Back to Frameworks

NIST SP 800-161 Rev 1

United States
vRevision 1 (May 2022)
20 domains
191 controls

NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Appendix A is an enhanced overlay on NIST SP 800-53 Rev. 5: it selects the controls that bear on cybersecurity supply chain risk, organizes them into the 20 SP 800-53 control families, and adds C-SCRM supplemental guidance. Two controls, MA-8 and SR-13, are defined by this publication and do not exist in SP 800-53 Rev. 5.

Verified

NIST SP 800-161 Rev 1 is a compliance framework from United States with 20 domains and 191 controls that map to 37 other frameworks. The largest domains are C-SCRM Family: Program Management (30 controls), C-SCRM Family: System and Services Acquisition (15 controls), C-SCRM Family: Access Control (14 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (20)

C-SCRM Family: Access Control

14 controls
Controls in the C-SCRM Family: Access Control domain of NIST SP 800-161 Rev 114 controls
CodeTitle
161R1-AC-1Policy and Procedures
161R1-AC-17Remote Access
161R1-AC-18Wireless Access
161R1-AC-19Access Control for Mobile Devices
161R1-AC-2Account Management
161R1-AC-20Use of External Systems
161R1-AC-21Information Sharing
161R1-AC-22Publicly Accessible Content
161R1-AC-23Data Mining Protection
161R1-AC-24Access Control Decisions
161R1-AC-3Access Enforcement
161R1-AC-4Information Flow Enforcement
161R1-AC-5Separation of Duties
161R1-AC-6Least Privilege

C-SCRM Family: Assessment, Authorization, and Monitoring

6 controls
Controls in the C-SCRM Family: Assessment, Authorization, and Monitoring domain of NIST SP 800-161 Rev 16 controls
CodeTitle
161R1-CA-1Policy and Procedures
161R1-CA-2Control Assessments
161R1-CA-3Information Exchange
161R1-CA-5Plan of Action and Milestones
161R1-CA-6Authorization
161R1-CA-7Continuous Monitoring

C-SCRM Family: Audit and Accountability

9 controls
Controls in the C-SCRM Family: Audit and Accountability domain of NIST SP 800-161 Rev 19 controls
CodeTitle
161R1-AU-1Policy and Procedures
161R1-AU-10Non-repudiation
161R1-AU-12Audit Record Generation
161R1-AU-13Monitoring for Information Disclosure
161R1-AU-14Session Audit
161R1-AU-16Cross-Organizational Audit Logging
161R1-AU-2Event Logging
161R1-AU-3Content of Audit Records
161R1-AU-6Audit Review, Analysis, and Reporting

C-SCRM Family: Awareness and Training

4 controls
Controls in the C-SCRM Family: Awareness and Training domain of NIST SP 800-161 Rev 14 controls
CodeTitle
161R1-AT-1Policy and Procedures
161R1-AT-2Literacy Training and Awareness
161R1-AT-3Role-Based Training
161R1-AT-4Training Records

C-SCRM Family: Configuration Management

14 controls
Controls in the C-SCRM Family: Configuration Management domain of NIST SP 800-161 Rev 114 controls
CodeTitle
161R1-CM-1Policy and Procedures
161R1-CM-10Software Usage Restrictions
161R1-CM-11User-Installed Software
161R1-CM-12Information Location
161R1-CM-13Data Action Mapping
161R1-CM-14Signed Components
161R1-CM-2Baseline Configuration
161R1-CM-3Configuration Change Control
161R1-CM-4Impact Analysis
161R1-CM-5Access Restrictions for Change
161R1-CM-6Configuration Settings
161R1-CM-7Least Functionality
161R1-CM-8System Component Inventory
161R1-CM-9Configuration Management Plan

C-SCRM Family: Contingency Planning

8 controls
Controls in the C-SCRM Family: Contingency Planning domain of NIST SP 800-161 Rev 18 controls
CodeTitle
161R1-CP-1Policy and Procedures
161R1-CP-11Alternative Communications Protocols
161R1-CP-2Contingency Plan
161R1-CP-3Contingency Training
161R1-CP-4Contingency Plan Testing
161R1-CP-6Alternative Storage Site
161R1-CP-7Alternative Processing Site
161R1-CP-8Telecommunications Services

