SR-8: Notification Agreements

SR-08 requires organizations to establish formal agreements with supply chain partners that define when and how those partners must repor...

Quick-reference card

FieldValue
Control IDSR-08
Control NameNotification Agreements
FrameworkNIST SP 800-53, Revision 5
Control FamilySupply Chain Risk Management
BaselinesLOW MODERATE HIGH
RelevanceOrganization (Third Party)
Risk SeverityMedium

What this control requires

SR-08 requires organizations to establish formal agreements with supply chain partners that define when and how those partners must report security compromises or assessment findings. Without these agreements, a vendor breach can unfold for weeks before you even know your data or systems are at risk.

In practice, this control means putting documented notification procedures in place with every entity involved in your supply chain risk management program. These agreements must specify what triggers a notification, who receives it, how quickly it must be sent, and what information it must contain. They also cover the sharing of audit results and security assessment outcomes that could affect the integrity of systems or components you rely on.

But the value goes beyond checking a compliance box. Notification agreements create a structured communication channel that lets your incident response team act on threats before they cascade through your environment. When a supplier discovers a compromise in a component you’ve deployed, a well-defined agreement means you hear about it in hours rather than discovering it months later during a routine audit.

Why it matters

Organizations that lack formal notification agreements with their supply chain partners face a structural blind spot in their risk posture. Even mature security programs can’t respond to threats they don’t know about, and vendors have no contractual obligation to alert you without a binding agreement in place. This gap is especially dangerous in environments where critical system components come from multiple tiers of suppliers.

Gaps in notification timelines create compounding risk. When a supplier discovers a compromise but has no defined obligation to report it, your organization loses the window for early containment. Regulatory bodies increasingly treat missing notification agreements as evidence of insufficient supply chain risk management, which can elevate audit findings from observations to material deficiencies.

The consequences extend beyond a single incident. Auditors reviewing your NIST SP 800-53 compliance will look for documented notification procedures within the Supply Chain Risk Management control family as evidence that your supply chain governance is operational, not just aspirational. Missing agreements signal a gap between policy and practice that can trigger remediation requirements across your broader security program.

Specifically, notification agreements also serve a forward-looking function. When vendors share the results of their own security assessments or third-party audits, your organization gains intelligence that can inform procurement decisions, contract renewals, and risk ratings. Without an agreement mandating this flow of information, you’re relying on voluntary disclosure from entities that may have commercial incentives to minimize bad news.

Key compliance risks without notification agreements

  • Audit findings escalation where missing notification procedures are flagged as material control gaps rather than minor observations
  • Regulatory exposure when oversight bodies determine that your organization lacked contractual mechanisms to learn about supply chain compromises in a timely manner
  • Certification jeopardy where authorization to operate decisions are delayed or revoked because supply chain communication controls can’t be demonstrated
  • Contract risk when incidents occur and no documented agreement exists to define liability, notification timelines, or information-sharing obligations between parties

How to implement

For your vendors

The most common failure mode with SR-08 is treating notification agreements as a one-time checkbox during onboarding rather than an enforceable, testable component of your third-party risk management program. Organizations frequently discover that their contracts include vague notification language that wouldn’t hold up under audit scrutiny or, worse, contain no notification provisions at all.

In practice, the fix starts with embedding specific notification clauses into every vendor contract and service level agreement (SLA). These clauses should define the types of events that trigger a notification, including confirmed breaches, suspected compromises, material findings from security assessments, and changes to the vendor’s risk profile that could affect your systems or data.

Specifically, your security questionnaires should ask pointed questions about the vendor’s current notification capabilities. Request evidence of their incident notification procedures, including documented escalation paths, defined notification timelines, and designated points of contact. Ask whether they have an established process for sharing the results of independent security audits or assessments with their customers.

In practice, the evidence you should request during assessments includes copies of the vendor’s incident response notification procedures, sample notification templates, and records of any prior notifications sent to other customers. Red flags include vendors who can’t produce a documented notification process, those who resist contractual notification timelines, or those who claim assessment results are proprietary and can’t be shared.

