Quick-reference card
| Field | Value |
|---|---|
| Control ID | SR-06 |
| Control Name | Supplier Assessments and Reviews |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | Supply Chain Risk Management |
| Baselines | MODERATE, HIGH |
| Relevance | Organization (Third Party) |
| Risk Severity | High |
What this control requires
SR-06 requires you to assess and review the cybersecurity risks that suppliers, contractors, and their subcontractors introduce to your organization. This control goes beyond accepting vendor self-attestations at face value, demanding that you evaluate supplier risk management processes, foreign ownership, control or influence (FOCI) considerations, and how well each supplier manages risk across its own supply chain.
In practice, this means building a structured, repeatable process for evaluating the security posture of every supplier that touches your systems, components, or services. Assessments should cover documented security processes and controls, open-source intelligence about the supplier’s track record, and publicly available information that might reveal poor development practices, data spillage, or counterfeit components. You can conduct these assessments internally or engage an independent third party to perform them.
The control also recognizes that supply chain risk doesn’t stop at your direct suppliers. Your organization must evaluate whether each supplier has the capability to assess its own second-tier and third-tier subcontractors. Where applicable, you may need to share assessment results with partner organizations, provided the sharing aligns with relevant policies, agreements, or contractual obligations.
Why it matters
Most organizations treat supplier assessments as a procurement checkbox rather than a continuous risk management discipline. That gap leaves a blind spot where compromised or negligent suppliers can introduce vulnerabilities into your environment without detection. The consequences aren’t hypothetical; they’re audit findings, certification withdrawals, and regulatory penalties.
Failure to maintain SR-06 introduces direct compliance risk for any organization operating under NIST SP 800-53 moderate or high baselines. Auditors expect documented evidence that supplier risk assessments occur at a defined frequency, that the methodology covers the full scope of supply chain risk, and that findings feed back into risk management decisions. Without that evidence, your authorization to operate is at stake.
The risk extends beyond audit readiness. Suppliers with weak security practices, undisclosed foreign ownership or influence, or limited visibility into their own subcontractors create attack vectors that you can’t detect through perimeter monitoring alone. A supplier with poor development controls may ship components with embedded vulnerabilities. A contractor with inadequate personnel screening may expose sensitive data through insider threats.
Regulatory expectations around supply chain risk management are tightening across sectors. Federal agencies, defense contractors, and critical infrastructure operators face increasing scrutiny over how they vet and monitor their supplier ecosystems. Failing to demonstrate a mature vendor security review process can result in lost contracts, regulatory findings, or exclusion from procurement opportunities.
The following list describes common weaknesses that adversaries and auditors target when supplier assessments are absent or insufficient.
- Undisclosed subcontractor dependencies where second-tier and third-tier suppliers introduce risk that the primary supplier doesn’t monitor or report
- Inadequate FOCI evaluation that fails to identify foreign ownership, control, or influence over suppliers handling sensitive systems or data
- Reliance on self-attestation alone without independent verification of supplier security controls, documented processes, or incident history
- Inconsistent assessment frequency where supplier reviews happen only at onboarding and never recur, missing changes in the supplier’s risk posture over time
How to implement
For your vendors
The core challenge with SR-06 implementation isn’t designing a questionnaire; it’s building a process that produces reliable, verifiable evidence of supplier risk posture at a defined cadence. Most organizations default to annual self-assessment forms, but that approach misses real-time changes in supplier risk and rarely covers second-tier dependencies.
Start by defining the scope and frequency of your supplier assessments. Not every supplier requires the same depth of review. Categorize vendors by criticality, based on the sensitivity of data they access, the systems they touch, and their role in your supply chain. High-criticality suppliers should undergo comprehensive assessments at least annually, with continuous monitoring between formal reviews. Lower-risk suppliers may follow a lighter review cycle, but you should still reassess them when contracts renew or their risk profile changes.
Your supplier risk assessment process should include structured security questionnaires that address the specific requirements of SR-06. Key areas to cover include supply chain risk management policies, incident response capabilities, personnel screening practices, and FOCI disclosures. Ask suppliers to describe how they assess and monitor their own subcontractors, since SR-06 explicitly requires evaluation of second-tier and third-tier supplier management.
