Supply Chain Risk Management (SR)¶
This page contains all 27 controls and control enhancements in the Supply Chain Risk Management (SR) family from the vendored NIST SP 800-53 Revision 5 OSCAL catalog.
Official NIST OSCAL source
- Catalog version: 5.2.0
- OSCAL version: 1.2.2
- Catalog last modified: May 11, 2026
SR-01 (Policy and Procedures)¶
- a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
- 1. [Selection: one or more of: organization-level; mission/business process-level; system-level] supply chain risk management policy that:
- (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
- (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
- 2. Procedures to facilitate the implementation of the supply chain risk management policy and the associated supply chain risk management controls;
- 1. [Selection: one or more of: organization-level; mission/business process-level; system-level] supply chain risk management policy that:
- b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the supply chain risk management policy and procedures; and
- c. Review and update the current supply chain risk management:
- 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and
- 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-02 (Supply Chain Risk Management Plan)¶
- a. Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services: [Assignment: organization-defined systems, system components, or system services];
- b. Review and update the supply chain risk management plan [Assignment: organization-defined frequency] or as required, to address threat, organizational or environmental changes; and
- c. Protect the supply chain risk management plan from unauthorized disclosure and modification.
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-02 (01) (Establish SCRM Team)¶
Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined supply chain risk management activities].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-03 (Supply Chain Controls and Processes)¶
- a. Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Assignment: organization-defined system or system component] in coordination with [Assignment: organization-defined supply chain personnel];
- b. Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined supply chain controls]; and
- c. Document the selected and implemented supply chain processes and controls in [Selection: one or more of: security and privacy plans; supply chain risk management plan].
FedRAMP Guidance
CSO must document and maintain the supply chain custody, including replacement devices, to ensure the integrity of the devices before being introduced to the boundary.
External Link for Additional Information: myctrl.tools
SR-03 (01) (Diverse Supply Base)¶
Employ a diverse set of sources for the following system components and services: [Assignment: organization-defined system components and services].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-03 (02) (Limitation of Harm)¶
Employ the following controls to limit harm from potential adversaries identifying and targeting the organizational supply chain: [Assignment: organization-defined controls].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-03 (03) (Sub-tier Flow Down)¶
Ensure that the controls included in the contracts of prime contractors are also included in the contracts of subcontractors.
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-04 (Provenance)¶
Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [Assignment: organization-defined systems, system components, and associated data].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-04 (01) (Identity)¶
Establish and maintain unique identification of the following supply chain elements, processes, and personnel associated with the identified system and critical system components: [Assignment: organization-defined supply chain elements, processes, and personnel].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-04 (02) (Track and Trace)¶
Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [Assignment: organization-defined systems and critical system components].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-04 (03) (Validate as Genuine and Not Altered)¶
Employ the following controls to validate that the system or system component received is genuine and has not been altered: [Assignment: organization-defined controls].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-04 (04) (Supply Chain Integrity — Pedigree)¶
Employ [Assignment: organization-defined controls] and conduct [Assignment: organization-defined analysis method] to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-05 (Acquisition Strategies, Tools, and Methods)¶
Employ the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: [Assignment: organization-defined strategies, tools, and methods].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-05 (01) (Adequate Supply)¶
Employ the following controls to ensure an adequate supply of [Assignment: organization-defined critical system components]: [Assignment: organization-defined controls].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-05 (02) (Assessments Prior to Selection, Acceptance, Modification, or Update)¶
Assess the system, system component, or system service prior to selection, acceptance, modification, or update.
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-06 (Supplier Assessments and Reviews)¶
Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide [Assignment: organization-defined frequency].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-06 (01) (Testing and Analysis)¶
Employ [Selection: one or more of: organizational analysis; independent third-party analysis; organizational testing; independent third-party testing] of the following supply chain elements, processes, and actors associated with the system, system component, or system service: [Assignment: organization-defined supply chain elements, processes, and actors].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-07 (Supply Chain Operations Security)¶
Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [Assignment: organization-defined OPSEC controls].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-08 (Notification Agreements)¶
Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [Selection: one or more of: notification of supply chain compromises].
FedRAMP Guidance
Follow the FedRAMP Incident Evaluation and Communication rules.
External Link for Additional Information: myctrl.tools
SR-09 (Tamper Resistance and Detection)¶
Implement a tamper protection program for the system, system component, or system service.
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-09 (01) (Multiple Stages of System Development Life Cycle)¶
Employ anti-tamper technologies, tools, and techniques throughout the system development life cycle.
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-10 (Inspection of Systems or Components)¶
Inspect the following systems or system components [Selection: one or more of: at random; at; upon] to detect tampering: [Assignment: organization-defined systems or system components].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-11 (Component Authenticity)¶
- a. Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and
- b. Report counterfeit system components to [Selection: one or more of: source of counterfeit component].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-11 (01) (Anti-counterfeit Training)¶
Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware).
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-11 (02) (Configuration Control for Component Service and Repair)¶
Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system components].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-11 (03) (Anti-counterfeit Scanning)¶
Scan for counterfeit system components [Assignment: organization-defined frequency].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools
SR-12 (Component Disposal)¶
Dispose of [Assignment: organization-defined data, documentation, tools, or system components] using the following techniques and methods: [Assignment: organization-defined techniques and methods].
This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.
External Link for Additional Information: myctrl.tools