Quick-reference card
| Field | Value |
|---|---|
| Control ID | SR-10 |
| Control Name | Inspection of Systems or Components |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Supply Chain Risk Management |
| Baselines | LOW MODERATE HIGH |
| Relevance | Organization (Third Party) |
| Risk Severity | HIGH |
What this control requires
SR-10 requires organizations to inspect systems and system components for signs of tampering after those assets leave organization-controlled areas. It belongs to the Supply Chain Risk Management control family. As a core element of the NIST SP 800-53 catalog, SR-10 addresses a specific verification gap that persists across federal and private-sector environments. Many supply chain risk management programs overlook the physical and logical integrity of hardware and software between the point of manufacture and the point of deployment.
The inspection itself covers both physical and logical tampering. Physical indicators include changes to packaging, broken tamper-evident seals, unexpected modifications to factory labeling, or shifts in the manufacturing location. Logical indicators might include unauthorized firmware modifications, unexpected software configurations, or altered component specifications. Organizations must define the conditions that trigger an inspection, whether that’s a routine schedule, random selection, or specific risk indicators like personnel returning from travel to high-risk locations.
In practice, this control forces organizations to move beyond trusting their supply chain on paper. It demands verifiable processes that confirm components haven’t been altered in transit, storage, or during third-party handling. Without these inspections, compromised hardware or software can enter production environments undetected, creating persistent vulnerabilities that traditional security monitoring won’t catch.
Why it matters
Failure to maintain SR-10 introduces significant audit risk and may result in certification withdrawal or regulatory findings during federal authorization assessments. Organizations pursuing or maintaining a NIST 800-53 compliance posture can’t afford to treat component inspection as optional, since auditors specifically look for documented inspection procedures and evidence of execution.
The broader risk is operational. Tampered components can introduce backdoors, exfiltrate data, or degrade system reliability in ways that are difficult to detect through software-based monitoring alone. When a component’s provenance is uncertain, the entire trust chain built on top of that component becomes suspect.
In practice, the absence of inspection processes creates a blind spot in your security posture that compounds over time. Every unverified component that enters production represents a potential persistent threat that traditional perimeter defenses and endpoint monitoring won’t catch. Organizations that source hardware through multiple tiers of subcontractors face the greatest exposure, since each handoff point introduces an opportunity for tampering that only physical or logical inspection can detect.
For organizations operating under federal requirements, the control applies across all three baselines, meaning there’s no exemption based on system categorization. This universal applicability reflects the severity of supply chain threats and the recognition that even low-impact systems can serve as entry points into more critical environments.
How to implement
For your vendors
The core challenge with SR-10 in a third-party risk management context is that you’re relying on vendors to maintain inspection practices over assets you don’t physically control. Self-attestation alone doesn’t provide adequate assurance that tampering detection occurs consistently.
Start by incorporating targeted questions into your security questionnaires. Ask vendors whether they have a documented inspection policy for systems and components that leave their controlled environments. Request specifics on what triggers an inspection, including whether inspections occur at random intervals, on a defined schedule, or based on risk indicators such as changes in packaging, manufacturing location, or purchasing entities. Ask whether inspections cover both physical tampering (seals, labels, hardware modifications) and logical tampering (firmware integrity, software configuration baselines).
Request evidence beyond policy documents. Effective verification requires inspection reports that show dates, findings, and follow-up actions. Ask for records of random inspections conducted over the past 12 months, along with any assessment results from internal audits or third-party evaluations of their inspection program. Service level agreements and acquisition contracts should include clauses that define inspection obligations and the vendor’s responsibility to notify you of any detected tampering.
Watch for red flags during your review. A vendor that can produce a policy document but no inspection records likely has a control that exists on paper only. Inconsistencies between stated inspection frequency and actual documentation are another warning sign. If a vendor sources components through multiple subcontractors but can’t describe how inspections cascade through the supply chain, that gap represents unmanaged risk.
