Quick-reference card
| Field | Value |
|---|---|
| Control ID | SR-03 |
| Control Name | Supply Chain Controls and Processes |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | Supply Chain Risk Management |
| Baselines | LOW MODERATE HIGH |
| Implementation Level | First Party and Third Party |
| Relevance | Organization and System Level (Third Party) |
| Risk Severity | CRITICAL |
What this control requires
SR-03 requires organizations to identify weaknesses in their supply chain and apply controls that reduce the risk those weaknesses introduce. This control sits within the NIST SP 800-53 Supply Chain Risk Management family and applies at LOW, MODERATE, and HIGH baselines, meaning every federal system and most organizations benchmarking against NIST must address it.
In practice, SR-03 breaks into three obligations. First, you establish a repeatable process to find and address deficiencies in your supply chain elements, which include the organizations, tools, and entities involved in design, manufacturing, acquisition, delivery, integration, maintenance, and disposal of systems and components. Second, you select and enforce controls that protect against supply chain risks and limit damage when supply chain events occur. Third, you document everything in your security and privacy plans, your supply chain risk management (SCRM) plan, or equivalent documentation.
The “so what” behind SR-03 is straightforward. Supply chains are a trust boundary, and every handoff between your organization and a supplier, integrator, or service provider introduces risk that you don’t directly control. Without a deliberate process to surface those risks and apply controls to them, you’re accepting exposure you haven’t measured.
Why it matters
Most organizations treat supply chain risk as a procurement checkbox rather than an ongoing security discipline. That gap between policy and practice is where audit findings accumulate and where adversaries find leverage.
Failure to maintain SR-03 introduces direct audit risk. Federal agencies and contractors operating under FISMA, FedRAMP, or CMMC face certification withdrawal or regulatory findings when assessors can’t verify documented supply chain controls. For private-sector organizations using NIST SP 800-53 as a benchmark, the absence of these controls signals a governance gap that auditors and customers will flag.
The risk compounds because supply chains span multiple organizations, geographies, and technology stacks. A vulnerability in a single supplier’s firmware development process or shipping procedure can propagate across every customer that integrates that component. You can’t inspect what you haven’t inventoried, and you can’t protect what you haven’t assessed.
Supply chain attacks have grown more sophisticated because they exploit the trust relationships between organizations. Adversaries target the seams between buyer and supplier, where visibility drops and accountability blurs.
What attackers exploit
- Unvetted software dependencies: Adversaries inject malicious code into open-source libraries or commercial software updates before they reach downstream customers.
- Weak supplier personnel security: Insufficient background checks or access controls at supplier organizations give insiders or compromised accounts a path into your environment.
- Gaps in hardware provenance: Counterfeit or tampered components enter supply chains when organizations lack verification procedures for hardware authenticity and integrity.
- Inadequate shipping and handling controls: Physical interception or modification of components during transit introduces risks that digital-only security programs miss.
- Opaque subcontractor chains: When your direct supplier outsources to entities you haven’t assessed, each additional tier multiplies the attack surface you can’t see.
How to implement
For your vendors
The most common failure mode with SR-03 isn’t that organizations skip vendor assessments entirely. It’s that they treat a completed security questionnaire as proof of compliance rather than the starting point for verification.
When you assess a vendor against SR-03, your security questionnaire should go beyond generic security questions and target supply chain-specific controls. Ask vendors to describe the process they use to identify weaknesses in their own supply chain elements, including their sub-processors and component suppliers. Request documentation of the specific controls they’ve implemented to protect against supply chain risks, not just a statement that controls exist.
Specifically, ask for these artifacts during the assessment:
- Their SCRM plan or the supply chain section of their security plan
- An inventory of critical system components and their sourcing
- Documentation of their supplier vetting and onboarding procedures
- Evidence of personnel security programs for staff who handle sensitive components
- Configuration management procedures that maintain provenance tracking
- Shipping and handling protocols for physical components
Red flags during assessment include vendors who can’t produce a documented SCRM process, who lack visibility into their own subcontractors, or who haven’t updated their supply chain risk assessments in over 12 months. Vendors who answer supply chain questions with generic information security policies rather than supply chain-specific controls are another warning sign.
To verify beyond self-attestation, request evidence of recent internal or third-party audits that specifically evaluated supply chain controls. Review their acquisition documentation and service level agreements (SLAs) for supply chain security clauses. Cross-reference their stated controls against their actual contracts with sub-suppliers where possible. A vendor risk management platform can help you centralize this evidence collection, track assessment status across your vendor portfolio, and flag gaps before they become audit findings.
