SR-2: Supply Chain Risk Management Plan

SR-02 requires your organization to develop, maintain, and protect a formal plan for managing supply chain risks across the full system l...

Quick-reference card

FieldDetail
Control IDSR-02
Control nameSupply Chain Risk Management Plan
FrameworkNIST SP 800-53 Revision 5
Control familySupply Chain Risk Management
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party)
Risk severityMedium

What this control requires

SR-02 requires your organization to develop, maintain, and protect a formal plan for managing supply chain risks across the full system lifecycle. That lifecycle spans research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal. Unlike controls that address individual supplier assessments, SR-02 demands a documented strategy that governs how you identify, evaluate, and respond to threats introduced through your supply chain.

The plan must be reviewed and updated on a defined schedule, or whenever changes in the threat landscape, organizational structure, or operating environment make the current version inadequate. Organizations that set a review cadence but never trigger ad hoc updates leave themselves exposed during the exact periods when threats shift fastest. The plan also must be protected from unauthorized disclosure and modification, because an exposed plan reveals your risk tolerances and mitigation gaps to adversaries.

In practice, SR-02 functions as the connective tissue between your broader risk management strategy and the tactical controls you apply to individual suppliers and components. Without it, supply chain security efforts tend to become fragmented, reactive, and difficult to audit.

Specifically, the plan must be tailored to the particular program, system, or operational context it governs. A generic template applied uniformly across an organization won’t satisfy the control. Each plan should reflect the unique threat profile, supplier dependencies, and risk tolerances of the systems it covers.

Why it matters

Most organizations treat supply chain risk as a vendor-by-vendor problem rather than a programmatic discipline. SR-02 exists because ad hoc supplier reviews don’t scale, and they leave systemic gaps that no individual assessment can close. A formal supply chain risk management (SCRM) plan forces you to define risk tolerances, assign roles, and establish repeatable evaluation processes before a threat materializes.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Federal agencies and their contractors face particular exposure, since SR-02 is included in all three NIST SP 800-53 baselines (LOW, MODERATE, HIGH), making a documented cyber supply chain risk management plan a baseline expectation for any system operating under federal authorization. An incomplete or outdated plan signals to assessors that your organization lacks the governance structure to manage supply chain threats systematically.

The dependence on external providers across hardware, software, and services continues to increase, and so does the attack surface that comes with it. Threat actors target supply chains precisely because a single compromised supplier can provide access to dozens or hundreds of downstream organizations. A documented plan ensures you have predefined response actions rather than scrambling to improvise when a supplier reports a breach or a component’s integrity comes into question.

The consequences extend beyond compliance. Without a current plan, your organization has no documented basis for deciding which suppliers require deeper scrutiny, which components need integrity verification, or how to respond when a supplier is compromised. Every supply chain decision becomes improvised rather than governed.

The complexity of modern supply chains makes this gap particularly dangerous. Coordinating SCRM activities across procurement, engineering, security, legal, and executive stakeholders requires a shared reference point that defines who does what, when, and to what standard. The plan provides that reference point, turning supply chain risk from a diffuse organizational concern into a managed discipline with clear accountability.

What attackers exploit

  • Counterfeit or tampered components inserted during manufacturing or delivery, bypassing integrity checks that a plan would require
  • Malicious software or hardware embedded by compromised suppliers who were never evaluated against documented risk criteria
  • Poor development practices at subcontractors whose security posture was never baselined because no plan defined evaluation requirements
  • Unauthorized production changes that go undetected when no plan establishes monitoring expectations for critical suppliers
  • Theft of sensitive design data during acquisition or integration phases that lack the protections a plan would prescribe

How to implement

For your organization

The most common failure with SR-02 is treating the plan as a static compliance document rather than an operational tool that drives decisions. Your SCRM plan should be a living reference that stakeholders across procurement, engineering, security, and legal consult when onboarding suppliers, evaluating components, or responding to supply chain incidents.

