NIST SP 800-161 Rev. 1 · C-SCRM
The American framework reaches you through the contract, not the statute.
Supplying US agencies or their contractors means finding cyber supply chain requirements in your contracts – written in NIST language.
The publication describes practices for cybersecurity supply chain risk management. It addresses US federal agencies but reaches much further: contractors pass the requirements down, and many corporations have adopted them into their own supplier programmes.
Much overlaps with ISO/IEC 27001 and the Cyber Resilience Act – component provenance, integrity of delivery, vulnerability handling. The difference lies in granularity and vocabulary: working to ISO means translating your evidence, not creating it anew.
Who encounters it
- Suppliers to companies holding US government contracts.
- Software and hardware vendors drawn into US procurement.
- European subsidiaries of US corporations with group-wide rules.
- Vendors required to evidence component provenance.
What it comes down to
- Programme
- A distinct C-SCRM programme with ownership and anchoring in procurement.
- Criticality
- Determine which components and suppliers are critical.
- Provenance
- Understand where components come from and who could have altered them.
- Contract
- Anchor security requirements, notification duties and audit rights contractually.
- Monitoring
- Observe suppliers continuously rather than assessing them at signature.
How SCRM covers it
One record, several frameworks
The same supplier data serves ISO 27001, the CRA and NIST – only the view differs.
Component provenance
Vendor per part or library, with location and upstream supplier.
Contract attributes
Notification duties and audit rights as checked fields with expiry.
Continuous assessment
Recurring review cycles instead of one-off approval.
Frequently asked
Must we apply it if we do not ship to the US?
Not as a duty. Once a customer sits in a US supply chain, the requirements arrive as contract clauses.
Is ISO 27001 enough?
Largely, but not identical. NIST goes further on component provenance and integrity; ISO is stronger on the management system.
What about CMMC?
A separate certification model for US defence supply chains built on related requirements. Suppliers there should assess it specifically.