Skip to content
SR-13

Supplier Inventory (SP 800-161 Rev. 1 Update 1)

Supply Chain Risk Management

NIST Control Text

  1. a.Develop, document, and maintain an inventory of suppliers that:
    1. 1.Accurately and minimally reflects the organization's tier one suppliers that may present a cybersecurity risk in the supply chain [Assignment: organization-defined parameters for determining the tier one supply chain];
    2. 2.Is at the level of granularity deemed necessary for assessing criticality and supply chain risk, tracking, and reporting;
    3. 3.Documents the following information for each tier one supplier (e.g., prime contractor):
      1. i.Unique identifier for the procurement instrument (i.e., contract, task, or delivery order);
      2. ii.Description of the supplied products and/or services;
      3. iii.Program, project, and/or system that uses the supplier's products and/or services; and
      4. iv.Assigned criticality level that aligns to the criticality of the program, project, and/or system (or component of system).
  2. b.Review and update the supplier inventory [Assignment: enterprise-defined frequency].

NIST Discussion

Enterprises rely on numerous suppliers to execute their missions and functions. Many suppliers provide products and services in support of multiple missions, functions, programs, projects, and systems. Some suppliers are more critical than others, based on the criticality of missions, functions, programs, projects, systems that their products and services support, and the enterprise's level of dependency on the supplier. Enterprises should use criticality analysis to help determine which products and services are critical to determine the criticality of suppliers to be documented in the supplier inventory. See Section 2, Appendix C, and RA-9 for guidance on conducting criticality analysis.

SL5 Supplemental Guidance

Apply SP 800-161 Rev. 1 Update 1 guidance [3] for maintaining a comprehensive, criticality-based inventory of all suppliers documenting supplier identities, products provided, and assigned risk levels.

Was this control helpful?