The goal isn’t to audit every vendor at the same depth. Tier your vendors by the criticality of the components or services they provide, and concentrate your deepest scrutiny on those whose supply chain failures would have the greatest impact on your operations.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| SCRM policy and procedures | Supply chain risk management policy defining roles, risk tolerance thresholds, and escalation procedures for supply chain events |
| SCRM strategy and plan | Supply chain risk management plan documenting the process for identifying supply chain weaknesses, selected controls, and coordination with supply chain personnel |
| System and component inventory | Inventory of critical system components identifying suppliers, sourcing details, and component criticality ratings |
| Acquisition and procurement documentation | Purchase orders, solicitation documents, and acquisition contracts containing supply chain security requirements and clauses |
| Service level agreements | SLAs with suppliers specifying supply chain security obligations, incident notification requirements, and right-to-audit provisions |
| Security and privacy plans | System security plan and privacy plan sections documenting the selected and implemented supply chain processes and controls |
| Risk register | Risk register entries covering identified supply chain risks, associated controls, and residual risk ratings |
Cross-framework mapping
| Framework | Control | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.20 Addressing information security within supplier agreements | Partial |
| ISO 27001:2022 | 5.21 Managing information security in the ICT supply chain | Partial |
| NIST SP 800-171 Rev 3 | 03.17.03 Supply Chain Requirements and Processes | Partial |
Related controls
- CA-02 — Control Assessments: validates that supply chain controls are tested and evaluated as part of the broader control assessment process.
- MA-02 — Controlled Maintenance: ensures maintenance activities on system components follow documented procedures, reducing supply chain risk during servicing.
- MA-06 — Timely Maintenance: requires maintenance to happen within defined timeframes, preventing delays that leave supply chain vulnerabilities unpatched.
- PE-03 — Physical Access Control: restricts physical access to facilities where supply chain components are stored, processed, or maintained.
- PE-16 — Delivery and Removal: governs the receipt and removal of system components, protecting against tampering during physical handoffs.
- PL-08 — Security and Privacy Architectures: integrates supply chain risk considerations into the overall security architecture of the system.
- PM-30 — Supply Chain Risk Management Strategy: establishes the organization-wide SCRM strategy that SR-03 implements at the system level.
- SA-02 — Allocation of Resources: ensures that adequate resources are budgeted for supply chain risk management activities.
- SA-03 — System Development Life Cycle: embeds supply chain controls into each phase of the development lifecycle, from design through disposal.
- SA-04 — Acquisition Process: defines the security requirements that must be included in acquisition contracts, directly supporting SR-03’s documentation obligations.
Frequently asked questions
What is NIST SP 800-53 SR-03?
SR-03 is the NIST SP 800-53 control that requires organizations to establish processes for identifying supply chain weaknesses, apply controls to mitigate supply chain risks, and document those processes in their security plans or SCRM plan. It applies across LOW, MODERATE, and HIGH baselines, making it a foundational requirement for any organization aligning with NIST. The control covers the full lifecycle of supply chain elements, from design and manufacturing through maintenance and disposal.
What happens if SR-03 is not implemented?
Without SR-03, your organization lacks a documented process for identifying and addressing weaknesses in supply chain elements and processes, which creates direct audit exposure. Assessors evaluating your systems will flag the absence of documented supply chain controls in your security plans and SCRM plan as a material finding. This gap can result in certification delays, failed audits, or regulatory action, depending on your compliance obligations. It also leaves you unable to demonstrate due diligence if a supply chain event affects your operations.
How do you audit SR-03?
Auditors verify SR-03 by examining whether the organization has established a documented process to identify and address supply chain weaknesses, coordinated with designated supply chain personnel. They review the SCRM plan, acquisition contracts, service level agreements, and system component inventory documentation to confirm that supply chain controls are selected, implemented, and recorded. Assessors also check that the selected controls are documented in the security and privacy plans or equivalent records, not just described verbally during interviews.
What is supply chain risk management in NIST 800-53?
Supply chain risk management in NIST 800-53 is the set of controls in the SR family that address risks arising from the design, development, manufacturing, acquisition, delivery, integration, and disposal of systems and components. These controls require organizations to develop an SCRM strategy, implement supply chain processes at the system level, and maintain documentation that demonstrates how supply chain risks are identified and mitigated. SR-03 sits at the center of this family by translating the organization-wide SCRM strategy into specific, system-level controls and processes.