SR-11: Component Authenticity

SR-11 requires organizations to build and enforce anti-counterfeit policies and procedures that detect and block counterfeit components b...

Quick-reference card

FieldValue
Control IDSR-11
Control nameComponent Authenticity
FrameworkNIST SP 800-53, Revision 5
Control familySupply Chain Risk Management
BaselinesLOW MODERATE HIGH
RelevanceOrganization (Third Party)
Risk severityHIGH

What this control requires

SR-11 requires organizations to build and enforce anti-counterfeit policies and procedures that detect and block counterfeit components before they enter a system. The control also mandates reporting confirmed counterfeits to the component source, designated external reporting organizations such as CISA, or specified internal personnel.

In practice, this means you need documented rules governing how your organization sources, inspects, and validates system components across the full supply chain risk management lifecycle. The goal isn’t just to react when a counterfeit surfaces. You need mechanisms that catch fraudulent hardware, software, and firmware at the point of acquisition, before they’re installed or integrated.

The requirement exists because counterfeit components create a direct pathway for malicious code injection, system instability, and data exposure. Manufacturers, developers, vendors, and contractors can all be sources of counterfeit components, whether through deliberate tampering or compromised supply chains. Without proactive detection and prevention, an organization inherits risks it can’t see and can’t contain after the fact.

Why it matters

Most organizations treat component authenticity as a procurement checkbox rather than a security control. That gap becomes visible during audits, where the absence of a documented anti-counterfeit policy and verifiable detection procedures can result in findings that stall or revoke a NIST SP 800-53 authorization.

Failure to implement SR-11 introduces direct audit risk and may result in certification withdrawal or regulatory findings. For organizations operating under federal mandates, a missing anti-counterfeit program signals systemic weakness in cyber supply chain risk management posture, one that assessors treat as a high-severity gap.

The compliance consequences compound when you consider that SR-11 sits within the Supply Chain Risk Management family, a control area that federal agencies and their contractors are under increasing pressure to demonstrate maturity in. An undocumented or informal approach to component verification won’t survive a third-party assessment.

Beyond the audit trail, the operational risk is tangible. Counterfeit components can carry embedded backdoors, degrade system reliability, or fail under conditions the original component was designed to handle.

Specifically, when a counterfeit component enters a production environment undetected, the organization loses assurance over the integrity of every system that component touches. Remediation after deployment is far more costly than prevention at the point of acquisition, which is exactly why SR-11 emphasizes both detection and prevention mechanisms rather than response alone.

What attackers exploit

  • Compromised vendor supply chains where counterfeit hardware or firmware is substituted before delivery to the end customer
  • Tampered software packages distributed through legitimate-looking channels but containing embedded malicious code
  • Grey-market components sourced from unauthorized resellers that lack provenance documentation or manufacturer validation
  • Weakened cryptographic modules introduced through counterfeit chips that bypass integrity verification checks
  • Forged certifications and documentation used to make counterfeit components appear to meet required specifications

How to implement

For your vendors

The hardest part of SR-11 in a third-party context is that you can’t inspect what you can’t see. Vendors control their own sourcing, manufacturing, and delivery pipelines, and most standard security questionnaires don’t probe deeply enough into anti-counterfeit practices to reveal gaps.

What to ask in security questionnaires

Start with questions that go beyond policy existence and probe operational specifics. Ask vendors whether they maintain a documented anti-counterfeit policy that covers hardware, software, and firmware components. Request details on their component sourcing practices, specifically whether they procure from original equipment manufacturers (OEMs) or authorized distributors only. Ask whether they verify component provenance through serial number validation, lot traceability, or cryptographic signature checks.

You should also ask vendors whether they have a defined process for reporting counterfeit components to upstream suppliers, regulatory bodies, or impacted customers. A vendor that lacks a reporting procedure likely lacks the detection mechanisms the procedure depends on.

What evidence to request

Don’t rely on self-attestation alone. Request copies of the vendor’s anti-counterfeit policy and supporting procedures. Ask for records of component inspections or verification activities performed during the most recent acquisition cycle. Acquisition contracts and service level agreements (SLAs) should contain clauses requiring component authenticity guarantees and counterfeit reporting obligations.

Where applicable, request the vendor’s supply chain risk management plan and any NIST SP 800-161-aligned documentation. An anti-counterfeit plan that maps to recognized frameworks gives you a concrete artifact to evaluate rather than a general assurance.

