Quick-reference card
| Field | Value |
|---|---|
| Control ID | SA-01 |
| Control Name | Policy and Procedures |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | System and Services Acquisition |
| Baselines | LOW MODERATE HIGH PRIVACY |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What this control requires
SA-01 requires your organization to develop, document, and distribute a system and services acquisition policy and its implementing procedures. This control targets the gap between having acquisition standards on paper and enforcing them consistently across every procurement decision your teams make.
Your policy must address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance with applicable laws, executive orders, directives, regulations, and standards. It also needs to align with your broader NIST SP 800-53 framework obligations, so the acquisition process doesn’t introduce risk that other controls are designed to prevent.
Beyond the policy itself, you need documented procedures that translate those principles into repeatable steps. You must also designate a specific official responsible for managing the development, documentation, and dissemination of both the policy and the procedures. That designated official owns the lifecycle of these documents, including reviewing and updating the policy and procedures at a defined frequency and following specific triggering events like audit findings, security incidents, or changes in the regulatory landscape. The System and Services Acquisition family contains the full set of controls that this policy underpins.
Why it matters
Most organizations treat acquisition policy as a checkbox exercise, restating control language in a document that collects dust until the next audit cycle. That approach introduces real compliance risk. Auditors don’t stop at verifying that a policy document exists. They check whether the policy addresses all required elements, whether procedures map to the policy’s intent, whether a designated official actively manages both, and whether review cycles reflect current organizational needs.
Failure to maintain SA-01 introduces audit risk and may result in certification withdrawal or regulatory findings. Without a current, actionable acquisition policy, your organization can’t demonstrate that it governs how third-party systems and services enter the environment. That gap undermines every downstream control in the SA family.
The risk compounds when your acquisition policy falls out of alignment with current laws and regulations. A policy drafted three years ago may not account for recent executive orders, updated federal acquisition regulations, or new supply chain risk management requirements. When auditors find misalignment, the finding doesn’t stay isolated to SA-01. It raises questions about your entire governance posture.
Supply chain risk management depends directly on this control. Without acquisition policy and procedures that address how you evaluate, onboard, and monitor service providers, your organization lacks the foundation for managing third-party risk at scale. Governance controls like SA-01 anchor the broader NIST SP 800-53 framework, and without them, downstream technical controls lack the policy foundation they depend on.
What attackers exploit
- Absent or outdated acquisition policies that allow unvetted software, hardware, or services into production environments without security review
- Lack of designated responsibility for policy management, creating accountability gaps where no single official tracks compliance drift
- Missing procedures for supply chain risk evaluation, enabling adversaries to introduce compromised components through vendors that bypassed formal assessment
- Inconsistent coordination among organizational entities, letting business units procure services independently without security team visibility
- Policies that haven’t been updated after regulatory changes, leaving gaps that threat actors target through compliance-adjacent attack paths
How to implement
For your organization
The most common failure here isn’t a missing policy. It’s a policy that exists in name but doesn’t connect to how your procurement teams operate day to day. Start by building the policy around your real acquisition workflows, not the other way around.
Step 1: Designate the responsible official. Assign a specific individual, typically the CISO, procurement director, or a senior risk officer, as the owner of the system and services acquisition policy and procedures. Document this designation formally within your system security plan.
Step 2: Draft the policy with required elements. Your policy must explicitly address purpose, scope, roles and responsibilities, management commitment, coordination among organizational entities, and compliance requirements. Don’t restate NIST control language. Instead, describe what your organization specifically does when acquiring systems and services. Reference applicable laws, executive orders, and directives by name.
Step 3: Develop implementation procedures. Write step-by-step procedures that map each policy statement to an actionable workflow. Include approval gates, security review checkpoints, and documentation requirements for each acquisition stage. Integrate your supply chain risk management plan so that vendor security assessments are part of the standard process.
Step 4: Define review triggers and cadence. Establish a review frequency, typically annual, and specify events that trigger out-of-cycle reviews. Assessment findings, security incidents, organizational restructuring, and changes to applicable regulations should all be listed as triggers.
Step 5: Disseminate and track acknowledgment. Distribute the policy and procedures to all personnel with acquisition responsibilities. Use version-controlled document management to track revisions and ensure staff access current versions.
Common mistakes to avoid: writing a policy that mirrors NIST language without organizational specifics, failing to document procedures separately from the policy, neglecting to update the policy when laws or organizational structures change, and assigning policy ownership to a committee instead of a named individual.
For your vendors
When evaluating whether a vendor meets SA-01, you’re checking whether they govern their own acquisition processes with the same rigor you apply internally. Vendors that lack formal acquisition policy and procedures introduce uncontrolled supply chain risk into your environment.
Questionnaire questions to ask:
- Does your organization maintain a documented system and services acquisition policy? When was it last reviewed?
