Quick-reference card
| Field | Value |
|---|---|
| Control ID | SR-09 |
| Control Name | Tamper Resistance and Detection |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Supply Chain Risk Management |
| Baselines | HIGH |
| Relevance | Organization (Third Party) |
| Risk Severity | High |
What this control requires
SR-09 requires organizations to implement a tamper protection program that safeguards systems, components, and services from unauthorized modification throughout the supply chain. Most organizations treat physical security and supply chain cybersecurity as separate concerns, but this control forces them together under a single operational mandate.
In practice, you need documented procedures that combine strong identification of components with tamper-resistant packaging, seals, or coatings and tamper-detection mechanisms that reveal whether interference has occurred. The program must cover the full lifecycle of a system component, from acquisition through deployment and ongoing use. Without these protections, you have no reliable way to verify that the hardware or software you received is the same hardware or software you ordered.
The control exists because supply chain threats don’t stop at digital boundaries. Attackers can intercept shipments, substitute counterfeit components, or modify firmware before a device ever reaches your data center. A tamper protection program closes that gap by ensuring you can detect and respond to physical or logical interference at every stage.
Specifically, the official guidance emphasizes that strong identification combined with tamper resistance and tamper detection is essential to protecting systems and components during distribution and when in use. You need both prevention and visibility, not one or the other.
Why it matters
Tamper resistance sits at the intersection of physical security and cyber supply chain risk management, which makes it one of the harder controls to operationalize. Organizations that overlook this control aren’t just accepting a theoretical risk. They’re leaving a verifiable gap that auditors will flag during any NIST SP 800-53 assessment scoped to the HIGH baseline.
Failure to maintain SR-09 introduces direct audit risk and may result in certification withdrawal or regulatory findings. Federal agencies and contractors operating under FISMA or FedRAMP face particular scrutiny here, since the HIGH baseline explicitly requires tamper protections for critical systems.
The challenge compounds when you factor in vendor relationships. If your third-party suppliers can’t demonstrate that their own components and services have tamper protections in place, your organization inherits that exposure. An auditor won’t accept “we trust our vendor” as evidence of compliance.
Beyond audit consequences, the absence of tamper detection creates a blind spot in your security architecture. You lose the ability to verify component integrity at the point of receipt and during operational use, which means compromised hardware or firmware could operate undetected for extended periods.
This risk is particularly acute for organizations that rely heavily on third-party hardware and embedded systems. Without a documented tamper protection program, you also lack the procedural foundation to respond when tampering is suspected, turning a containable incident into an open-ended investigation.
Where this often breaks down is during vendor renewals and contract negotiations. Organizations that don’t have tamper protection requirements baked into their acquisition documentation and service level agreements discover the gap only when an assessor asks for evidence. At that point, retroactively inserting anti-tamper clauses into existing contracts is both costly and time-consuming, and it still won’t produce the historical evidence an auditor expects to see.
How to implement
For your vendors
The core challenge with SR-09 in a third-party context is verification. Vendors will claim their products are tamper-resistant, but you need concrete evidence that a formal tamper protection program exists and covers the components or services you’re procuring. Self-attestation alone doesn’t satisfy this control.
Start by incorporating tamper protection requirements into your security questionnaires. Ask vendors to describe their tamper protection program, including what anti-tamper technologies, tools, and techniques they apply to the specific systems or components you’re purchasing. Request documentation of their tamper resistance and detection procedures, not just a policy statement confirming they exist.
You should ask vendors for specific evidence, including tamper protection program documentation that names the controls applied to your components, cryptographic module validation certificates for components that handle sensitive data, supply chain custody records showing chain-of-custody tracking from manufacturing through delivery, and tamper-evident packaging specifications used during shipment.
Red flags during vendor assessment include vendors who can’t distinguish between tamper resistance (preventing interference) and tamper detection (revealing that interference occurred). Both capabilities are required under SR-09. Another warning sign is a vendor whose tamper protection program applies only to finished products but not to subcomponents sourced from their own suppliers. Similarly, watch for vendors who reference general quality assurance programs but can’t point to specific anti-tamper technologies or techniques applied to the components you’re procuring.
