Why: The practice puts security into plant purchasing — vetting vendors before selection, expecting component provenance, involving OT in procurement decisions — which is this requirement's acquisition-time machinery applied to the OT slice of the supply chain.
What this does not claim: May partially address the requirement, whose scope is organization-wide acquisition strategy, contract tooling, and procurement method; purchases outside the plant — enterprise software, cloud services, IT hardware — need the same machinery from other owners. OT vendor reality also limits leverage: sole-source control system suppliers accept contract terms that large buyers can demand and small manufacturers often cannot.
- Vet suppliers and components before purchase, with OT input on consequence
- Carry security terms — notification, provenance, support commitments — into OT purchase agreements where negotiable
- Pre-purchase vetting records for OT acquisitions
- Purchase agreements carrying security terms, with documented residual risk where terms were refused
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06