Step 1: Define scope and risk tolerance. Identify the systems, components, and services that fall within the plan’s coverage. Document your organization’s risk appetite for supply chain threats, specifying which categories of risk (counterfeit parts, single-source dependencies, foreign ownership) require active mitigation versus acceptance.

Step 2: Catalog supply chain threats and safeguards. Build a threat inventory specific to your acquisition and integration processes. Map each threat category (counterfeits, tampering, malicious insertion, poor manufacturing, unauthorized production, data theft) to existing safeguards and identify gaps. This threat-and-safeguard list becomes a key evidence artifact for auditors and the foundation for prioritizing your mitigation investments.

Step 3: Establish evaluation processes. Define how you assess supplier trustworthiness, including criteria for initial qualification, ongoing monitoring, and re-evaluation triggers. Specify what evidence you require from suppliers (security certifications, audit reports, development practice documentation) and how you verify it. A vendor risk management platform can centralize questionnaire distribution, response tracking, and risk scoring for this process.

Step 4: Assign roles and responsibilities. Document who owns the SCRM plan, who reviews supplier risk assessments, who approves component sourcing decisions, and who triggers plan updates. Include escalation paths for supply chain incidents and define which roles have authority to accept residual supply chain risks. Without clear ownership, plan maintenance stalls and accountability gaps emerge during audits.

Step 5: Integrate with existing governance. Your SCRM plan can stand alone or fold into your system security plan and privacy plan, but it must reference and align with your organization’s broader risk management strategy (PM-30). Clarify the distinction between the SCRM plan (SR-02), which is implementation-specific and addresses operational risks for particular systems, and the SCRM strategy (PM-30), which sets organization-wide policy and governance direction.

Step 6: Protect and maintain the plan. Apply access controls that prevent unauthorized disclosure or modification. Store the plan in a document management system with version control, audit logging, and role-based access. Establish a review cadence (annually at minimum, or whenever threat intelligence, organizational changes, or environmental shifts warrant it). Log all revisions with dates, change descriptions, and approval signatures.

Step 7: Document inter-organizational agreements. Where supply chain relationships involve shared responsibilities, capture those arrangements in formal agreements. Service-level agreements, contracts, and memoranda of understanding should reference the SCRM plan’s requirements and specify how suppliers will support your risk evaluation, incident reporting, and compliance verification processes.

Common mistakes to avoid:

  • Confusing the SCRM plan with the SCRM strategy. SR-02 is system-specific and operational; PM-30 is organizational and strategic.
  • Writing a plan that lists risks but doesn’t specify response actions or accountability
  • Failing to tailor the plan to the specific program, system, or operational context it covers
  • Omitting disposal-phase risks, which are explicitly within SR-02’s lifecycle scope
  • Treating the plan as a one-time deliverable rather than maintaining the review and update cadence that assessors will verify

Evidence examples

Evidence TypeExample Artifact
SCRM planDocumented plan defining risk tolerances, threat categories, mitigation strategies, evaluation criteria, roles, and review schedule for covered systems
Supply chain threat inventoryCatalog of identified supply chain threats mapped to specific safeguards, with gap analysis for each system or component category
Acquisition and contract documentationSupplier contracts, service-level agreements, and procurement records specifying security requirements and supply chain provisions
Supplier evaluation recordsCompleted security questionnaires, audit reports, and risk assessment results for critical suppliers
Plan review and update logVersion history showing review dates, change rationale, responsible parties, and approvals for each plan revision
Access control documentationAccess control lists, permission records, and protection mechanisms applied to the SCRM plan to prevent unauthorized disclosure or modification
Lifecycle proceduresSystem development lifecycle documentation covering supply chain considerations from design through disposal

