Vendor Register
Regimes ยท SP 800-161

NIST SP 800-161 Rev 1

Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access.

On the register, tick "US federal supply chain (SP 800-161)" and these rows appear on every vendor the regime reaches. Framework page.

Which vendors it reaches

FamiliesCloud and hosting, Software and SaaS, Network and connectivity, Hardware and devices, Managed and professional services, Data and content, Payments and financial, Operations
On every vendorSP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13
Cloud and hostingSP 800-161 SA-9, SP 800-161 AC-20, SP 800-161 CA-3, SP 800-161 IR-6
Software and SaaSSP 800-161 SA-9, SP 800-161 AC-20, SP 800-161 IR-6
Network and connectivitySP 800-161 CP-8, SP 800-161 CA-3, SP 800-161 SA-9
Hardware and devicesSP 800-161 SR-4, SP 800-161 SR-9, SP 800-161 SR-10, SP 800-161 SR-11, SP 800-161 MA-6, SP 800-161 SR-12
Managed and professional servicesSP 800-161 SA-9, SP 800-161 PS-7, SP 800-161 MA-4, SP 800-161 AC-20, SP 800-161 IR-6
Data and contentSP 800-161 SA-9, SP 800-161 CA-3
Payments and financialSP 800-161 SA-9
OperationsSP 800-161 PS-7
Outsourced software developmentSP 800-161 SA-4
Rated critical on the registerSP 800-161 CP-2, SP 800-161 CP-4

NIST SP 800-161 Rev 1, acquisition and notification

The clauses the register expects in every vendor agreement the regime reaches, and the further clauses for a vendor rated critical.

  1. Security and supply chain requirements written into the acquisition, with the evidence the supplier must deliver
  2. Notification agreements: the supplier tells you of compromise, vulnerability and relevant change
  3. Personnel security requirements for the supplier's staff, including notice when someone leaves
  4. Terms for organisational information on the supplier's systems

Where the vendor rated critical on the register

  1. Contingency arrangements for the loss of the supplier, including alternate sources that can deliver
  2. Provenance and authenticity assurances for delivered components

Provenance and the origin finding

The hardware controls (SR-4 provenance, SR-9 tamper resistance, SR-10 inspection, SR-11 authenticity) are the ones the origin finding leans on: a blank country of origin on accelerators, power and cooling modules, network equipment or components is recorded as unconfirmed, and the lists to check are named. Named references only: EAR, the US Export Administration Regulations (the Entity List sits under it); ITAR, the US International Traffic in Arms Regulations.

The clauses, quoted

19 of 191 in the framework

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

SP 800-161 SR-6 Supplier Assessments and Reviews

Assesses and reviews suppliers, at a depth matched to what they supply and the access they hold.

Evidence an auditor accepts: assessment methodology and tiering by criticality; assessment records per supplier; review cycle evidence
Common gap: all suppliers assessed with the same questionnaire
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-8 Notification Agreements

Establishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.

Evidence an auditor accepts: notification clauses with defined triggers and timeframes; evidence of notifications received; escalation route when notification fails
Common gap: notification obligation absent or without a timeframe
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-4 Acquisition Process

Puts security and supply chain requirements into the contract, including the evidence the supplier must provide.

Evidence an auditor accepts: contract templates carrying security and C-SCRM requirements; evidence of requirements in executed contracts; acceptance criteria tied to those requirements
Common gap: requirements in the template but absent from signed contracts
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-13 Supplier Inventory

A control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.

Evidence an auditor accepts: supplier inventory with the systems and components each supports; criticality attached to each supplier; update procedure on supplier change
Common gap: supplier list held by procurement with no link to systems
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-9 External System Services

Governs external service providers across their life cycle, including the security roles each party holds.

Evidence an auditor accepts: inventory of external services; agreements defining security roles and responsibilities; monitoring and assessment evidence
Common gap: responsibilities assumed rather than defined
Source framework: NIST SP 800-161 Rev 1
SP 800-161 AC-20 Use of External Systems

Sets the terms under which organizational information may be processed on supplier and provider systems, and verifies them.

