Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cybersecurity Supply Chain Risk Management C-SCRM

Contacting the NIST C-SCRM Team


How Can We Help?

 

The most common reasons users contact the NIST Cybersecurity Supply Chain Risk Management (C-SCRM) team are to:

 

Request more information about C-SCRM technical documents (e.g., clarifying a concept from a Special Publication (SP) such as Cybersecurity Supply Chain Risk Management for Systems and Organizations [SP 800-161 Revision 1]).  

Questions and comments about Cybersecurity Supply Chain Risk Management (C-SCRM) are always welcome and can be directed to [email protected].

 

Join a C-SCRM E-mail Listserv. The following Listservs are available:

  1. Federal C-SCRM Forum Email Listserv - for federal, state, and local government employees whose job includes C-SCRM responsibilities to share information and ask questions about privacy and security issues.

 

  1. The Federal Cybersecurity and Privacy Professionals Forum Listserv - for members of U.S. federal, state, and local government, and higher education organizations to share of cybersecurity and privacy knowledge, best practices, and resources. 

 

  1. Software Assurance Google Group - an open to the public Google Group for sharing information on the Software and Supply Chain Assurance (SSCA) Forum and other related events. 

 

Inquire about a member of the C-SCRM team speaking at an event.  To contact the NIST C-SCRM team about speaking at your organization's event, use our Speaker Request Form

 

Suggest a topic for an upcoming Software and Supply Chain Assurance (SSCA) Forum. The SSCA Forum allows government, industry, and academic participants from around the world to share their knowledge and expertise regarding software and supply chain risks.  It occurs 2-3 times a year, is free, and is open to the public. To suggest a topic for the Forum, use the SSCA Topic Suggestion Form

 

Submit public comments on initial versions of C-SCRM publications called initial public drafts (ipd). 

 

When a public comment period for a C-SCRM publication is open, instructions for providing feedback on it will be listed in the "Status" column of the table below.

 

The following C-SCRM guidance documents are in progress: 

Status of C-SCRM Guidance Publications in Progress
Title Series & Number Public Comment Period Status
NICE Workforce Framework for Cybersecurity N/A CLOSED

Reviewing feedback from the public comment period.

Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities Special Publication (SP) 800-218 Revision 1 CLOSED

Reviewing feedback from the public comment period. 

NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick Start Guide  SP 1326 CLOSED Final version released July 8th, 2026. 
Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems SP 800-18 Revision 2 CLOSED

Final version released June 30th, 2026.

 

Created May 24, 2016, Updated September 03, 2026