The NIST 800-53 SR family is the set of twelve controls that Revision 5 added to manage the risks that arrive through suppliers, components and software you did not build yourself. It is the family most assessors now probe first, because a single compromised vendor or counterfeit part can defeat every other control you operate.
This guide lists the SR controls, explains what each group is for, shows how to build a supply chain risk management plan, and describes the evidence an assessor will expect. For the wider catalogue, see our NIST 800-53 control families guide and the overview of NIST SP 800-53.
Free gap assessment
Which 800-53 families would not survive an assessment?
Score all twenty control families, free, plus the categorisation, baseline and parameter decisions everything else depends on.
Run the free NIST SP 800-53 gap assessment → or View premium report sample
What the NIST 800-53 SR family covers
The SR family addresses the management of risks associated with the research, development, design, manufacturing, acquisition, delivery, integration, operations, maintenance and disposal of systems and components. NIST introduced it as a new control family in Revision 5, which is why older programmes built on Revision 4 often have little in place. The twelve controls fall into four practical groups.
| Group | Controls | Purpose |
|---|---|---|
| Governance | SR-1 Policy and Procedures, SR-2 Supply Chain Risk Management Plan | Set the policy, the plan and the team |
| Supplier selection and contracts | SR-3 Supply Chain Controls and Processes, SR-5 Acquisition Strategies, Tools, and Methods, SR-6 Supplier Assessments and Reviews, SR-8 Notification Agreements | Choose, contract and review suppliers |
| Traceability and protection | SR-4 Provenance, SR-7 Supply Chain Operations Security | Know where components come from and protect the process |
| Components and disposal | SR-9 Tamper Resistance and Detection, SR-10 Inspection of Systems or Components, SR-11 Component Authenticity, SR-12 Component Disposal | Protect items in transit and in service, and retire them safely |
Governance controls in the NIST 800-53 SR family
SR-1 requires supply chain risk management policy and procedures, with a named official to manage them. SR-2 requires a plan for supply chain risk management that covers systems and components across their lifecycle, from research and development through disposal. The plan must be reviewed and updated as required to address changes in threats, the organisation or the environment, and protected from unauthorised disclosure and modification. The enhancement SR-2(1), establishing a supply chain risk management team, appears in every baseline according to a public control reference, which shows how central NIST considers it.
Building the plan and the team
A workable plan states which suppliers and components matter most, what threats you consider, how you assess suppliers, what you require in contracts, how you monitor them and how you respond to a supplier incident. The team should include procurement, security, legal, engineering and the business owners of critical services, so that decisions on buying are not made in isolation. NIST’s companion publication SP 800-161 on cybersecurity supply chain risk management gives fuller guidance. Our third-party risk management guide covers the wider discipline.
Free third-party risk assessment
How much risk does this vendor bring?
Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.
Start the free vendor risk assessment → or View premium report sample
Supplier selection and contract controls
SR-3 asks for controls and processes that identify and address weaknesses in the supply chain for a defined set of systems and components, and SR-5 asks for acquisition strategies, tools and methods to protect against supply chain risks. SR-6 requires you to assess and review suppliers. SR-8 covers notification agreements, in which suppliers agree to tell you about compromises and other events affecting your supply chain. In practical terms, that means the following.
- Risk tiering. Rank suppliers by the criticality of what they provide. See vendor risk tiering.
- Due diligence before award. Use questionnaires, assurance reports and, where relevant, security testing. Our vendor due diligence checklist lists questions.
- Contract clauses. Require security practices, incident and compromise notification, flow-down to subcontractors and audit or assurance rights.
- Periodic reassessment. Review suppliers on a schedule set by tier and after any change or incident.
Traceability, authenticity and disposal
SR-4 covers provenance: documenting the origin and history of systems and components, so that you know where a component came from and who has handled it. SR-9 and SR-10 deal with tamper resistance and detection, and inspection of systems or components, including checks on items received. SR-11 addresses component authenticity, meaning detection and prevention of counterfeit parts, while SR-12 covers component disposal. Software teams will recognise the same ideas in the software bill of materials and signed artefacts: know what is in your product, where it came from and whether it is genuine.
