Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cybersecurity Supply Chain Risk Management C-SCRM

NIST-Sponsored Research

NIST regularly conducts and awards contracts, grants, or cooperative agreements to conduct research into cybersecurity supply chain risk management (C-SCRM) and related topics. The following are relevant research activities:


Cyber Risk Analytics: A NIST and GSA-Sponsored grant from 2015-2017 examining the relationship between various risk management practices and publicly disclosed breaches.

Industry C-SCRM Best Practices: Ongoing work developing case studies exploring effective risk management practices used by various industry organizations. 

Cyber Risk Portal: An Enterprise Risk Assessment Application developed by the University of Maryland from grants awarded in 2010 and 2012.

C-SCRM Environmental Scan: From a grant awarded in 2010, the University of Maryland researched existing standards documents related to SCRM.


To submit a grant / cooperative agreement proposal, please see


Supply Chain General Inquiries

Jon Boyens - Project Lead - NIST

Rebecca McWhite - Technical Lead - NIST

Jeff Brewer - NIST

sw.assurance Google Group

Created May 24, 2016, Updated May 06, 2024