Verification should go beyond self-attestation. Review whether the vendor’s notification commitments align with what they’ve documented in their own security plans and acquisition procedures. Cross-reference their stated notification timelines against industry standards and your own incident response plan requirements. Where possible, conduct tabletop exercises that test whether the vendor can execute their notification procedures within the agreed timeframe. Using a vendor risk management platform can help you centralize notification tracking, flag vendors missing required agreements, and maintain an auditable record of all supply chain communications.

Evidence examples

Evidence TypeExample Artifact
Supply chain notification policySupply chain risk management policy defining notification triggers, timelines, and escalation procedures for supply chain compromises
Vendor agreements and contractsAcquisition contracts and SLAs containing specific clauses for breach notification, assessment result sharing, and designated points of contact
Inter-organizational notification proceduresDocumented procedures between your organization and supply chain entities outlining communication channels, notification formats, and response expectations
System security documentationSystem security plan sections addressing supply chain protection controls, including notification agreement references and vendor communication protocols
Assessment and audit sharing recordsRecords of security assessment results or audit findings shared by supply chain partners, including any open-source intelligence that informed their conclusions

Cross-framework mapping

No cross-framework mappings are currently configured for this control.

  • IR-04 — Incident Handling: Defines the processes your organization follows once a supply chain notification is received, connecting SR-08’s communication requirements to operational response workflows.
  • IR-06 — Incident Reporting: Governs how incidents identified through supply chain notifications are reported internally and to external authorities, ensuring SR-08 notifications feed into your broader reporting obligations.
  • IR-08 — Incident Response Plan: Establishes the organizational plan that SR-08 notification agreements should reference, aligning vendor notification timelines with your own response and recovery procedures.

Frequently asked questions

What is NIST SP 800-53 SR-08?

SR-08 is a supply chain risk management control that requires organizations to establish formal notification agreements with supply chain entities covering compromises and security assessment results. These agreements define the triggers, timelines, and procedures for how supply chain partners must communicate security events that could affect your systems or system components. The control applies across all three baselines (LOW, MODERATE, and HIGH) and focuses on ensuring that documented inter-organizational communication channels exist before an incident occurs, not after one forces improvised coordination.

What happens if SR-08 is not implemented?

Without SR-08 notification agreements, your organization has no contractual mechanism to require supply chain partners to report compromises or share assessment findings in a timely manner. Auditors will flag the absence of documented inter-organizational notification procedures as a control gap, which can escalate to a plan of action and milestones (POA&M) item requiring remediation. The downstream impact is that compromised system components or services may remain in your environment for extended periods because no agreed-upon communication channel exists to surface the threat. In practice, this control gap also weakens your ability to demonstrate due diligence during regulatory reviews or third-party assessments.

How do you audit SR-08?

Auditing SR-08 starts with verifying that documented agreements and procedures exist between your organization and each entity involved in the supply chain for covered systems and services. Assessors will examine acquisition contracts, service level agreements, and inter-organizational procedures for explicit notification provisions covering supply chain compromises and assessment result sharing. They’ll also look for evidence that these agreements specify defined timelines, designated contacts, and the types of events requiring notification, rather than relying on generic contractual language. Effective audit preparation includes maintaining a current inventory of all supply chain notification agreements mapped to the systems and components they cover.

What should a supply chain notification agreement include?

A supply chain notification agreement should define the specific events that trigger a notification, the maximum allowable timeframe for reporting, and the designated points of contact on both sides. It should also address the sharing of security assessment results, audit findings, and any open-source information that contributed to risk decisions affecting the systems or system components you rely on. Effective agreements include provisions for how notifications are delivered, what information they must contain, and how follow-up communications are handled until the issue is resolved. They should also specify how shared assessment data will be protected and what happens when a supplier fails to meet agreed notification timelines.

Experience superior visibility and a simpler approach to cyber risk management