NIST SP 800-161 Rev 1
NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Appendix A is an enhanced overlay on NIST SP 800-53 Rev. 5: it selects the controls that bear on cybersecurity supply chain risk, organizes them into the 20 SP 800-53 control families, and adds C-SCRM supplemental guidance. Two controls, MA-8 and SR-13, are defined by this publication and do not exist in SP 800-53 Rev. 5.
NIST SP 800-161 Rev 1 is a compliance framework from United States with 20 domains and 191 controls that map to 37 other frameworks. The largest domains are C-SCRM Family: Program Management (30 controls), C-SCRM Family: System and Services Acquisition (15 controls), C-SCRM Family: Access Control (14 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
C-SCRM Family: Access Control
| Code | Title |
|---|---|
| 161R1-AC-1 | Policy and Procedures |
| 161R1-AC-17 | Remote Access |
| 161R1-AC-18 | Wireless Access |
| 161R1-AC-19 | Access Control for Mobile Devices |
| 161R1-AC-2 | Account Management |
| 161R1-AC-20 | Use of External Systems |
| 161R1-AC-21 | Information Sharing |
| 161R1-AC-22 | Publicly Accessible Content |
| 161R1-AC-23 | Data Mining Protection |
| 161R1-AC-24 | Access Control Decisions |
| 161R1-AC-3 | Access Enforcement |
| 161R1-AC-4 | Information Flow Enforcement |
| 161R1-AC-5 | Separation of Duties |
| 161R1-AC-6 | Least Privilege |
C-SCRM Family: Assessment, Authorization, and Monitoring
| Code | Title |
|---|---|
| 161R1-CA-1 | Policy and Procedures |
| 161R1-CA-2 | Control Assessments |
| 161R1-CA-3 | Information Exchange |
| 161R1-CA-5 | Plan of Action and Milestones |
| 161R1-CA-6 | Authorization |
| 161R1-CA-7 | Continuous Monitoring |
C-SCRM Family: Audit and Accountability
| Code | Title |
|---|---|
| 161R1-AU-1 | Policy and Procedures |
| 161R1-AU-10 | Non-repudiation |
| 161R1-AU-12 | Audit Record Generation |
| 161R1-AU-13 | Monitoring for Information Disclosure |
| 161R1-AU-14 | Session Audit |
| 161R1-AU-16 | Cross-Organizational Audit Logging |
| 161R1-AU-2 | Event Logging |
| 161R1-AU-3 | Content of Audit Records |
| 161R1-AU-6 | Audit Review, Analysis, and Reporting |
C-SCRM Family: Awareness and Training
| Code | Title |
|---|---|
| 161R1-AT-1 | Policy and Procedures |
| 161R1-AT-2 | Literacy Training and Awareness |
| 161R1-AT-3 | Role-Based Training |
| 161R1-AT-4 | Training Records |
C-SCRM Family: Configuration Management
| Code | Title |
|---|---|
| 161R1-CM-1 | Policy and Procedures |
| 161R1-CM-10 | Software Usage Restrictions |
| 161R1-CM-11 | User-Installed Software |
| 161R1-CM-12 | Information Location |
| 161R1-CM-13 | Data Action Mapping |
| 161R1-CM-14 | Signed Components |
| 161R1-CM-2 | Baseline Configuration |
| 161R1-CM-3 | Configuration Change Control |
| 161R1-CM-4 | Impact Analysis |
| 161R1-CM-5 | Access Restrictions for Change |
| 161R1-CM-6 | Configuration Settings |
| 161R1-CM-7 | Least Functionality |
| 161R1-CM-8 | System Component Inventory |
| 161R1-CM-9 | Configuration Management Plan |
C-SCRM Family: Contingency Planning
| Code | Title |
|---|---|
| 161R1-CP-1 | Policy and Procedures |
| 161R1-CP-11 | Alternative Communications Protocols |
| 161R1-CP-2 | Contingency Plan |
| 161R1-CP-3 | Contingency Training |
| 161R1-CP-4 | Contingency Plan Testing |
| 161R1-CP-6 | Alternative Storage Site |
| 161R1-CP-7 | Alternative Processing Site |
| 161R1-CP-8 | Telecommunications Services |
C-SCRM Family: Identification and Authentication
| Code | Title |
|---|---|
| 161R1-IA-1 | Policy and Procedures |
| 161R1-IA-2 | Identification and Authentication (Organizational Users) |
| 161R1-IA-3 | Device Identification and Authentication |
| 161R1-IA-4 | Identifier Management |
| 161R1-IA-5 | Authenticator Management |
| 161R1-IA-8 | Identification and Authentication (Non-Organizational Users) |
| 161R1-IA-9 | Service Identification and Authentication |
C-SCRM Family: Incident Response
| Code | Title |
|---|---|
| 161R1-IR-1 | Policy and Procedures |
| 161R1-IR-2 | Incident Response Training |
