Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 1326

NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide

Date Published: July 2026

Author(s)

National Institute of Standards and Technology

Abstract

Keywords

cybersecurity supply chain risk management; due diligence; C-SCRM
Control Families

Risk Assessment; Supply Chain Risk Management

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.1326
Download URL

Supplemental Material:
Cybersecurity Supply Chain Risk Management

Related NIST Publications:
SP 800-161 Rev. 1

Document History:
10/30/24: SP 1326 (Draft)
07/08/26: SP 1326 (Final)

Topics

Security and Privacy

cybersecurity supply chain risk management, risk assessment

Activities and Products

quick-start guides