NIST SP 800-161
NIST SP 800-161 is a NIST guidance document that helps organizations find, evaluate, and reduce cybersecurity risks that come from their supply chains. It focuses on the risks introduced by the products, components, and services an organization obtains from suppliers and partners. Because it is guidance, organizations should confirm how it applies to their specific systems and any contractual or agency requirements against the current official text.
NIST SP 800-161, titled 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (originally published in 2015 and updated as Revision 1 in May 2022, authored by J. Boyens et al.), is a NIST Special Publication providing guidance on identifying, assessing, and responding to cybersecurity supply chain risks (C-SCRM) at all levels of an organization. The original 2015 publication was oriented toward federal agencies and information and communications technology (ICT) supply chain risks, while Revision 1 broadened the framing to cybersecurity supply chain risk management practices for systems and organizations generally. As NIST guidance, it is intended to inform C-SCRM programs and processes; practitioners should note it is distinct from mandatory control catalogs such as NIST SP 800-53 and from contractual regimes such as DFARS or CMMC, and should verify current applicability, tailoring, and the governing revision against the authoritative NIST source.
Why it matters
Cybersecurity supply chain risk has become a central concern for federal agencies, defense organizations, and their contractors because the products, components, and services an organization acquires can introduce vulnerabilities that are difficult to detect and control. NIST SP 800-161 provides structured guidance for identifying, assessing, and responding to these risks, helping organizations move beyond ad hoc supplier vetting toward a repeatable Cybersecurity Supply Chain Risk Management (C-SCRM) program. Compliance officers and information system security managers rely on this framing because a single compromised supplier, component, or software update can undermine otherwise sound internal security controls.
The evolution of the document reflects a broadening understanding of the problem. The original 2015 publication was oriented toward federal agencies and information and communications technology (ICT) supply chain risks, while Revision 1, published in May 2022, reframed the guidance around cybersecurity supply chain risk management practices for systems and organizations more generally. This shift signals that supply chain risk is no longer treated as a narrow procurement or IT-acquisition issue but as an organization-wide concern spanning multiple tiers of an enterprise.
Practitioners should keep in mind that NIST SP 800-161 is guidance rather than a mandatory control catalog or contractual requirement. It is distinct from NIST SP 800-53 and from contractual regimes such as DFARS or CMMC, and adopting its practices does not by itself demonstrate compliance with any specific agency mandate or clause. Organizations should verify how the guidance applies to their own systems and confirm the governing revision and any applicable tailoring against the current authoritative NIST source.
Who it's relevant to
Inside NIST SP 800-161
Common questions
Answers to the questions practitioners most commonly ask about NIST SP 800-161.