NIST SP 800-161 Rev 1
Rendered when the buyer ticks "US federal supply chain (SP 800-161)". The register cites 26 of its 191 clauses, behind 8 findings: single-source vendors with no fallback named, concentration at or above the threshold, hardware with an unconfirmed country of origin, contracts ending inside 90 days with no re-tender noted, critical vendors with no contract end recorded, nis2 supplier assessment not evidenced, cloud services with no exit plan, sub-outsourcing chains longer than one hop, and on the obligation rows of every vendor it reaches.
Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches to a vendor: the SP 800-161 regime page.
Clauses cited
26 of 191SP 800-161 SR-13 Supplier InventoryA control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.
Common gap: supplier list held by procurement with no link to systems
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-2 Supply Chain Risk Management PlanRequires a plan for managing supply chain risk for the system, reviewed and updated and protected from disclosure.
Common gap: one generic plan reused for every system
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-1 Policy and ProceduresEstablishes the supply chain risk management policy and procedures that the rest of the SR family operates under.
Common gap: policy exists with no procedures behind it
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-3 Supply Chain Controls and ProcessesEstablishes the processes that identify and address supply chain risk for the system, in coordination with its suppliers.
Common gap: processes defined centrally and unused by the projects
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PM-30 Supply Chain Risk Management StrategySets the organizational C-SCRM strategy and implementation plan that everything else in the programme derives from.
Common gap: strategy written once and never operationalized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 RA-3 Risk AssessmentAssesses supply chain risk across the enterprise, mission and system levels, and keeps it current.
Common gap: one assessment covering all suppliers equally
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-5 Acquisition Strategies, Tools, and MethodsUses acquisition strategy, contract tools and purchasing methods to reduce supply chain risk before it enters the organization.
Common gap: one purchasing approach for critical and trivial alike
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PL-8 Security and Privacy ArchitecturesBuilds supply chain considerations into architecture, including diversity, provenance and the ability to replace a supplier.
Common gap: architecture locks the organization to a single supplier with no analysis
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-2 Contingency PlanPlans for continued operation when a critical supplier, integrator or component source becomes unavailable.
Common gap: plan lists systems but not the suppliers that keep them running
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-8 Telecommunications ServicesAddresses dependence on telecommunications suppliers, including shared upstream carriers behind nominally separate services.
Common gap: two circuits from different resellers share one physical path
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-4 ProvenanceEstablishes and maintains provenance for systems, components and associated data so origin and change history are known.
Common gap: provenance known only as far as the reseller
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-11 Component AuthenticityEstablishes an anti-counterfeit policy and the means to detect and report counterfeit components.
Common gap: authenticity assumed because the reseller is authorized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-10 Inspection of Systems or ComponentsInspects systems and components at defined points to detect tampering, substitution or counterfeit.
Common gap: inspection performed only when something looks wrong
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-6 Supplier Assessments and ReviewsAssesses and reviews suppliers, at a depth matched to what they supply and the access they hold.
Common gap: all suppliers assessed with the same questionnaire
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-9 External System ServicesGoverns external service providers across their life cycle, including the security roles each party holds.
Common gap: responsibilities assumed rather than defined
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-8 Notification AgreementsEstablishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.
Common gap: notification obligation absent or without a timeframe
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-4 Acquisition ProcessPuts security and supply chain requirements into the contract, including the evidence the supplier must provide.
Common gap: requirements in the template but absent from signed contracts
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-4 Contingency Plan TestingTests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.
Common gap: alternate supplier named but never approached
Source framework: NIST SP 800-161 Rev 1
SP 800-161 AC-20 Use of External SystemsSets the terms under which organizational information may be processed on supplier and provider systems, and verifies them.
Common gap: supplier subcontracts processing with no notification
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CA-3 Information ExchangeGoverns the connections and exchanges between the organization and its suppliers, integrators and providers.
Common gap: connections established for a project and never decommissioned
Source framework: NIST SP 800-161 Rev 1
SP 800-161 IR-6 Incident ReportingReports supply chain incidents to the parties who need to know, including other users of the same supplier or component.
Common gap: reporting obligations to sector bodies unidentified
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-9 Tamper Resistance and DetectionApplies tamper resistance and detection to components across development, transport and operation.
Common gap: tamper evidence applied but never inspected on receipt
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-6 Timely MaintenanceSecures the spares and supplier support needed to restore critical components within the time the organization can tolerate.
Common gap: support commitments assumed rather than contracted
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-12 Component DisposalDisposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.
Common gap: components sold on with organizational markings intact
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PS-7 External Personnel SecuritySets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.
Common gap: provider does not notify departures so access lingers
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-4 Nonlocal MaintenanceGoverns remote maintenance performed by suppliers, which is where most supplier technical access actually occurs.
Common gap: permanent vendor tunnels rather than session enablement
Source framework: NIST SP 800-161 Rev 1
See which clauses your list engages
Paste the list and every vendor names the clauses behind it, filtered to the regimes that apply to you. Eight vendors free, no account.
Build my vendor register