To verify beyond self-attestation, consider requesting the right to audit inspection processes directly or through an independent assessor. Review the vendor’s supply chain risk management plan for alignment with their stated inspection procedures. Cross-reference acquisition documentation with inspection records to confirm that components identified as high-risk received the inspections described in policy. Where possible, use a vendor risk management platform to centralize and track this evidence across your vendor portfolio.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | Supply chain risk management policy defining inspection triggers, frequency, and scope for systems and components leaving controlled areas |
| Inspection records | Randomized inspection reports documenting dates, components examined, inspection methods used, and findings |
| Assessment results | Third-party or internal audit reports evaluating the effectiveness of tamper detection and inspection processes |
| Acquisition documentation | Procurement contracts and service level agreements specifying vendor inspection obligations and tampering notification requirements |
| Risk management planning | Supply chain risk management plan detailing how inspection requirements integrate with broader risk assessment and mitigation activities |
| System security documentation | System security plan sections addressing component integrity verification procedures and tamper resistance requirements |
| Inter-organizational agreements | Documented agreements between organizations defining shared inspection responsibilities, notification protocols, and escalation procedures for detected tampering |
Cross-framework mapping
No cross-framework mappings are currently configured for SR-10.
Related controls
- AT-03 — Role-based Training: Ensures personnel responsible for conducting inspections receive training on tamper detection techniques and reporting procedures.
- PM-30 — Supply Chain Risk Management Strategy: Establishes the overarching strategy that defines when and how component inspections fit into the organization’s supply chain risk posture.
- SI-04 — System Monitoring: Provides continuous monitoring capabilities that complement periodic physical inspections by detecting logical indicators of tampering in deployed systems.
- SI-07 — Software, Firmware, and Information Integrity: Verifies the integrity of software and firmware through cryptographic mechanisms, supporting the logical inspection requirements of SR-10.
- SR-03 — Supply Chain Controls and Processes: Defines the broader supply chain controls within which component inspection serves as a specific verification activity.
- SR-04 — Provenance: Tracks the origin and custody chain of components, providing the context needed to determine when inspections should be triggered.
- SR-05 — Acquisition Strategies, Tools, and Methods: Governs how acquisition practices incorporate tamper resistance requirements into vendor selection and procurement processes.
- SR-09 — Tamper Resistance and Detection: Specifies the technical mechanisms for tamper resistance and detection that inspections are designed to verify.
- SR-11 — Component Authenticity: Addresses the verification of component authenticity, which inspections help confirm by identifying counterfeit or substituted parts.
Frequently asked questions
What is NIST SP 800-53 SR-10
SR-10 is the NIST SP 800-53 control that requires organizations to inspect systems and system components for evidence of tampering. It applies to assets that have left organization-controlled areas, covering both physical indicators like packaging changes and broken seals, and logical indicators such as unauthorized firmware modifications. The control requires organizations to define specific triggers for inspection, whether those are random checks, scheduled reviews, or risk-based indicators like changes in factory location or purchasing entities.
What happens if SR-10 is not implemented
Without SR-10, organizations lack a structured process for detecting tampered components before they enter production environments. This gap creates persistent, hard-to-detect vulnerabilities that bypass traditional perimeter defenses and software-based monitoring. From a compliance perspective, missing SR-10 implementation introduces audit findings that can delay or prevent federal authorization, since auditors expect documented inspection procedures backed by verifiable inspection reports and assessment results.
How do you audit SR-10
Auditing SR-10 starts with reviewing the organization’s supply chain risk management policy for defined inspection triggers, frequencies, and scope. Auditors then examine records of random inspections and scheduled reviews to verify that inspections occur as documented. Assessment reports, acquisition contracts with tamper notification clauses, and evidence of follow-up actions on inspection findings round out the audit trail. The key is confirming that the control moves beyond policy into demonstrated practice.
What triggers a supply chain component inspection
Defined triggers for SR-10 inspections include changes in component packaging, altered specifications from the original order, shifts in factory location or manufacturing facility, and changes to the entity through which a part is purchased. Personnel returning from travel to high-risk locations can also trigger inspections of any systems or components they carried. Organizations can supplement these risk-based triggers with random inspections and scheduled reviews at an organization-defined frequency, ensuring coverage even when no specific risk indicator is present.