- Who is the designated official responsible for managing acquisition policy and procedures?
- How do your acquisition procedures address supply chain risk management?
- What events trigger an out-of-cycle policy review?
- How do you ensure your acquisition policy remains consistent with current laws, regulations, and directives?
Evidence to request:
- A copy of the current system and services acquisition policy, with revision history
- System and services acquisition procedures
- Documentation identifying the designated policy owner
- Records of the most recent policy and procedure review
- The vendor’s supply chain risk management plan
Red flags during verification:
- The policy document lacks a revision date or hasn’t been updated in over two years
- No named individual is designated as the policy owner
- Procedures are embedded within the policy document rather than maintained separately
- The policy uses generic NIST language without organization-specific details
- The vendor can’t produce evidence of a defined review cycle or triggering events
Your third-party risk management process should align with NIST SP 800-53 requirements to ensure vendor assessment questionnaires cover governance controls like SA-01 consistently.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Acquisition policy | System and services acquisition policy defining purpose, scope, roles, responsibilities, management commitment, coordination requirements, and applicable compliance obligations |
| Acquisition procedures | Documented procedures detailing approval workflows, security review checkpoints, and procurement steps for system and service acquisitions |
| Supply chain risk management documentation | Supply chain risk management policy and plan specifying vendor evaluation criteria, ongoing monitoring requirements, and risk acceptance thresholds |
| Designated official assignment | Formal designation memo or system security plan section identifying the official responsible for managing acquisition policy and procedures |
| Review and update records | Records of policy and procedure reviews, including dates, triggering events, revision history, and approver sign-offs |
| Privacy and security plans | System security plan and privacy plan sections that reference acquisition policy alignment and control implementation status |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.1 Policies for information security | Partial |
| ISO 27001:2022 | 5.2 Information security roles and responsibilities | Partial |
| ISO 27001:2022 | 5.23 Information security for use of cloud services | Partial |
| ISO 27001:2022 | 5.3 Segregation of duties | Partial |
| ISO 27001:2022 | 5.31 Legal, statutory, regulatory and contractual requirements | Partial |
| ISO 27001:2022 | 5.36 Compliance with policies, rules and standards for information security | Partial |
| ISO 27001:2022 | 5.37 Documented operating procedures | Partial |
| ISO 27001:2022 | 5.4 Management responsibilities | Partial |
| ISO 27001:2022 | 8.1 User end point devices | Partial |
| NIST SP 800-171 Rev 3 | 03.15.01 Policy and Procedures | Partial |
Related controls
- PM-09 — Risk Management Strategy: defines the overarching risk management approach that shapes the scope and priorities of your system and services acquisition policy
- PS-08 — Personnel Sanctions: establishes consequences for personnel who fail to comply with acquisition policy and procedures, reinforcing accountability
- SA-08 — Security and Privacy Engineering Principles: provides the technical design principles that acquisition procedures must reference when evaluating candidate systems and services
- SI-12 — Information Management and Retention: governs how you retain acquisition-related documentation, including policy versions, review records, and procurement evidence
Frequently asked questions
What is NIST SP 800-53 SA-01?
SA-01 requires organizations to develop, document, and disseminate a system and services acquisition policy along with the procedures needed to implement that policy and its associated controls. The control also mandates designating a specific official to manage these documents and establishing a defined review cycle. Every organization subject to NIST SP 800-53 at any baseline level, including privacy, must satisfy SA-01 as a foundational governance requirement.
What happens if SA-01 is not implemented?
Without SA-01, your organization lacks a documented foundation for governing how systems and services enter your environment, which auditors flag as a systemic governance gap. The absence of a supply chain risk management plan tied to acquisition procedures means you can’t demonstrate due diligence in evaluating third-party providers. Regulatory findings from this gap can cascade across the entire SA control family, since every downstream control depends on the policy and procedures SA-01 establishes.
How do you audit SA-01?
Auditors verify that a system and services acquisition policy exists, that it addresses purpose, scope, roles, responsibilities, management commitment, coordination, and compliance with applicable laws and regulations, and that corresponding procedures are documented separately. They also confirm that a designated official is named in the system security plan as responsible for managing the policy lifecycle. Review records must show that both the policy and procedures have been updated at the organization’s defined frequency and in response to triggering events such as audit findings or regulatory changes.
How often should SA-01 policy be reviewed?
NIST SP 800-53 doesn’t prescribe a fixed review frequency for SA-01. Instead, your organization defines the cadence based on its risk tolerance and operational tempo. Most organizations review their system and services acquisition policy annually, with out-of-cycle reviews triggered by events such as security incidents, assessment findings, or changes to applicable executive orders and directives. The review should produce documented evidence of what changed, who approved the update, and when the revised policy was disseminated to personnel with acquisition responsibilities.