Vendor Register
Standards ยท SP 800-161

NIST SP 800-161 Rev 1

Rendered when the buyer ticks "US federal supply chain (SP 800-161)". The register cites 26 of its 191 clauses, behind 8 findings: single-source vendors with no fallback named, concentration at or above the threshold, hardware with an unconfirmed country of origin, contracts ending inside 90 days with no re-tender noted, critical vendors with no contract end recorded, nis2 supplier assessment not evidenced, cloud services with no exit plan, sub-outsourcing chains longer than one hop, and on the obligation rows of every vendor it reaches.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches to a vendor: the SP 800-161 regime page.

Clauses cited

26 of 191
SP 800-161 SR-13 Supplier Inventory

A control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.

Evidence an auditor accepts: supplier inventory with the systems and components each supports; criticality attached to each supplier; update procedure on supplier change
Common gap: supplier list held by procurement with no link to systems
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-2 Supply Chain Risk Management Plan

Requires a plan for managing supply chain risk for the system, reviewed and updated and protected from disclosure.

Evidence an auditor accepts: system-level C-SCRM plan; review and update records; protection and access control on the plan
Common gap: one generic plan reused for every system
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-1 Policy and Procedures

Establishes the supply chain risk management policy and procedures that the rest of the SR family operates under.

Evidence an auditor accepts: C-SCRM policy with approval and scope; procedures implementing it; named roles and responsibilities
Common gap: policy exists with no procedures behind it
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-3 Supply Chain Controls and Processes

Establishes the processes that identify and address supply chain risk for the system, in coordination with its suppliers.

Evidence an auditor accepts: defined supply chain processes for the system; evidence of coordination with suppliers; records of risks identified and addressed
Common gap: processes defined centrally and unused by the projects
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PM-30 Supply Chain Risk Management Strategy

Sets the organizational C-SCRM strategy and implementation plan that everything else in the programme derives from.

Evidence an auditor accepts: C-SCRM strategy with objectives and scope; implementation plan with owners and milestones; review and update records
Common gap: strategy written once and never operationalized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 RA-3 Risk Assessment

Assesses supply chain risk across the enterprise, mission and system levels, and keeps it current.

Evidence an auditor accepts: supply chain risk assessments at each level; methodology covering supplier, component and process risk; update evidence on change
Common gap: one assessment covering all suppliers equally
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-5 Acquisition Strategies, Tools, and Methods

Uses acquisition strategy, contract tools and purchasing methods to reduce supply chain risk before it enters the organization.

Evidence an auditor accepts: acquisition strategies differentiated by criticality; contract tools and clauses in use; evidence of application in real purchases
Common gap: one purchasing approach for critical and trivial alike
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PL-8 Security and Privacy Architectures

Builds supply chain considerations into architecture, including diversity, provenance and the ability to replace a supplier.

Evidence an auditor accepts: architecture artefacts addressing supplier dependency and diversity; analysis of substitutability for critical components; architecture decision records
Common gap: architecture locks the organization to a single supplier with no analysis
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-2 Contingency Plan

Plans for continued operation when a critical supplier, integrator or component source becomes unavailable.

Evidence an auditor accepts: contingency plan with supplier failure scenarios; identification of critical suppliers and single points of failure; alternate sourcing arrangements
Common gap: plan lists systems but not the suppliers that keep them running
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-8 Telecommunications Services

Addresses dependence on telecommunications suppliers, including shared upstream carriers behind nominally separate services.

Evidence an auditor accepts: service arrangements with named carriers; analysis of shared upstream infrastructure; priority service arrangements where applicable
Common gap: two circuits from different resellers share one physical path
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-4 Provenance

Establishes and maintains provenance for systems, components and associated data so origin and change history are known.

Evidence an auditor accepts: provenance records for critical components; evidence of origin and chain of custody; update of provenance as components change
Common gap: provenance known only as far as the reseller
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-11 Component Authenticity

Establishes an anti-counterfeit policy and the means to detect and report counterfeit components.