If your organisation also handles operational technology or hardware supply chains, compare this guidance with the way standards such as AS9100 counterfeit parts controls handle authenticity in manufacturing.
Implementing the NIST 800-53 SR family step by step
Treat the NIST 800-53 SR family as a programme with an owner, a budget and a calendar, not as a paperwork exercise added before an assessment.
- Set your baseline. Confirm which SR controls and enhancements your selected baseline includes, and adjust through tailoring where justified.
- Write the policy and plan. Cover SR-1 and SR-2, and name the owner and team.
- Inventory suppliers and components. Record what each provides and how critical it is.
- Tier and assess. Apply due diligence in proportion to the tier.
- Update contracts. Add notification, flow-down and assurance terms.
- Add provenance and inspection. Track origin and check what arrives.
- Plan disposal. Define how components are retired and data removed.
- Monitor and test. Review regularly and rehearse a supplier incident.
Evidence assessors expect
Assessors following the assessment procedures in NIST SP 800-53A will look for documents, interviews and tests. Prepare the SR policy, the approved plan, team membership and meeting records, the supplier inventory with tiers, completed assessments, sample contracts with the notification clause, provenance records for critical components, inspection and authenticity checks, and disposal records. They may also ask you to walk through what happened when a supplier notified you of a problem. Keep the case records, because a documented response is stronger than a policy.
Software supply chain and the NIST 800-53 SR family
Software now dominates most supply chains. Open-source packages, container images, build tools, cloud services and managed platforms all count as components. Apply the SR controls to them in the same way: keep an inventory of what is inside your products, record where each item came from, verify integrity with signatures or hashes, watch for vulnerability and compromise notices, and control who can change the build pipeline. A software bill of materials generated with each release makes provenance and incident response far easier, and it supports the notification duty you place on your own suppliers. Also protect your build environment, since an attacker who changes the pipeline can compromise every customer downstream.
Where you consume software as a service, the contract and the provider’s assurance evidence take the place of direct inspection. Ask how the provider manages its own suppliers, and how quickly it will tell you of a compromise. That is the practical test of the SR family in a cloud world.
A hypothetical example
A federal contractor runs a moderate-impact system that depends on a hosted log analytics service, a vendor-supplied network appliance and an open-source library used across its applications. It tiers all three as critical. For the analytics service, it reviews the provider’s assurance report and adds a compromise notification clause. For the appliance, it verifies provenance through the reseller, inspects the packaging and firmware hash on receipt, and records the serial numbers. For the library, it generates a software bill of materials and subscribes to vulnerability notices. When the library maintainers announce a compromised release, the supply chain team, already defined, finds the affected builds within a day and rolls back. The example is illustrative only.
Common mistakes with the NIST 800-53 SR family
- A policy but no plan. SR-1 is written, SR-2 never is.
- No team. Supply chain decisions remain with procurement alone.
- Contracts unchanged. Suppliers are not required to notify you of compromises.
- Software ignored. Focus stays on hardware, while libraries and services carry the risk.
- Onboarding only. Suppliers are assessed once and never reviewed.
- No disposal process. Retired components leave with data still on them.
Templates for the NIST 800-53 SR family
The records are repeatable: an SR policy, a supply chain risk management plan, a supplier register, an assessment form, a contract clause set, an inspection checklist and a disposal procedure. The NIST SP 800-53 Toolkit includes templates for control documentation, which you can tailor to your baseline. A useful public reference is the SR family listing on CSF Tools, and the authoritative text is in NIST’s publication and its control catalogue.
NIST 800-53 SR family FAQ
How many controls are in the SR family?
Twelve base controls, SR-1 to SR-12, plus enhancements. The family is new in Revision 5.
Is the SR family required in every baseline?
Some SR controls and enhancements are in all baselines, for example SR-2(1), but the exact selection depends on the baseline, so check the control baselines publication and your tailoring.
What is the difference between SR and SP 800-161?
The SR family is the set of controls in SP 800-53. SP 800-161 is companion guidance on how to implement supply chain risk management across an organisation.
Does SR cover software?
Yes. The family covers systems and components, which include software, services and open-source libraries as well as hardware.