NIST Special Publication 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
NIST SP 800-161r1 provides practices for identifying, assessing, and responding to cybersecurity risks across system and technology supply chains.
What the authority record establishes
NIST SP 800-161r1 provides practices for identifying, assessing, and responding to cybersecurity risks across system and technology supply chains.
Guidance unless incorporated through another requirement, policy, or contract
The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.
Why it matters to this market
Procurement workflows may need to capture security requirements, evidence, risk decisions, contract obligations, monitoring, and changes without turning one questionnaire or rating into a complete risk determination.
Affected operating stages
- Strategy
- Requirements
- Supplier Evaluation
- Contracting
- Monitoring
- Incident And Change Response
- Exit
Capabilities to examine
Request Intake And Procurement Orchestration
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for request intake and procurement orchestration.
Supplier Discovery And Market Intelligence
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for supplier discovery and market intelligence.
Contract Authoring, Repository, And Obligation Handoff
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for contract authoring, repository, and obligation handoff.
Supplier Onboarding And Master-Data Governance
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for supplier onboarding and master-data governance.
Supplier Qualification, Risk, And Performance Management
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for supplier qualification, risk, and performance management.
Supplier Network, Portal, And Transaction Collaboration
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for supplier network, portal, and transaction collaboration.
Savings Pipeline, Value Tracking, And Performance Analytics
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for savings pipeline, value tracking, and performance analytics.
ERP Integration, Data Lineage, And Access Governance
Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for ERP integration, data lineage, and access governance.
Affected buyer audiences
- technology procurement
- third-party cyber risk
- security and architecture teams
- supplier-management leaders
Implementation questions
- Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
- What is binding, what is guidance, and what is a technical or consensus standard?
- Which publication, adoption, effective, application, transition, and enforcement dates differ?
- Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
- How will a source revision affect open work and historical decisions?
Interpretation boundary
This page is not a cybersecurity assessment and does not establish a supplier's conformance or fitness for a buyer's system.