Red flags to watch for

Be cautious when a vendor can’t name their component sources or relies heavily on brokers and secondary-market suppliers. Other warning signs include the absence of incoming inspection procedures, no documented process for handling suspected counterfeits, and contracts that don’t reference component authenticity requirements. A vendor risk management program that omits supply chain integrity from its assessment criteria is another indicator of weak SR-11 alignment.

How to verify beyond self-attestation

Cross-reference vendor claims against independent signals. Review whether the vendor’s acquisition contracts include anti-counterfeit clauses. Check whether they participate in industry counterfeit-reporting programs or maintain relationships with organizations like CISA for incident coordination. Where feasible, conduct periodic on-site or virtual audits focused on incoming component inspection processes and chain-of-custody documentation. A vendor risk assessment platform can help you track these verification activities across your vendor portfolio at scale.

Evidence examples

Evidence TypeExample Artifact
Anti-counterfeit policyAnti-counterfeit policy defining detection methods, prevention measures, component sourcing requirements, and roles responsible for enforcement
Anti-counterfeit proceduresDocumented procedures specifying incoming inspection workflows, component verification techniques, and escalation steps for suspected counterfeits
Counterfeit reporting recordsReports submitted to component sources, CISA, or designated internal personnel documenting confirmed or suspected counterfeit system components
Supply chain risk management planSCRM plan addressing component authenticity controls, authorized sourcing requirements, and vendor anti-counterfeit obligations aligned to NIST SP 800-161
Acquisition documentationProcurement records, acquisition contracts, and SLAs containing anti-counterfeit clauses and component authenticity guarantees
Incident response recordsIncident response policy and associated records covering the discovery, containment, and reporting of counterfeit component incidents
Media protection and disposal policyPolicy governing the secure handling and disposal of components identified as counterfeit, preventing re-entry into the supply chain

Cross-framework mapping

No cross-framework mappings are currently configured for this control.

  • PE-03 — Physical Access Control: Restricts physical access to systems and facilities, reducing the opportunity for unauthorized substitution of legitimate components with counterfeit replacements.
  • SA-04 — Acquisition Process: Establishes procurement requirements that can include anti-counterfeit clauses, component provenance verification, and authorized sourcing obligations in acquisition contracts.
  • SI-07 — Software, Firmware, and Information Integrity: Provides integrity verification mechanisms such as cryptographic hashing and digital signatures that support detection of tampered or counterfeit software and firmware components.
  • SR-09 — Tamper Resistance and Detection: Implements physical and logical tamper protections that complement anti-counterfeit controls by making it harder to introduce modified or fraudulent components undetected.
  • SR-10 — Inspection of Systems or Components: Requires inspection activities at designated points in the supply chain, directly supporting the detection mechanisms that SR-11’s anti-counterfeit procedures depend on.

Frequently asked questions

What is NIST SP 800-53 SR-11?

SR-11 requires organizations to develop anti-counterfeit policies and procedures that detect and prevent counterfeit components from entering their systems. The control applies across all three baselines (LOW, MODERATE, HIGH) within the Supply Chain Risk Management family. It also requires reporting confirmed counterfeit system components to the component source, external reporting organizations like CISA, or designated personnel.

What happens if SR-11 is not implemented?

Without SR-11, your organization has no documented mechanism to identify or block counterfeit hardware, software, or firmware before installation. Assessors will flag the absence of an anti-counterfeit policy and counterfeit component reporting procedures as a high-severity finding during NIST SP 800-53 assessments. The gap can delay or prevent authorization decisions and exposes the organization to operational risk from components that may carry embedded vulnerabilities or backdoors.

How do you audit SR-11?

Auditors evaluate SR-11 by examining the anti-counterfeit policy, reviewing anti-counterfeit procedures for detection and prevention measures, and verifying that counterfeit component reporting records exist and name the correct reporting parties. They also inspect acquisition contracts and SLAs for anti-counterfeit clauses and review the supply chain risk management plan for alignment with component authenticity requirements. Interviews with personnel responsible for incoming component inspection confirm that documented procedures are followed in practice.

How do you verify component authenticity in a software supply chain?

You verify software component authenticity by validating cryptographic signatures, checking software hashes against publisher-provided digests, and reviewing software bills of materials (SBOMs) for provenance data. Organizations should source software only from OEMs or authorized distributors and maintain records of verification activities for each acquisition. Automated integrity checking tools can flag components that fail signature validation or arrive from unverified distribution channels.

Experience superior visibility and a simpler approach to cyber risk management