To verify beyond self-attestation, review the vendor’s acquisition contracts and service level agreements for tamper protection clauses. Request access to their supply chain risk management plan and look for specific references to anti-tamper technologies. Where possible, conduct or commission physical inspections of delivered components to confirm that tamper-evident seals and packaging match the vendor’s documented specifications.
The UpGuard Vendor Risk platform helps you centralize vendor questionnaire responses and track evidence artifacts across your supplier ecosystem, giving you a defensible record that your third-party tamper protection requirements are being met.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Tamper protection program | Formal program documentation defining anti-tamper technologies, tools, and techniques applied to systems and components |
| Supply chain risk management policy | Policy and procedures addressing tamper resistance and detection requirements across the acquisition lifecycle |
| Acquisition and procurement records | Contracts and service level agreements specifying tamper protection obligations for suppliers and service providers |
| Component identification and tracking | Provenance records, chain-of-custody logs, and strong identification mechanisms for system components |
| Tamper detection and response procedures | Documented procedures for identifying, reporting, and responding to evidence of tampering during receipt, deployment, and operation |
| System security plan | Security plan sections addressing tamper resistance and detection controls, roles, and responsibilities |
Cross-framework mapping
No applicable cross-framework mappings for this control.
Related controls
- PE-03 — Physical Access Control: Governs physical access protections that complement tamper detection by restricting who can physically reach system components
- PM-30 — Supply Chain Risk Management Strategy: Establishes the organizational strategy within which tamper protection programs operate
- SA-15 — Development Process, Standards, and Tools: Defines development environment protections that reduce opportunities for tampering during the build process
- SI-04 — System Monitoring: Provides the monitoring capabilities that can detect anomalies caused by tampered components during operation
- SI-07 — Software, Firmware, and Information Integrity: Verifies the integrity of software and firmware, which directly supports detection of unauthorized modifications
- SR-03 — Supply Chain Controls and Processes: Establishes the broader supply chain control framework that tamper protection programs fit within
- SR-04 — Provenance: Tracks the origin and custody of components, providing the identification data that tamper detection relies on
- SR-05 — Acquisition Strategies, Tools, and Methods: Addresses procurement practices that should include tamper protection requirements in vendor contracts
- SR-10 — Inspection of Systems or Components: Covers the physical and logical inspection activities that verify tamper protections are intact upon receipt
- SR-11 — Component Authenticity: Ensures components are genuine and unmodified, which is the outcome tamper resistance and detection programs are designed to achieve
Frequently asked questions
What is NIST SP 800-53 SR-09
SR-09 is the NIST SP 800-53 control that requires organizations to implement a tamper protection program for systems, system components, and system services. The program must combine tamper-resistant design with tamper-detection mechanisms to protect against unauthorized modification throughout the supply chain. Strong identification of components is a prerequisite, since detection is only useful when you can verify what the original component should look like.
What happens if SR-09 is not implemented
Organizations that fail to implement SR-09 face audit findings and potential certification withdrawal during NIST SP 800-53 assessments scoped to the HIGH baseline. The absence of a tamper protection program means you can’t verify that delivered components haven’t been modified, substituted, or reverse engineered during transit or storage. For federal agencies and contractors, non-compliance with this supply chain risk management control may trigger corrective action requirements or contract remediation.
How do you audit SR-09
Auditors verify SR-09 by examining whether a tamper protection program exists and whether it addresses the system, system components, and services in scope. They review tamper resistance and detection tools and techniques documentation, acquisition contracts with tamper protection clauses, and service level agreements that specify anti-tamper obligations. Physical inspection of tamper-evident seals and packaging on delivered components may also form part of the assessment.
What are examples of tamper resistance techniques
Tamper resistance techniques include anti-tamper coatings that destroy circuitry when removed, tamper-evident seals and packaging that reveal physical interference, cryptographic module validation that detects firmware modification, and hardware-based secure enclaves that protect sensitive operations from physical probing. These techniques work alongside tamper detection mechanisms, which focus on revealing that interference occurred rather than preventing it outright.