What should teams do about counterfeit risk under NIST SP 800-161 Rev. 1?
Use criticality analysis to identify the systems and components where counterfeit or tampered items could create unacceptable mission, safety, availability, confidentiality, or integrity impact. NIST's SR-11 guidance calls for coordinated anti-counterfeit policies and procedures and, where appropriate, qualified bidder or manufacturer lists and authorized suppliers. SR-11(3) says enterprises should conduct anti-counterfeit scanning for critical components at a minimum.
Prevention also includes tamper resistance and detection for critical components (SR-9), inspection before use and periodically afterward (SR-10), controlled service and repair (SR-11(2)), and contract flow-down where relevant. The organization must still tailor methods to the item and threat; the publication does not prescribe a single test, universal reporting destination, certification, or fixed inspection frequency for every organization.
Obsolete parts are a common borderline case. NIST's telecommunications example considers an original component that is no longer produced, a costly redesign, and purchases from the secondary market. The example uses trained physical inspection, digital imaging, signature and serial or part-number verification, sample electrical testing, design redundancy, and alternative vetted sources. These are illustrative controls, not a universal checklist or proof that every secondary-market item is counterfeit.
When authenticity is in doubt, stop the item from entering or remaining in production until the authorized decision-maker resolves its status. Follow applicable legal, regulatory, contractual, safety, evidence-handling, and reporting procedures rather than assuming that one NIST process fits every sector.
- Before purchase: record criticality, approved sources, manufacturer and distributor identity, required traceability, inspection or test criteria, and relevant flow-down terms.
- At receipt and before use: match the delivered item to purchase, part, lot, serial, custody, packaging, signature, inspection, and acceptance records appropriate to the item.
- On suspicion: segregate the item, prevent installation or further distribution, preserve records and chain of custody when required, investigate related lots and systems, and use the organization's required reporting channel.
- After disposition: record the authenticity decision, removal or replacement, supplier corrective action, affected inventory and systems, alternative sources, and the updated supplier and continuity risk.
Appendix A, SR-9 through SR-11 cover tamper controls, inspection, component authenticity, coordinated anti-counterfeit procedures, qualified sources, service and repair, and scanning for critical components.