The most common reasons users contact the NIST Cybersecurity Supply Chain Risk Management (C-SCRM) team are to:
Request more information about C-SCRM technical documents (e.g., clarifying a concept from a Special Publication (SP) such as Cybersecurity Supply Chain Risk Management for Systems and Organizations [SP 800-161 Revision 1]).
Questions and comments about Cybersecurity Supply Chain Risk Management (C-SCRM) are always welcome and can be directed to [email protected].
Join a C-SCRM E-mail Listserv. The following Listservs are available:
Inquire about a member of the C-SCRM team speaking at an event. To contact the NIST C-SCRM team about speaking at your organization's event, use our Speaker Request Form.
Suggest a topic for an upcoming Software and Supply Chain Assurance (SSCA) Forum. The SSCA Forum allows government, industry, and academic participants from around the world to share their knowledge and expertise regarding software and supply chain risks. It occurs 2-3 times a year, is free, and is open to the public. To suggest a topic for the Forum, use the SSCA Topic Suggestion Form.
Submit public comments on initial versions of C-SCRM publications called initial public drafts (ipd).
When a public comment period for a C-SCRM publication is open, instructions for providing feedback on it will be listed in the "Status" column of the table below.
The following C-SCRM guidance documents are in progress:
| Title | Series & Number | Public Comment Period | Status |
|---|---|---|---|
| NICE Workforce Framework for Cybersecurity | N/A | CLOSED |
Reviewing feedback from the public comment period. |
| Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities | Special Publication (SP) 800-218 Revision 1 | CLOSED |
Reviewing feedback from the public comment period. |
| NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick Start Guide | SP 1326 | CLOSED | Final version released July 8th, 2026. |
| Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems | SP 800-18 Revision 2 | CLOSED |
Final version released June 30th, 2026. |
Security and Privacy: controls assessment, cybersecurity supply chain risk management, information sharing, malware, risk assessment, security controls, security measurement, security programs & operations, systems security engineering, vulnerability management
Technologies: cloud & virtualization, hardware, software & firmware
Applications: communications & wireless, cybersecurity framework
Laws and Regulations: Comprehensive National Cybersecurity Initiative, Cybersecurity Enhancement Act, Cybersecurity Strategy and Implementation Plan, Cyberspace Policy Review, Executive Order 13636, Federal Acquisition Regulation, Federal Information Security Modernization Act, Homeland Security Presidential Directive 12, OMB Circular A-130