Evidence an auditor accepts: anti-counterfeit policy and procedures; authenticity verification methods used; records of suspected counterfeits and their reporting
Common gap: authenticity assumed because the reseller is authorized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-10 Inspection of Systems or Components

Inspects systems and components at defined points to detect tampering, substitution or counterfeit.

Evidence an auditor accepts: inspection procedure and the points at which it applies; inspection records with results; criteria for what constitutes a failed inspection
Common gap: inspection performed only when something looks wrong
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-6 Supplier Assessments and Reviews

Assesses and reviews suppliers, at a depth matched to what they supply and the access they hold.

Evidence an auditor accepts: assessment methodology and tiering by criticality; assessment records per supplier; review cycle evidence
Common gap: all suppliers assessed with the same questionnaire
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-9 External System Services

Governs external service providers across their life cycle, including the security roles each party holds.

Evidence an auditor accepts: inventory of external services; agreements defining security roles and responsibilities; monitoring and assessment evidence
Common gap: responsibilities assumed rather than defined
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-8 Notification Agreements

Establishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.

Evidence an auditor accepts: notification clauses with defined triggers and timeframes; evidence of notifications received; escalation route when notification fails
Common gap: notification obligation absent or without a timeframe
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-4 Acquisition Process

Puts security and supply chain requirements into the contract, including the evidence the supplier must provide.

Evidence an auditor accepts: contract templates carrying security and C-SCRM requirements; evidence of requirements in executed contracts; acceptance criteria tied to those requirements
Common gap: requirements in the template but absent from signed contracts
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-4 Contingency Plan Testing

Tests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.

Evidence an auditor accepts: test plan including supplier failure scenarios; test results and lessons; evidence alternate sources were contacted or validated
Common gap: alternate supplier named but never approached
Source framework: NIST SP 800-161 Rev 1
SP 800-161 AC-20 Use of External Systems

Sets the terms under which organizational information may be processed on supplier and provider systems, and verifies them.

Evidence an auditor accepts: inventory of external systems used by suppliers for organizational data; agreements setting the security terms; verification evidence such as assessment or attestation
Common gap: supplier subcontracts processing with no notification
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CA-3 Information Exchange

Governs the connections and exchanges between the organization and its suppliers, integrators and providers.

Evidence an auditor accepts: inventory of supply chain exchanges and connections; agreements documenting each; technical protections and review records
Common gap: connections established for a project and never decommissioned
Source framework: NIST SP 800-161 Rev 1
SP 800-161 IR-6 Incident Reporting

Reports supply chain incidents to the parties who need to know, including other users of the same supplier or component.

Evidence an auditor accepts: reporting thresholds and recipients including external bodies; records of reports made; evidence of onward notification where required
Common gap: reporting obligations to sector bodies unidentified
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-9 Tamper Resistance and Detection

Applies tamper resistance and detection to components across development, transport and operation.

Evidence an auditor accepts: tamper resistance and detection measures in use; inspection procedures and records; handling of components found tampered with
Common gap: tamper evidence applied but never inspected on receipt
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-6 Timely Maintenance

Secures the spares and supplier support needed to restore critical components within the time the organization can tolerate.

Evidence an auditor accepts: spares holdings or supply agreements for critical components; support response commitments and their evidence; criticality analysis driving the requirement
Common gap: support commitments assumed rather than contracted
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-12 Component Disposal

Disposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.

Evidence an auditor accepts: disposal procedure covering data and physical component; disposal records with serial numbers; controls preventing resale of components carrying organizational identity
Common gap: components sold on with organizational markings intact
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PS-7 External Personnel Security

Sets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.

Evidence an auditor accepts: requirements imposed on providers; notification obligations for personnel change and their evidence; records of access removed on notification
Common gap: provider does not notify departures so access lingers
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-4 Nonlocal Maintenance

Governs remote maintenance performed by suppliers, which is where most supplier technical access actually occurs.

Evidence an auditor accepts: approval records per remote maintenance session; authentication and monitoring evidence; termination of access after the session
Common gap: permanent vendor tunnels rather than session enablement
Source framework: NIST SP 800-161 Rev 1

See which clauses your list engages

Paste the list and every vendor names the clauses behind it, filtered to the regimes that apply to you. Eight vendors free, no account.

Build my vendor register