Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-161 Rev. 1

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

Date Published: May 2022

Supersedes: SP 800-161 (04/08/2015)

Planning Note (11/01/2024):

See the errata update released on November 1, 2024.


Author(s)

Jon Boyens (NIST), Angela Smith (NIST), Nadya Bartol (Boston Consulting Group), Kris Winkler (Boston Consulting Group), Alex Holbrook (Boston Consulting Group), Matthew Fallon (Boston Consulting Group)

Abstract

Keywords

acquire; C-SCRM; cybersecurity supply chain; cybersecurity supply chain risk management; information and communication technology; risk management; supplier; supply chain; supply chain risk assessment; supply chain assurance; supply chain risk; supply chain security
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-161r1
Download URL

Supplemental Material:
NIST’s Cyber Supply Chain Risk Management Program
NIST news article (May 2022)

Related NIST Publications:
IR 8286
Other

Document History:
02/04/20: SP 800-161 Rev. 1 (Draft)
04/29/21: SP 800-161 Rev. 1 (Draft)
10/28/21: SP 800-161 Rev. 1 (Draft)
05/05/22: SP 800-161 Rev. 1 (Final)

Topics

Security and Privacy

acquisition, cybersecurity supply chain risk management

Laws and Regulations

Executive Order 14028