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.19 Information security in supplier relationshipsPartial
ISO 27001:20225.20 Addressing information security within supplier agreementsPartial
ISO 27001:20225.21 Managing information security in the ICT supply chainPartial
ISO 27001:20228.30 Outsourced developmentPartial
NIST SP 800-171 Rev 303.17.01 Supply Chain Risk Management PlanPartial
  • CA-02 — Control Assessments: provides the assessment methodology used to evaluate whether the SCRM plan meets its stated objectives and remains effective
  • CP-04 — Contingency Plan Testing: validates that supply chain disruption scenarios are addressed in continuity planning and that recovery procedures account for supplier dependencies
  • IR-04 — Incident Handling: defines how supply chain security incidents are detected, reported, and resolved when a threat identified in the SCRM plan materializes
  • MA-02 — Controlled Maintenance: ensures that maintenance activities performed by suppliers or third parties follow the security requirements established in the SCRM plan
  • MA-06 — Timely Maintenance: addresses the risk of delayed maintenance from supply chain dependencies, which the SCRM plan should account for in its risk tolerances
  • PE-16 — Delivery and Removal: governs physical custody controls during component delivery and disposal, two lifecycle phases explicitly covered by SR-02
  • PL-02 — System Security and Privacy Plans: can host the SCRM plan as an integrated section and must reference supply chain risk considerations
  • PM-09 — Risk Management Strategy: establishes the organizational risk framework that the SCRM plan implements at the system or program level
  • PM-30 — Supply Chain Risk Management Strategy: sets the organization-wide SCRM policy and governance direction that SR-02 operationalizes into a system-specific plan
  • RA-03 — Risk Assessment: produces the risk analysis that informs which supply chain threats the SCRM plan must address and prioritize

Frequently asked questions

What is NIST SP 800-53 SR-02

SR-02 requires organizations to develop a formal plan for managing supply chain risks across the full system lifecycle, from research and development through disposal. The plan must document risk tolerances, mitigation strategies, evaluation processes, and roles and responsibilities tailored to the specific systems and operational context it covers. Unlike the broader SCRM strategy defined in PM-30, the SR-02 plan is implementation-specific and addresses operational risks for particular systems or programs. It also must be reviewed on a defined schedule and protected from unauthorized access or changes.

What happens if SR-02 is not implemented

Without an SCRM plan, your organization has no documented basis for evaluating supplier trustworthiness, responding to supply chain incidents, or demonstrating due diligence during audits. Assessors will flag the absence of a plan as a direct control failure, which can jeopardize authorization to operate and result in regulatory findings. The gap also leaves acquisition and contract documentation without a governing framework, meaning procurement decisions happen without formalized security requirements for suppliers. In federal environments, this gap may prevent systems from receiving or maintaining an authorization to operate.

How do you audit SR-02

Auditors verify that a documented SCRM plan exists and that it addresses risks across each lifecycle phase, including research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal. They review the plan’s version history to confirm it has been updated at the required frequency and examine access control records to ensure protection against unauthorized disclosure and modification. Assessors also check that the plan includes a supply chain threat inventory with mapped safeguards, defined evaluation processes for suppliers, and assigned roles for plan ownership and review. Expect auditors to request your acquisition documentation, service-level agreements, and inter-organizational agreements to verify that the plan’s requirements flow through to actual supplier relationships.

What should a supply chain risk management plan include

An SCRM plan should include your organization’s supply chain risk tolerance levels, a catalog of identified threats with corresponding mitigation strategies, evaluation criteria and processes for assessing supplier security posture, and clearly assigned roles and responsibilities for plan governance. The plan should also define its review and update cadence, specify how inter-organizational agreements incorporate supply chain provisions, and document the access controls that protect the plan itself from tampering or exposure.

Beyond these core elements, the plan should address how you justify the measures taken, including the rationale for accepting certain risks and mitigating others. Each plan must be tailored to the specific program, system, or operational context it governs rather than applied as a generic template across the entire organization.

Experience superior visibility and a simpler approach to cyber risk management