C-SCRM Family: Identification and Authentication

7 controls
Controls in the C-SCRM Family: Identification and Authentication domain of NIST SP 800-161 Rev 17 controls
CodeTitle
161R1-IA-1Policy and Procedures
161R1-IA-2Identification and Authentication (Organizational Users)
161R1-IA-3Device Identification and Authentication
161R1-IA-4Identifier Management
161R1-IA-5Authenticator Management
161R1-IA-8Identification and Authentication (Non-Organizational Users)
161R1-IA-9Service Identification and Authentication

C-SCRM Family: Incident Response

9 controls
Controls in the C-SCRM Family: Incident Response domain of NIST SP 800-161 Rev 19 controls
CodeTitle
161R1-IR-1Policy and Procedures
161R1-IR-2Incident Response Training
161R1-IR-3Incident Response Testing
161R1-IR-4Incident Handling
161R1-IR-5Incident Monitoring
161R1-IR-6Incident Reporting
161R1-IR-7Incident Response Assistance
161R1-IR-8Incident Response Plan
161R1-IR-9Information Spillage Response

C-SCRM Family: Maintenance

8 controls
Controls in the C-SCRM Family: Maintenance domain of NIST SP 800-161 Rev 18 controls
CodeTitle
161R1-MA-1Policy and Procedures
161R1-MA-2Controlled Maintenance
161R1-MA-3Maintenance Tools
161R1-MA-4Nonlocal Maintenance
161R1-MA-5Maintenance Personnel
161R1-MA-6Timely Maintenance
161R1-MA-7Field Maintenance
161R1-MA-8Maintenance Monitoring and Information Sharing

C-SCRM Family: Media Protection

4 controls
Controls in the C-SCRM Family: Media Protection domain of NIST SP 800-161 Rev 14 controls
CodeTitle
161R1-MP-1Policy and Procedures
161R1-MP-4Media Storage
161R1-MP-5Media Transport
161R1-MP-6Media Sanitization

C-SCRM Family: Personally Identifiable Information Processing and Transparency

1 controls
Controls in the C-SCRM Family: Personally Identifiable Information Processing and Transparency domain of NIST SP 800-161 Rev 11 controls
CodeTitle
161R1-PT-1Policy and Procedures

C-SCRM Family: Personnel Security

4 controls
Controls in the C-SCRM Family: Personnel Security domain of NIST SP 800-161 Rev 14 controls
CodeTitle
161R1-PS-1Policy and Procedures
161R1-PS-3Personnel Screening
161R1-PS-6Access Agreements
161R1-PS-7External Personnel Security

C-SCRM Family: Physical and Environmental Protection

9 controls
Controls in the C-SCRM Family: Physical and Environmental Protection domain of NIST SP 800-161 Rev 19 controls
CodeTitle
161R1-PE-1Policy and Procedures
161R1-PE-16Delivery and Removal
161R1-PE-17Alternative Work Site
161R1-PE-18Location of System Components
161R1-PE-2Physical Access Authorizations
161R1-PE-20Asset Monitoring and Tracking
161R1-PE-23Facility Location
161R1-PE-3Physical Access Control
161R1-PE-6Monitoring Physical Access

C-SCRM Family: Planning

7 controls
Controls in the C-SCRM Family: Planning domain of NIST SP 800-161 Rev 17 controls
CodeTitle
161R1-PL-1Policy and Procedures
161R1-PL-10Baseline Selection
161R1-PL-2System Security and Privacy Plans
161R1-PL-4Rules of Behavior
161R1-PL-7Concept of Operations
161R1-PL-8Security and Privacy Architectures
161R1-PL-9Central Management

