← Back to all briefings
Cybersecurity 5 min read Published Updated Credibility 40/100

Cybersecurity Briefing — NIST issues SP 800-161 Rev.1 on supply chain risk management

On 5 May 2022 NIST released SP 800-161 Revision 1, expanding cybersecurity supply chain risk management practices for federal agencies and critical suppliers in line with EO 14028.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

NIST published Special Publication 800-161 Revision 1 on 5 May 2022, updating guidance for Cybersecurity Supply Chain Risk Management (C-SCRM). The revision aligns with Executive Order 14028, adds threat-informed controls for open-source and third-party software, and introduces tiered implementation guidance for federal agencies and suppliers.

Security and procurement teams should integrate the new controls into acquisition language, SBOM and vulnerability disclosure expectations, and third-party risk assessments, especially where federal customers impose C-SCRM requirements.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

Continue in the Cybersecurity pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Supply Chain Security
  • Third-Party Risk
  • Federal Compliance
Back to curated briefings