Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.17.01OFFICIAL TITLEPENDING NIST SME REVIEW

03.17.01Supply Chain Risk Management Plan

03.17 Supply Chain Risk Management · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system and its components and services; review and update the plan at an organization-defined frequency; and protect it from unauthorized disclosure.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

A written answer to the question 'how does this organization decide what risk its suppliers bring, and what does it do about it.' The plan is the frame the other two supply chain requirements hang from — what gets assessed, who decides, what happens when a supplier falls short — kept current, and kept out of the hands of the suppliers it evaluates.

Across revisions

New family in Rev. 3 — Rev. 2 contained no supply chain requirements. The plan requirement is the governance anchor for 03.17.02 and 03.17.03.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: Knowing what vendors and components bring into the plant is the risk knowledge a supply chain risk management plan documents and governs — the practice generates the assessments, vendor facts, and decisions the plan is written from.

What this does not claim: A plan is authored governance the practice does not produce: development, a defined review frequency, and protection from disclosure are their own obligations. The requirement's scope also spans the full system lifecycle — development through disposal, IT services included — where this practice's center of gravity is plant procurement and operations.

Practice-side activities
  • Record vendor and component risk decisions in a form the plan can incorporate
  • Surface supplier changes — acquisitions, end-of-life notices, incidents — to the plan owner as review triggers
Evidence this produces
  • Vendor risk assessments feeding the plan
  • Review-trigger records connecting supplier events to plan updates

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Scope the plan to the system that handles CUI — the components, software, and services it depends on — rather than attempting an enterprise-wide procurement rewrite on day one.
  • Reuse what exists: vendor-vetting habits, purchasing rules, and contract templates are plan content already in operation; the plan's job is to connect and own them, not reinvent them.
  • Tie the review cadence to supplier change — a new critical vendor, an acquisition, a discontinued product line — not only to the calendar.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The supply chain risk management plan with version history against its defined review frequency
  • Records showing the plan's processes exercised on a real acquisition or supplier event

Suggested owners, derived from the mapped practices and artifacts: Procurement + OT · IT leader or compliance lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

No direct Rev. 2 counterpart — this requirement is new in Rev. 3. Open the transition crosswalk →

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated