How should teams tier suppliers without confusing NIST models?
Create organization-defined supplier categories using consistent criteria. NIST gives strategic/innovative, mission-critical, sustaining, and standard/non-essential as examples, not a required four-tier scale. These focus analysis and treatment; they do not replace a supplier-specific risk assessment. Relevant criteria include mission and system dependency, product or component criticality, access and data sensitivity, concentration and substitutability, geographic and ownership considerations, known threats and vulnerabilities, incident history, and potential business or safety impact. A low-spend sole-source component or service with privileged access can warrant the highest treatment even if the supplier is small.
Use the category to set due-diligence depth, required evidence, contract and flow-down terms, assessment method, monitoring interval and triggers, incident involvement, contingency planning, and approval authority. The category should reflect the dependency and exposure before considering assurance. A strong assessment result does not make a single-source, mission-critical dependency non-critical.
Record separately which risk-management level owns the decision. Level 1 sets enterprise strategy, governance, policy, risk appetite, and enterprise decisions. Level 2 tailors that direction to missions and business processes. Level 3 applies it to systems, procurements, and other operational work. The describe the organization's broader practices and should not replace either field.
- Define every category, decision criterion, treatment, exception route, and approver before rating suppliers.
- Record dependency and exposure separately from assurance, control performance, and residual risk.
- Use the same facts and criteria for comparable suppliers, while documenting case-specific judgment and missing information.
- Reclassify after material changes to scope, dependency, access, ownership, location, subcontractors, threats, vulnerabilities, incidents, recovery needs, or available alternatives.
Section 2.3 defines the enterprise, mission/business, and operational levels; Section 3.1.1 describes organization-defined supplier groupings and their use in prioritization and contract tailoring.
CSF 2.0 explains that its four Tiers characterize the rigor of cybersecurity risk governance and management practices and are not maturity levels or supplier ratings.