| 161R1-IR-3 | Incident Response Testing |
| 161R1-IR-4 | Incident Handling |
| 161R1-IR-5 | Incident Monitoring |
| 161R1-IR-6 | Incident Reporting |
| 161R1-IR-7 | Incident Response Assistance |
| 161R1-IR-8 | Incident Response Plan |
| 161R1-IR-9 | Information Spillage Response |
C-SCRM Family: Maintenance
| Code | Title |
|---|---|
| 161R1-MA-1 | Policy and Procedures |
| 161R1-MA-2 | Controlled Maintenance |
| 161R1-MA-3 | Maintenance Tools |
| 161R1-MA-4 | Nonlocal Maintenance |
| 161R1-MA-5 | Maintenance Personnel |
| 161R1-MA-6 | Timely Maintenance |
| 161R1-MA-7 | Field Maintenance |
| 161R1-MA-8 | Maintenance Monitoring and Information Sharing |
C-SCRM Family: Media Protection
| Code | Title |
|---|---|
| 161R1-MP-1 | Policy and Procedures |
| 161R1-MP-4 | Media Storage |
| 161R1-MP-5 | Media Transport |
| 161R1-MP-6 | Media Sanitization |
C-SCRM Family: Personally Identifiable Information Processing and Transparency
| Code | Title |
|---|---|
| 161R1-PT-1 | Policy and Procedures |
C-SCRM Family: Personnel Security
| Code | Title |
|---|---|
| 161R1-PS-1 | Policy and Procedures |
| 161R1-PS-3 | Personnel Screening |
| 161R1-PS-6 | Access Agreements |
| 161R1-PS-7 | External Personnel Security |
C-SCRM Family: Physical and Environmental Protection
| Code | Title |
|---|---|
| 161R1-PE-1 | Policy and Procedures |
| 161R1-PE-16 | Delivery and Removal |
| 161R1-PE-17 | Alternative Work Site |
| 161R1-PE-18 | Location of System Components |
| 161R1-PE-2 | Physical Access Authorizations |
| 161R1-PE-20 | Asset Monitoring and Tracking |
| 161R1-PE-23 | Facility Location |
| 161R1-PE-3 | Physical Access Control |
| 161R1-PE-6 | Monitoring Physical Access |
C-SCRM Family: Planning
| Code | Title |
|---|---|
| 161R1-PL-1 | Policy and Procedures |
| 161R1-PL-10 | Baseline Selection |
| 161R1-PL-2 | System Security and Privacy Plans |
| 161R1-PL-4 | Rules of Behavior |
| 161R1-PL-7 | Concept of Operations |
| 161R1-PL-8 | Security and Privacy Architectures |
| 161R1-PL-9 | Central Management |
C-SCRM Family: Program Management
| Code | Title |
|---|---|
| 161R1-PM-10 | Authorization Process |
| 161R1-PM-11 | Mission and Business Process Definition |
| 161R1-PM-12 | Insider Threat Program |
| 161R1-PM-13 | Security and Privacy Workforce |
| 161R1-PM-14 | Testing, Training, and Monitoring |
| 161R1-PM-15 | Security and Privacy Groups and Associations |
| 161R1-PM-16 | Threat Awareness Program |
| 161R1-PM-17 | Protecting Controlled Unclassified Information on External Systems |
| 161R1-PM-18 | Privacy Program Plan |
| 161R1-PM-19 | Privacy Program Leadership Role |
| 161R1-PM-2 | Information Security Program Leadership Role |
| 161R1-PM-20 | Dissemination of Privacy Program Information |
| 161R1-PM-21 | Accounting of Disclosures |
| 161R1-PM-22 | Personally Identifiable Information Quality Management |
| 161R1-PM-23 | Data Governance Body |
| 161R1-PM-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research |
| 161R1-PM-26 | Complaint Management |
| 161R1-PM-27 | Privacy Reporting |
| 161R1-PM-28 | Risk Framing |
| 161R1-PM-29 | Risk Management Program Leadership Roles |
| 161R1-PM-3 | Information Security and Privacy Resources |
| 161R1-PM-30 | Supply Chain Risk Management Strategy |
| 161R1-PM-31 | Continuous Monitoring Strategy |
| 161R1-PM-32 | Purposing |
| 161R1-PM-4 | Plan of Action and Milestones Process |
| 161R1-PM-5 | System Inventory |
| 161R1-PM-6 | Measures of Performance |
| 161R1-PM-7 | Enterprise Architecture |
| 161R1-PM-8 | Critical Infrastructure Plan |
| 161R1-PM-9 | Risk Management Strategy |
C-SCRM Family: Risk Assessment
| Code | Title |
|---|---|
| 161R1-RA-1 | Policy and Procedures |
| 161R1-RA-10 | Threat Hunting |
| 161R1-RA-2 | Security Categorization |
| 161R1-RA-3 | Risk Assessment |
| 161R1-RA-5 | Vulnerability Monitoring and Scanning |
| 161R1-RA-7 | Risk Response |
| 161R1-RA-9 | Criticality Analysis |
C-SCRM Family: Supply Chain Risk Management
| Code | Title |
|---|---|
| 161R1-SR-1 | Policy and Procedures |
