Supply Chain Risk Management (SR) Control Family
The Supply Chain Risk Management (SR) control family is a group of security and privacy controls focused on identifying and reducing risks that come from the products, components, and services an organization acquires from suppliers and other third parties. These controls help organizations understand who and what is in their supply chain and take steps to guard against tampering, counterfeit parts, and other threats introduced before or during delivery. The specific controls, labels, and requirements should be confirmed against the current authoritative publication that defines this family.
The SR control family designates the set of controls addressing supply chain risk management within a security and privacy control catalog. In most implementations, this family covers areas such as supply chain risk management planning, supplier and provider assessment, provenance and traceability of components, anti-counterfeit measures, tamper resistance and detection, and secure acquisition and disposal practices, generally intended to be tailored through a supply chain risk management plan and applied according to the applicable baseline and impact level. Practitioners should verify the exact control identifiers, enhancements, and applicability against the current revision of the governing publication and any agency- or program-specific tailoring, since control content, numbering, and baseline assignments can change across revisions. This entry describes the family at a conceptual level and does not specify implementation details, contractual flow-down obligations, or how the SR family maps to any particular authorization, assessment, or CUI/defense requirement, all of which must be confirmed against current official sources.
Why it matters
Supply chain compromise has become one of the more consequential attack vectors facing defense and public sector systems because a single trusted supplier, component, or software update can introduce risk across many downstream organizations at once. The SR control family exists to give organizations a structured way to reason about who and what is in their supply chain, so that threats such as tampering, counterfeit parts, and maliciously modified components can be identified and mitigated before they reach an operational system. Without deliberate supply chain risk management, an organization may inherit vulnerabilities it never directly introduced and cannot easily see.
These controls matter because the risks they address generally originate before or during delivery, at points where the acquiring organization may have limited visibility. Provenance and traceability, supplier assessment, anti-counterfeit measures, and tamper detection are all aimed at closing that visibility gap and establishing a defensible basis for trusting acquired products and services. A common expert correction here is to remember that satisfying these controls is not the same as being secure: implementing SR controls reduces certain categories of supply chain risk, but it does not guarantee that every supplier relationship or component is free of compromise.
Because control content, numbering, and baseline assignments can change across revisions of the governing publication, and because agencies and programs may tailor requirements to their own contexts, the practical weight of the SR family depends heavily on how it is applied. Organizations should treat this entry as conceptual and confirm the specific controls, enhancements, and applicability, including any contractual flow-down or CUI and defense-specific obligations, against the current authoritative source rather than assuming a fixed set of requirements.
Who it's relevant to
Inside SR
Common questions
Answers to the questions practitioners most commonly ask about SR.