FedRAMP Rev 5 supply chain risk management aligns with Executive Order 14028 + NIST SP 800-218 Secure Software Development Framework (SSDF). REQUIREMENTS: (a) SUPPLY CHAIN RISK MANAGEMENT POLICY + PLAN (NIST 800-53 Rev 5 SR family) + integration into the SSP; (b) SOFTWARE BILL OF MATERIALS (SBOM) for critical software + components per OMB M-22-18 + the FedRAMP 2024 Pre-market SBOM guidance + the NTIA SBOM Minimum Elements; (c) Software Provider Assurance via NIST SSDF attestation + supply-chain risk-management practices documented in the SSP; (d) Vulnerability Exploitability eXchange (VEX) documents for SBOM components; (e) Component-level monitoring for known vulnerabilities (CISA KEV Catalog) + sector-specific threat intelligence; (f) FOREIGN COMPONENT RESTRICTIONS - certain components from countries of concern restricted per the Countering CCP Software Act + Section 889 of the FY2019 NDAA + the FY2024 NDAA prohibitions on TikTok / WeChat / Kaspersky / Huawei / ZTE software + hardware. The 2025 EO 14117 on cross-border data transfers to countries of concern adds additional restrictions on data-transfer relationships with components / vendors from designated countries.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.