Evidence an auditor accepts: inventory of external systems used by suppliers for organizational data; agreements setting the security terms; verification evidence such as assessment or attestation
Common gap: supplier subcontracts processing with no notification
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CA-3 Information Exchange

Governs the connections and exchanges between the organization and its suppliers, integrators and providers.

Evidence an auditor accepts: inventory of supply chain exchanges and connections; agreements documenting each; technical protections and review records
Common gap: connections established for a project and never decommissioned
Source framework: NIST SP 800-161 Rev 1
SP 800-161 IR-6 Incident Reporting

Reports supply chain incidents to the parties who need to know, including other users of the same supplier or component.

Evidence an auditor accepts: reporting thresholds and recipients including external bodies; records of reports made; evidence of onward notification where required
Common gap: reporting obligations to sector bodies unidentified
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-8 Telecommunications Services

Addresses dependence on telecommunications suppliers, including shared upstream carriers behind nominally separate services.

Evidence an auditor accepts: service arrangements with named carriers; analysis of shared upstream infrastructure; priority service arrangements where applicable
Common gap: two circuits from different resellers share one physical path
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-4 Provenance

Establishes and maintains provenance for systems, components and associated data so origin and change history are known.

Evidence an auditor accepts: provenance records for critical components; evidence of origin and chain of custody; update of provenance as components change
Common gap: provenance known only as far as the reseller
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-9 Tamper Resistance and Detection

Applies tamper resistance and detection to components across development, transport and operation.

Evidence an auditor accepts: tamper resistance and detection measures in use; inspection procedures and records; handling of components found tampered with
Common gap: tamper evidence applied but never inspected on receipt
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-10 Inspection of Systems or Components

Inspects systems and components at defined points to detect tampering, substitution or counterfeit.

Evidence an auditor accepts: inspection procedure and the points at which it applies; inspection records with results; criteria for what constitutes a failed inspection
Common gap: inspection performed only when something looks wrong
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-11 Component Authenticity

Establishes an anti-counterfeit policy and the means to detect and report counterfeit components.

Evidence an auditor accepts: anti-counterfeit policy and procedures; authenticity verification methods used; records of suspected counterfeits and their reporting
Common gap: authenticity assumed because the reseller is authorized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-6 Timely Maintenance

Secures the spares and supplier support needed to restore critical components within the time the organization can tolerate.

Evidence an auditor accepts: spares holdings or supply agreements for critical components; support response commitments and their evidence; criticality analysis driving the requirement
Common gap: support commitments assumed rather than contracted
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-12 Component Disposal

Disposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.

Evidence an auditor accepts: disposal procedure covering data and physical component; disposal records with serial numbers; controls preventing resale of components carrying organizational identity
Common gap: components sold on with organizational markings intact
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PS-7 External Personnel Security

Sets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.

Evidence an auditor accepts: requirements imposed on providers; notification obligations for personnel change and their evidence; records of access removed on notification
Common gap: provider does not notify departures so access lingers
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-4 Nonlocal Maintenance

Governs remote maintenance performed by suppliers, which is where most supplier technical access actually occurs.

Evidence an auditor accepts: approval records per remote maintenance session; authentication and monitoring evidence; termination of access after the session
Common gap: permanent vendor tunnels rather than session enablement
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-2 Contingency Plan

Plans for continued operation when a critical supplier, integrator or component source becomes unavailable.

Evidence an auditor accepts: contingency plan with supplier failure scenarios; identification of critical suppliers and single points of failure; alternate sourcing arrangements
Common gap: plan lists systems but not the suppliers that keep them running
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-4 Contingency Plan Testing

Tests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.

Evidence an auditor accepts: test plan including supplier failure scenarios; test results and lessons; evidence alternate sources were contacted or validated
Common gap: alternate supplier named but never approached
Source framework: NIST SP 800-161 Rev 1

See what it attaches to your list

Paste the vendor list, tick the regime, and every vendor it reaches carries these rows. Eight vendors free, no account.

Build my vendor register