FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
17of17items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Which contract controls should teams define under NIST SP 800-161 Rev. 1?

What contract controls should teams include in supplier agreements?

NIST says acquisition teams should select relevant C-SCRM controls with the mission or business owner, security personnel, technical experts, and procurement officials. Contractual agreements and contract management should address applicable security requirements, relevant subcontractor flow-down, periodic revalidation, vulnerability and incident reporting, and the parties' response and recovery roles.

Write each requirement so performance can be inspected. State the covered product or service, required result, evidence, delivery frequency, responsible party, permitted deviations, corrective-action process, and available remedies. Certifications, site visits, third-party assessments, and self-attestations are examples of validation methods; NIST says their rigor should match the criticality and assurance needs of the acquisition.

The control identifiers below are useful starting points from the publication's C-SCRM control catalog, not clauses that every agreement must contain. Tailor them to the supplier's span of control and check the acquisition rules, mandatory clauses, and sector requirements that apply to the transaction.

  • Access and personnel: identify approved users and access paths, account lifecycle rules, remote-access conditions, training, and return or revocation duties.
  • Traceability and change: require inventories, approved changes, component or release identity, provenance where needed, logging, record retention, and notice of material product or service changes.
  • Assessment and monitoring: define the evidence, assessment rights, revalidation interval, off-cycle triggers, findings process, and deadline for corrective action.
  • Subcontractors: identify which requirements require flow-down, which sub-tier relationships require notice or approval, and how the prime will verify conformance.
  • Vulnerabilities and incidents: define reportable events, notification channel, content, timing, updates, evidence preservation, coordination, containment, recovery, and post-incident review.
  • Continuity and exit: set recovery participation, alternate-source or transition support, data return or destruction, component disposal, and termination rights when risk cannot be reduced to an acceptable level.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 3.1.2 describes acquisition-team roles, contract and contract-management topics, risk-based validation methods, monitoring during performance, and termination provisions; Appendix A identifies C-SCRM controls and relevant flow-down guidance.

Which contract controls should teams define under NIST SP 800-161 Rev. 1?

What evidence should support contract controls under NIST SP 800-161 Rev. 1?

Keep a clause-to-evidence record for the full period of performance. A signed agreement proves that a term exists; it does not prove that the supplier performs it. The contract owner and control owner should be able to trace each material requirement to current evidence, findings, exceptions, corrective actions, and the decision to continue, escalate, or terminate.

  • Requirement record: clause, covered deliverable or service, supplier and sub-tier scope, source risk decision, and responsible contract and control owners.
  • Verification record: expected artifact or test, acceptance criteria, review date, reviewer, result, and any limitation in the evidence.
  • Exception record: unmet requirement, affected risk, compensating measure, authorized decision, corrective-action owner, due date, and escalation threshold.
  • Review record: scheduled revalidation plus off-cycle triggers such as an incident, vulnerability, ownership change, service change, failed test, or stale evidence.
  • Closeout record: confirmed access revocation, data return or destruction, retained records, component disposition, and transition or continuity actions.
Citations
NIST SP 800-161 Rev. 1 Update 1 C-SCRM

Section 3.1.2 calls for periodic supplier revalidation and risk-based validation methods; the Monitor step covers compliance, effectiveness, change, regular review intervals, and off-cycle reassessment triggers.

Page 2 of 2