C-SCRM Family: Program Management

30 controls
Controls in the C-SCRM Family: Program Management domain of NIST SP 800-161 Rev 130 controls
CodeTitle
161R1-PM-10Authorization Process
161R1-PM-11Mission and Business Process Definition
161R1-PM-12Insider Threat Program
161R1-PM-13Security and Privacy Workforce
161R1-PM-14Testing, Training, and Monitoring
161R1-PM-15Security and Privacy Groups and Associations
161R1-PM-16Threat Awareness Program
161R1-PM-17Protecting Controlled Unclassified Information on External Systems
161R1-PM-18Privacy Program Plan
161R1-PM-19Privacy Program Leadership Role
161R1-PM-2Information Security Program Leadership Role
161R1-PM-20Dissemination of Privacy Program Information
161R1-PM-21Accounting of Disclosures
161R1-PM-22Personally Identifiable Information Quality Management
161R1-PM-23Data Governance Body
161R1-PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research
161R1-PM-26Complaint Management
161R1-PM-27Privacy Reporting
161R1-PM-28Risk Framing
161R1-PM-29Risk Management Program Leadership Roles
161R1-PM-3Information Security and Privacy Resources
161R1-PM-30Supply Chain Risk Management Strategy
161R1-PM-31Continuous Monitoring Strategy
161R1-PM-32Purposing
161R1-PM-4Plan of Action and Milestones Process
161R1-PM-5System Inventory
161R1-PM-6Measures of Performance
161R1-PM-7Enterprise Architecture
161R1-PM-8Critical Infrastructure Plan
161R1-PM-9Risk Management Strategy

C-SCRM Family: Risk Assessment

7 controls
Controls in the C-SCRM Family: Risk Assessment domain of NIST SP 800-161 Rev 17 controls
CodeTitle
161R1-RA-1Policy and Procedures
161R1-RA-10Threat Hunting
161R1-RA-2Security Categorization
161R1-RA-3Risk Assessment
161R1-RA-5Vulnerability Monitoring and Scanning
161R1-RA-7Risk Response
161R1-RA-9Criticality Analysis

C-SCRM Family: Supply Chain Risk Management

13 controls
Controls in the C-SCRM Family: Supply Chain Risk Management domain of NIST SP 800-161 Rev 113 controls
CodeTitle
161R1-SR-1Policy and Procedures
161R1-SR-10Inspection of Systems or Components
161R1-SR-11Component Authenticity
161R1-SR-12Component Disposal
161R1-SR-13Supplier Inventory
161R1-SR-2Supply Chain Risk Management Plan
161R1-SR-3Supply Chain Controls and Processes
161R1-SR-4Provenance
161R1-SR-5Acquisition Strategies, Tools, and Methods
161R1-SR-6Supplier Assessments and Reviews
161R1-SR-7Supply Chain Operations Security
161R1-SR-8Notification Agreements
161R1-SR-9Tamper Resistance and Detection

C-SCRM Family: System and Communications Protection

14 controls
Controls in the C-SCRM Family: System and Communications Protection domain of NIST SP 800-161 Rev 114 controls
CodeTitle
161R1-SC-1Policy and Procedures
161R1-SC-18Mobile Code
161R1-SC-27Platform-Independent Applications
161R1-SC-28Protection of Information at Rest
161R1-SC-29Heterogeneity
161R1-SC-30Concealment and Misdirection
161R1-SC-36Distributed Processing and Storage
161R1-SC-37Out-of-Band Channels
161R1-SC-38Operations Security
161R1-SC-4Information in Shared Resources
161R1-SC-47Alternative Communications Paths
161R1-SC-5Denial-of-Service Protection
161R1-SC-7Boundary Protection
161R1-SC-8Transmission Confidentiality and Integrity

C-SCRM Family: System and Information Integrity

8 controls
Controls in the C-SCRM Family: System and Information Integrity domain of NIST SP 800-161 Rev 18 controls
CodeTitle
161R1-SI-1Policy and Procedures
161R1-SI-12Information Management and Retention
161R1-SI-2Flaw Remediation
161R1-SI-20Tainting
161R1-SI-3Malicious Code Protection
161R1-SI-4System Monitoring
161R1-SI-5Security Alerts, Advisories, and Directives
161R1-SI-7Software, Firmware, and Information Integrity

C-SCRM Family: System and Services Acquisition

15 controls
Controls in the C-SCRM Family: System and Services Acquisition domain of NIST SP 800-161 Rev 115 controls
CodeTitle
161R1-SA-1Policy and Procedures
161R1-SA-10Developer Configuration Management
161R1-SA-11Developer Testing and Evaluation
161R1-SA-15Development Process, Standards, and Tools
161R1-SA-16Developer-Provided Training
161R1-SA-17Developer Security and Privacy Architecture and Design
161R1-SA-2Allocation of Resources
161R1-SA-20Customized Development of Critical Components
161R1-SA-21Developer Screening
161R1-SA-22Unsupported System Components
161R1-SA-3System Development Life Cycle
161R1-SA-4Acquisition Process
161R1-SA-5System Documentation
161R1-SA-8Security and Privacy Engineering Principles
161R1-SA-9External System Services

