A. Develop a plan for managing supply chain risks associated with the research, development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system, system components, or system services. B. Review and update the supply chain risk management plan [Assignment: organization-defined frequency]. C. Protect the supply chain risk management plan from unauthorized disclosure.
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
Your organization must create a formal plan for managing supply chain risks across the entire system lifecycle -- from acquisition through disposal. The plan must be reviewed and updated regularly, and it must be protected from unauthorized disclosure because it contains sensitive information about your supply chain vulnerabilities and risk posture.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Supply chain risk management plan development
Implementation Steps
Develop a supply chain risk management (SCRM) plan covering the full system lifecycle: acquisition, integration, operations, maintenance, and disposal
Identify and assess supply chain risks for critical system components, software, and service providers
Define risk mitigation strategies for identified supply chain risks, including alternative sourcing and verification procedures
Review and update the SCRM plan at the defined frequency (e.g., annually); protect the plan from unauthorized disclosure with access controls
Tools / Systems
SCRM plan template (NIST SP 800-161 aligned)Third-party risk management platform (SecurityScorecard, BitSight, OneTrust)Secure document repository with access controlsSCRM plan review and update calendar
Typical Control Supply chain risk management plan development
Evidence Artifacts
Supply chain risk management plan with lifecycle coverage
Supply chain risk assessment results for critical components and providers
SCRM plan review records with revision dates and access control configuration
📅Annual SCRM plan review and update (or at defined frequency); per-event updates for significant supply chain changes
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
03.17.02
Acquisition strategies, tools, and methods
Supply chain risk management
3 evidence1 control
03.17.03
Supply chain requirements and processes
Supply chain risk management
3 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Supply chain risk management plan development
Implementation steps
Create an SCRM plan addressing supply chain risks across the system lifecycle for all critical components and services
Assess supply chain risks for hardware, software, firmware, and service providers; document findings and risk levels
Define mitigation strategies including multi-sourcing, integrity verification, and vendor diversification
Schedule regular plan reviews and updates; restrict plan access to authorized personnel
Tools / systems
SCRM plan template and methodology documentation
Supply chain risk assessment tools and questionnaires
Secure document storage with access restrictions
Review schedule and change tracking
Evidence artifacts
SCRM plan with management approval and effective date
Supply chain risk assessments for critical vendors and components
Plan revision history and access control records
Evidence frequency: Annual SCRM plan review and update (or at defined frequency); per-event updates for significant supply chain changes