriate.
  • Action record: containment, eradication, recovery, notification, communication, owner, authorization, time, result, and reversal or exit criteria.
  • Closure record: verified restoration, root cause, residual risk, supplier corrective action, contract follow-up, lessons, reassessment owner, and scheduled or event-driven review.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 3.1.2 and Appendix A support supplier reporting, notification agreements, response roles, corrective action, recovery, and contract coordination for supply-chain incidents.

How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?

How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?

Begin with a risk scenario that connects a threat event, vulnerability or exposure, affected supplier, product, service, or supply-chain path, likelihood, and impact. State the time horizon and assumptions. Consider criticality, concentration, substitutability, dependencies, recovery or replacement time, and effects on missions, systems, data, people, other organizations, and the Nation where relevant.

Compare responses against risk appetite and risk tolerance, mission priorities, applicable law and contracts, cost, feasibility, dependencies, and decision authority. Acceptance keeps the identified exposure without further risk-reducing action because the authorized owner judges the remaining risk acceptable. Avoidance removes the activity or exposure. Mitigation changes likelihood or impact through controls. Sharing or transfer reallocates some responsibility or financial consequence through arrangements such as contracts or insurance, but it does not automatically remove operational, mission, legal, or reputational exposure.

Mitigation can include alternate sources, contract changes, added inspection or testing, segmentation, reduced access, patching, inventory buffers, recovery measures, or increased monitoring. State which part of the scenario each action changes and how effectiveness will be measured. Listing controls without that connection does not explain the response.

  • Confirm that the risk statement and assessment are specific enough for a decision and identify uncertainty that could change the result.
  • Document alternatives considered, the selected course, the authority making the decision, and why the residual risk is within that authority's tolerance.
  • Translate the response into funded acquisition, contract, engineering, security, monitoring, and contingency actions with owners, milestones, dependencies, and measures.
  • Escalate risk above tolerance, outside the owner's authority, or aggregated across several systems or missions to the appropriate mission/business or enterprise authority.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 2.3.4 and Appendix G's Respond step cover alternative courses of action, risk response across all three levels, tailored controls, acceptable risk, and documented C-SCRM plans and POA&Ms.

How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support supply chain risk response under NIST SP 800-161 Rev. 1?

The record should preserve the assessed scenario, source information, assumptions, alternatives, selected response, decision authority, residual risk, funded actions, dependencies, effectiveness measures, and current status. Link it to the relevant C-SCRM plan, risk register, system plan, supplier assessment, contract, contingency plan, incident record, or plan of action and milestones (POA&M).

  • Risk scenario, scope, likelihood, impact, criticality, assumptions, and source information.
  • Response options considered, expected effect on likelihood or impact, selected action, accountable authority, residual risk, rationale, and approval date.
  • Action owners, funding and other resources, milestones, dependencies, measures, monitoring signals, escalation threshold, completion evidence, and review triggers.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Appendix G requires decision-makers to receive assessment results, mitigation options, and acceptable-risk information and describes response outputs in C-SCRM plans and POA&Ms.

How should teams handle supply chain risk response under NIST SP 800-161 Rev. 1 supply-chain risk management?

When should supply chain risk response be reviewed again?

Review the response at the planned interval and when a material change could alter likelihood, impact, effectiveness, or decision authority. NIST's Monitor step calls for organization-set review intervals and documented off-cycle triggers, not one universal cadence.

Triggers can include new threat or vulnerability information, an incident, failed control, stale evidence, supplier or product change, ownership change, loss of an alternative source, contract change, changed mission or architecture, audit finding, natural disaster, or resource change. Update the assessment and response rather than recording the trigger without a new decision.

  • Use both a scheduled review and documented off-cycle triggers.
  • Recheck the scenario, alternatives, control effectiveness, residual risk, and authority after a trigger.
  • Close or replace the response only when completion evidence supports the decision and ongoing monitoring has an owner.
  • Preserve the history so reviewers can see why the response changed.
Citations
How should teams handle tiering under NIST SP 800-161 Rev. 1 supply-chain risk management?

How should teams tier suppliers without confusing NIST models?

Create organization-defined supplier categories using consistent criteria. NIST gives strategic/innovative, mission-critical, sustaining, and standard/non-essential as examples, not a required four-tier scale. These supplier groupings focus analysis and treatment; they do not replace a supplier-specific risk assessment. Relevant criteria include mission and system dependency, product or component criticality, access and data sensitivity, concentration and substitutability, geographic and ownership considerations, known threats and vulnerabilities, incident history, and potential business or safety impact. A low-spend sole-source component or service with privileged access can warrant the highest treatment even if the supplier is small.

Use the category to set due-diligence depth, required evidence, contract and flow-down terms, assessment method, monitoring interval and triggers, incident involvement, contingency planning, and approval authority. The category should reflect the dependency and exposure before considering assurance. A strong assessment result does not make a single-source, mission-critical dependency non-critical.

Record separately which risk-management level owns the decision. Level 1 sets enterprise strategy, governance, policy, risk appetite, and enterprise decisions. Level 2 tailors that direction to missions and business processes. Level 3 applies it to systems, procurements, and other operational work. The CSF Tiers describe the organization's broader practices and should not replace either field.

  • Define every category, decision criterion, treatment, exception route, and approver before rating suppliers.
  • Record dependency and exposure separately from assurance, control performance, and residual risk.
  • Use the same facts and criteria for comparable suppliers, while documenting case-specific judgment and missing information.
  • Reclassify after material changes to scope, dependency, access, ownership, location, subcontractors, threats, vulnerabilities, incidents, recovery needs, or available alternatives.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 2.3 defines the enterprise, mission/business, and operational levels; Section 3.1.1 describes organization-defined supplier groupings and their use in prioritization and contract tailoring.

NIST CSF 2.0 (CSWP 29)

CSF 2.0 explains that its four Tiers characterize the rigor of cybersecurity risk governance and management practices and are not maturity levels or supplier ratings.

How should teams handle tiering under NIST SP 800-161 Rev. 1 supply-chain risk management?

What evidence should support tiering under NIST SP 800-161 Rev. 1?

Keep the supplier category and rationale linked to the relationship inventory and the treatment it drives. Separately record the risk-management level that owns the decision and any CSF Tier used to characterize the organization's broader practices. This prevents a label such as 'Tier 2' from silently carrying three different meanings.

  • Supplier, product or service, supported mission and systems, access, data, sub-tier dependencies, recovery needs, and alternatives.
  • Category, criteria scores or narrative rationale, facts and assumptions, missing information, treatment requirements, approver, and exceptions.
  • Owning risk-management level and, if relevant, the separately recorded CSF Tier and reason for using it.
  • Review date and event triggers, plus a history of category, evidence, treatment, and approval changes.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Sections 2.3 and 3.1.1 support separate records for decision ownership, supplier inventory, organization-defined groupings, and treatment based on strategic or operational importance.

Page 1 of 2
Previous12Next