Maps to 37 other frameworks

191 total controls
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
191 source controls mapped|150 target controls covered
100%
NIST SP 800-53 Rev 5
190 source controls mapped|191 target controls covered
99%
C5 (Germany)
163 source controls mapped|91 target controls covered
85%
FedRAMP Moderate
138 source controls mapped|147 target controls covered
72%
FedRAMP High
137 source controls mapped|146 target controls covered
72%
NIST SP 800-53 Rev 5 MODERATE
132 source controls mapped|131 target controls covered
69%
NIST SP 800-53 Revision 5.1 HIGH
132 source controls mapped|131 target controls covered
69%
NIST SP 800-171 Rev 3
105 source controls mapped|82 target controls covered
55%
NIST SP 800-53 Rev 5 LOW
101 source controls mapped|97 target controls covered
53%
AWS Well-Architected Security Pillar
98 source controls mapped|60 target controls covered
51%
ISO 27002:2022
96 source controls mapped|77 target controls covered
50%
ISO 27001:2022
96 source controls mapped|77 target controls covered
50%
NIST Cybersecurity Framework 2.0
95 source controls mapped|89 target controls covered
50%
NIST SP 800-172
87 source controls mapped|35 target controls covered
46%
HIPAA Security Rule
86 source controls mapped|59 target controls covered
45%
NIST SP 800-66 Rev 2
81 source controls mapped|51 target controls covered
42%
CIS Controls v8
76 source controls mapped|85 target controls covered
40%
CMMC 2.0
73 source controls mapped|73 target controls covered
38%
ISO 27701:2019
72 source controls mapped|66 target controls covered
38%
Azure Security Benchmark
71 source controls mapped|76 target controls covered
37%
PCI DSS 4.0
70 source controls mapped|82 target controls covered
37%
DORA
58 source controls mapped|18 target controls covered
30%
NIST SP 800-218
58 source controls mapped|42 target controls covered
30%
SOC 2
56 source controls mapped|42 target controls covered
29%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
55 source controls mapped|38 target controls covered
29%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
47 source controls mapped|42 target controls covered
25%
Australia Consumer Data Right - Banking (CDR)
42 source controls mapped|17 target controls covered
22%
APRA CPS 234
38 source controls mapped|24 target controls covered
20%
ISO 22301:2019
37 source controls mapped|56 target controls covered
19%
APEC Cross-Border Privacy Rules (CBPR) System
35 source controls mapped|33 target controls covered
18%
APRA CPS 230 Operational Risk Management
32 source controls mapped|34 target controls covered
17%
ASD Strategies to Mitigate Cyber Security Incidents
26 source controls mapped|22 target controls covered
14%
Australia My Health Records Act 2012
25 source controls mapped|10 target controls covered
13%
UK Cyber Essentials
24 source controls mapped|34 target controls covered
13%
APPI
23 source controls mapped|12 target controls covered
12%
ACSC Essential Eight
17 source controls mapped|18 target controls covered
9%
APRA CPS 220 Risk Management
16 source controls mapped|19 target controls covered
8%

What is NIST SP 800-161 Rev 1 and who does it apply to?

NIST SP 800-161 Rev 1 is a compliance framework from United States with 20 domains and 191 controls. NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Appendix A is an enhanced overlay on NIST SP 800-53 Rev. 5: it selects the controls that bear on cybersecurity supply chain risk, organizes them into the 20 SP 800-53 control families, and adds C-SCRM supplemental guidance. Two controls, MA-8 and SR-13, are defined by this publication and do not exist in SP 800-53 Rev. 5. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-161 Rev 1 actually require?

NIST SP 800-161 Rev 1 has 191 controls organised across 20 domains. The largest domains are C-SCRM Family: Program Management (30 controls), C-SCRM Family: System and Services Acquisition (15 controls), C-SCRM Family: Access Control (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-161 Rev 1 do I already cover?

NIST SP 800-161 Rev 1 maps to 37 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (100% coverage), NIST SP 800-53 Rev 5 (99% coverage), C5 (Germany) (85% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-161 Rev 1?

Start your NIST SP 800-161 Rev 1 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-161 Rev 1 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 191 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required