| 161R1-SR-10 | Inspection of Systems or Components |
| 161R1-SR-11 | Component Authenticity |
| 161R1-SR-12 | Component Disposal |
| 161R1-SR-13 | Supplier Inventory |
| 161R1-SR-2 | Supply Chain Risk Management Plan |
| 161R1-SR-3 | Supply Chain Controls and Processes |
| 161R1-SR-4 | Provenance |
| 161R1-SR-5 | Acquisition Strategies, Tools, and Methods |
| 161R1-SR-6 | Supplier Assessments and Reviews |
| 161R1-SR-7 | Supply Chain Operations Security |
| 161R1-SR-8 | Notification Agreements |
| 161R1-SR-9 | Tamper Resistance and Detection |
C-SCRM Family: System and Communications Protection
| Code | Title |
|---|---|
| 161R1-SC-1 | Policy and Procedures |
| 161R1-SC-18 | Mobile Code |
| 161R1-SC-27 | Platform-Independent Applications |
| 161R1-SC-28 | Protection of Information at Rest |
| 161R1-SC-29 | Heterogeneity |
| 161R1-SC-30 | Concealment and Misdirection |
| 161R1-SC-36 | Distributed Processing and Storage |
| 161R1-SC-37 | Out-of-Band Channels |
| 161R1-SC-38 | Operations Security |
| 161R1-SC-4 | Information in Shared Resources |
| 161R1-SC-47 | Alternative Communications Paths |
| 161R1-SC-5 | Denial-of-Service Protection |
| 161R1-SC-7 | Boundary Protection |
| 161R1-SC-8 | Transmission Confidentiality and Integrity |
C-SCRM Family: System and Information Integrity
| Code | Title |
|---|---|
| 161R1-SI-1 | Policy and Procedures |
| 161R1-SI-12 | Information Management and Retention |
| 161R1-SI-2 | Flaw Remediation |
| 161R1-SI-20 | Tainting |
| 161R1-SI-3 | Malicious Code Protection |
| 161R1-SI-4 | System Monitoring |
| 161R1-SI-5 | Security Alerts, Advisories, and Directives |
| 161R1-SI-7 | Software, Firmware, and Information Integrity |
C-SCRM Family: System and Services Acquisition
| Code | Title |
|---|---|
| 161R1-SA-1 | Policy and Procedures |
| 161R1-SA-10 | Developer Configuration Management |
| 161R1-SA-11 | Developer Testing and Evaluation |
| 161R1-SA-15 | Development Process, Standards, and Tools |
| 161R1-SA-16 | Developer-Provided Training |
| 161R1-SA-17 | Developer Security and Privacy Architecture and Design |
| 161R1-SA-2 | Allocation of Resources |
| 161R1-SA-20 | Customized Development of Critical Components |
| 161R1-SA-21 | Developer Screening |
| 161R1-SA-22 | Unsupported System Components |
| 161R1-SA-3 | System Development Life Cycle |
| 161R1-SA-4 | Acquisition Process |
| 161R1-SA-5 | System Documentation |
| 161R1-SA-8 | Security and Privacy Engineering Principles |
| 161R1-SA-9 | External System Services |
Your Compliance Coverage
If you comply with NIST SP 800-161 Rev 1, you already cover:
Maps to 37 other frameworks
What is NIST SP 800-161 Rev 1 and who does it apply to?
NIST SP 800-161 Rev 1 is a compliance framework from United States with 20 domains and 191 controls. NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. Appendix A is an enhanced overlay on NIST SP 800-53 Rev. 5: it selects the controls that bear on cybersecurity supply chain risk, organizes them into the 20 SP 800-53 control families, and adds C-SCRM supplemental guidance. Two controls, MA-8 and SR-13, are defined by this publication and do not exist in SP 800-53 Rev. 5. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST SP 800-161 Rev 1 actually require?
NIST SP 800-161 Rev 1 has 191 controls organised across 20 domains. The largest domains are C-SCRM Family: Program Management (30 controls), C-SCRM Family: System and Services Acquisition (15 controls), C-SCRM Family: Access Control (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST SP 800-161 Rev 1 do I already cover?
NIST SP 800-161 Rev 1 maps to 37 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (100% coverage), NIST SP 800-53 Rev 5 (99% coverage), C5 (Germany) (85% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST SP 800-161 Rev 1?
Start your NIST SP 800-161 Rev 1 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-161 Rev 1 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 191 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required