Don’t rely solely on questionnaire responses. Request supporting evidence such as independent audit reports (SOC 2 Type II, ISO 27001 certificates), penetration test summaries, vulnerability management metrics, and documented supply chain risk management plans. Cross-reference supplier claims against publicly available information, including regulatory filings, breach history databases, and open-source intelligence feeds.
Watch for red flags during the assessment. These include suppliers that can’t produce documented security policies, resistance to sharing audit reports, gaps in subcontractor oversight, undisclosed changes in ownership or corporate structure, and evidence of past security incidents without documented remediation. Using standardized vendor assessment questionnaires helps ensure consistent coverage across your supplier portfolio and makes it easier to compare risk profiles.
For organizations managing large supplier ecosystems, a vendor risk management platform can automate questionnaire distribution, track assessment completion, aggregate risk scores, and flag suppliers whose posture has changed since the last review. Automation doesn’t replace professional judgment, but it ensures that assessment cycles don’t slip and that no supplier falls through the cracks.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Supply chain risk management policy | Policy document defining supplier assessment criteria, frequency, scope, roles, and escalation procedures for identified risks |
| Supply chain risk management plan and strategy | Strategic plan outlining the organization’s approach to identifying, evaluating, and mitigating supply chain risks, including FOCI assessment methodology |
| Supplier due diligence records | Completed assessment questionnaires, risk scoring matrices, FOCI evaluation forms, and supporting documentation for each assessed supplier |
| Acquisition and procurement procedures | Documented procedures for integrating security requirements into supplier selection, contract terms, and onboarding workflows |
| Independent assessment reports | Third-party audit reports, SOC 2 Type II attestations, or ISO 27001 certificates collected from suppliers as part of the verification process |
| System security plan | Security plan sections documenting supply chain protection controls, supplier monitoring requirements, and integration with organizational risk management |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.22 Monitoring, review and change management of supplier services | Partial |
| NIST SP 800-171 Rev 3 | 03.11.01 Risk Assessment | Partial |
Related controls
- SR-03 — Supply Chain Controls and Processes: establishes the foundational supply chain protection controls that SR-06 assessments evaluate suppliers against
- SR-05 — Acquisition Strategies, Tools, and Methods: defines the procurement strategies and acquisition tools that inform how supplier assessments are scoped and conducted
Frequently asked questions
What is NIST SP 800-53 SR-06?
SR-06 is the NIST SP 800-53 control that requires organizations to assess and review the cybersecurity risks introduced by their suppliers, contractors, and subcontractors. It covers evaluation of supplier security processes, foreign ownership, control or influence (FOCI), and the supplier’s ability to manage risk across second-tier and third-tier dependencies. The control applies to moderate and high baselines and expects assessments to occur at a defined frequency with documented results.
What happens if SR-06 is not implemented?
Without SR-06, your organization lacks documented evidence that supplier risks are being assessed, which creates a direct gap in your supply chain risk management plan. Auditors reviewing NIST SP 800-53 compliance will flag the absence of supplier due diligence reviews as a control failure. This gap can result in delayed or denied authorization to operate, regulatory findings, and increased exposure to supply chain vulnerabilities that go undetected because no structured review process exists.
How do you audit SR-06?
Auditing SR-06 starts by verifying that the organization has a documented supply chain risk management policy that defines assessment scope, criteria, and frequency. Auditors then examine supplier due diligence records to confirm that assessments have been completed for relevant suppliers, including FOCI evaluations and reviews of subordinate subcontractor management. They also check whether assessment results are shared with partner organizations in accordance with applicable agreements and whether findings feed into the organization’s risk management decisions.
How often should you assess suppliers under NIST 800-53?
SR-06 requires supplier assessments at an organization-defined frequency, which means you set the cadence based on supplier criticality and risk. High-criticality suppliers that access sensitive data or systems should undergo formal assessments at least annually, with continuous monitoring between reviews. Lower-risk suppliers may follow a less frequent cycle, but you should reassess whenever contracts renew, the supplier’s risk profile changes, or new supply chain risk management strategy requirements emerge.