NIST SP 800-161 Rev 1
Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access.
On the register, tick "US federal supply chain (SP 800-161)" and these rows appear on every vendor the regime reaches. Framework page.
Which vendors it reaches
| Families | Cloud and hosting, Software and SaaS, Network and connectivity, Hardware and devices, Managed and professional services, Data and content, Payments and financial, Operations |
|---|---|
| On every vendor | SP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13 |
| Cloud and hosting | SP 800-161 SA-9, SP 800-161 AC-20, SP 800-161 CA-3, SP 800-161 IR-6 |
| Software and SaaS | SP 800-161 SA-9, SP 800-161 AC-20, SP 800-161 IR-6 |
| Network and connectivity | SP 800-161 CP-8, SP 800-161 CA-3, SP 800-161 SA-9 |
| Hardware and devices | SP 800-161 SR-4, SP 800-161 SR-9, SP 800-161 SR-10, SP 800-161 SR-11, SP 800-161 MA-6, SP 800-161 SR-12 |
| Managed and professional services | SP 800-161 SA-9, SP 800-161 PS-7, SP 800-161 MA-4, SP 800-161 AC-20, SP 800-161 IR-6 |
| Data and content | SP 800-161 SA-9, SP 800-161 CA-3 |
| Payments and financial | SP 800-161 SA-9 |
| Operations | SP 800-161 PS-7 |
| Outsourced software development | SP 800-161 SA-4 |
| Rated critical on the register | SP 800-161 CP-2, SP 800-161 CP-4 |
NIST SP 800-161 Rev 1, acquisition and notification
The clauses the register expects in every vendor agreement the regime reaches, and the further clauses for a vendor rated critical.
- Security and supply chain requirements written into the acquisition, with the evidence the supplier must deliver
- Notification agreements: the supplier tells you of compromise, vulnerability and relevant change
- Personnel security requirements for the supplier's staff, including notice when someone leaves
- Terms for organisational information on the supplier's systems
Where the vendor rated critical on the register
- Contingency arrangements for the loss of the supplier, including alternate sources that can deliver
- Provenance and authenticity assurances for delivered components
Provenance and the origin finding
The hardware controls (SR-4 provenance, SR-9 tamper resistance, SR-10 inspection, SR-11 authenticity) are the ones the origin finding leans on: a blank country of origin on accelerators, power and cooling modules, network equipment or components is recorded as unconfirmed, and the lists to check are named. Named references only: EAR, the US Export Administration Regulations (the Entity List sits under it); ITAR, the US International Traffic in Arms Regulations.
The clauses, quoted
19 of 191 in the frameworkRequirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
SP 800-161 SR-6 Supplier Assessments and ReviewsAssesses and reviews suppliers, at a depth matched to what they supply and the access they hold.
Common gap: all suppliers assessed with the same questionnaire
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-8 Notification AgreementsEstablishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.
Common gap: notification obligation absent or without a timeframe
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-4 Acquisition ProcessPuts security and supply chain requirements into the contract, including the evidence the supplier must provide.
Common gap: requirements in the template but absent from signed contracts
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-13 Supplier InventoryA control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.
Common gap: supplier list held by procurement with no link to systems
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-9 External System ServicesGoverns external service providers across their life cycle, including the security roles each party holds.
Common gap: responsibilities assumed rather than defined
Source framework: NIST SP 800-161 Rev 1
SP 800-161 AC-20 Use of External SystemsSets the terms under which organizational information may be processed on supplier and provider systems, and verifies them.
Common gap: supplier subcontracts processing with no notification
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CA-3 Information ExchangeGoverns the connections and exchanges between the organization and its suppliers, integrators and providers.
Common gap: connections established for a project and never decommissioned
Source framework: NIST SP 800-161 Rev 1
SP 800-161 IR-6 Incident ReportingReports supply chain incidents to the parties who need to know, including other users of the same supplier or component.
Common gap: reporting obligations to sector bodies unidentified
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-8 Telecommunications ServicesAddresses dependence on telecommunications suppliers, including shared upstream carriers behind nominally separate services.
Common gap: two circuits from different resellers share one physical path
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-4 ProvenanceEstablishes and maintains provenance for systems, components and associated data so origin and change history are known.
Common gap: provenance known only as far as the reseller
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-9 Tamper Resistance and DetectionApplies tamper resistance and detection to components across development, transport and operation.
Common gap: tamper evidence applied but never inspected on receipt
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-10 Inspection of Systems or ComponentsInspects systems and components at defined points to detect tampering, substitution or counterfeit.
Common gap: inspection performed only when something looks wrong
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-11 Component AuthenticityEstablishes an anti-counterfeit policy and the means to detect and report counterfeit components.
Common gap: authenticity assumed because the reseller is authorized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-6 Timely MaintenanceSecures the spares and supplier support needed to restore critical components within the time the organization can tolerate.
Common gap: support commitments assumed rather than contracted
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-12 Component DisposalDisposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.
Common gap: components sold on with organizational markings intact
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PS-7 External Personnel SecuritySets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.
Common gap: provider does not notify departures so access lingers
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-4 Nonlocal MaintenanceGoverns remote maintenance performed by suppliers, which is where most supplier technical access actually occurs.
Common gap: permanent vendor tunnels rather than session enablement
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-2 Contingency PlanPlans for continued operation when a critical supplier, integrator or component source becomes unavailable.
Common gap: plan lists systems but not the suppliers that keep them running
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-4 Contingency Plan TestingTests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.
Common gap: alternate supplier named but never approached
Source framework: NIST SP 800-161 Rev 1
See what it attaches to your list
Paste the vendor list, tick the regime, and every vendor it reaches carries these rows. Eight vendors free, no account.
Build my vendor register