Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-161 Rev. 1

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

Date Published: May 2022 (includes updates as of 11-01-2024)

Supersedes: SP 800-161 Rev. 1 (05/05/2022)

Planning Note (12/02/2025):

A fillable version of the SCRM Assessment Scoping Questionnaire (Table 26) is now available.


Author(s)

Jon Boyens (NIST), Angela Smith (NIST), Nadya Bartol (Boston Consulting Group), Kris Winkler (Boston Consulting Group), Alex Holbrook (Boston Consulting Group), Matthew Fallon (Boston Consulting Group)

Abstract

Keywords

acquire; C-SCRM; cybersecurity supply chain; cybersecurity supply chain risk management; information and communication technology; risk management; supplier; supply chain; supply chain risk assessment; supply chain assurance; supply chain risk; supply chain security
Control Families

None selected