Skip to content

Supply Chain Risk Management (SR)

This page contains all 27 controls and control enhancements in the Supply Chain Risk Management (SR) family from the vendored NIST SP 800-53 Revision 5 OSCAL catalog.

Official NIST OSCAL source

  • Catalog version: 5.2.0
  • OSCAL version: 1.2.2
  • Catalog last modified: May 11, 2026

SR-01 (Policy and Procedures)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
    • 1. [Selection: one or more of: organization-level; mission/business process-level; system-level] supply chain risk management policy that:
      • (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
      • (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
    • 2. Procedures to facilitate the implementation of the supply chain risk management policy and the associated supply chain risk management controls;
  • b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the supply chain risk management policy and procedures; and
  • c. Review and update the current supply chain risk management:
    • 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and
    • 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-02 (Supply Chain Risk Management Plan)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services: [Assignment: organization-defined systems, system components, or system services];
  • b. Review and update the supply chain risk management plan [Assignment: organization-defined frequency] or as required, to address threat, organizational or environmental changes; and
  • c. Protect the supply chain risk management plan from unauthorized disclosure and modification.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-02 (01) (Establish SCRM Team)

FedRAMP Rev5 Baselines: Class BClass CClass D

Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined supply chain risk management activities].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-03 (Supply Chain Controls and Processes)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Establish a process or processes to identify and address weaknesses or deficiencies in the supply chain elements and processes of [Assignment: organization-defined system or system component] in coordination with [Assignment: organization-defined supply chain personnel];
  • b. Employ the following controls to protect against supply chain risks to the system, system component, or system service and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined supply chain controls]; and
  • c. Document the selected and implemented supply chain processes and controls in [Selection: one or more of: security and privacy plans; supply chain risk management plan].

FedRAMP Guidance

CSO must document and maintain the supply chain custody, including replacement devices, to ensure the integrity of the devices before being introduced to the boundary.


External Link for Additional Information: myctrl.tools


SR-03 (01) (Diverse Supply Base)

Employ a diverse set of sources for the following system components and services: [Assignment: organization-defined system components and services].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-03 (02) (Limitation of Harm)

Employ the following controls to limit harm from potential adversaries identifying and targeting the organizational supply chain: [Assignment: organization-defined controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-03 (03) (Sub-tier Flow Down)

Ensure that the controls included in the contracts of prime contractors are also included in the contracts of subcontractors.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-04 (Provenance)

Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [Assignment: organization-defined systems, system components, and associated data].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-04 (01) (Identity)

Establish and maintain unique identification of the following supply chain elements, processes, and personnel associated with the identified system and critical system components: [Assignment: organization-defined supply chain elements, processes, and personnel].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-04 (02) (Track and Trace)

Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [Assignment: organization-defined systems and critical system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-04 (03) (Validate as Genuine and Not Altered)

Employ the following controls to validate that the system or system component received is genuine and has not been altered: [Assignment: organization-defined controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-04 (04) (Supply Chain Integrity — Pedigree)

Employ [Assignment: organization-defined controls] and conduct [Assignment: organization-defined analysis method] to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-05 (Acquisition Strategies, Tools, and Methods)

FedRAMP Rev5 Baselines: Class BClass CClass D

Employ the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: [Assignment: organization-defined strategies, tools, and methods].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-05 (01) (Adequate Supply)

Employ the following controls to ensure an adequate supply of [Assignment: organization-defined critical system components]: [Assignment: organization-defined controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-05 (02) (Assessments Prior to Selection, Acceptance, Modification, or Update)

Assess the system, system component, or system service prior to selection, acceptance, modification, or update.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-06 (Supplier Assessments and Reviews)

FedRAMP Rev5 Baselines: Class CClass D

Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide [Assignment: organization-defined frequency].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-06 (01) (Testing and Analysis)

Employ [Selection: one or more of: organizational analysis; independent third-party analysis; organizational testing; independent third-party testing] of the following supply chain elements, processes, and actors associated with the system, system component, or system service: [Assignment: organization-defined supply chain elements, processes, and actors].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-07 (Supply Chain Operations Security)

Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [Assignment: organization-defined OPSEC controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-08 (Notification Agreements)

FedRAMP Rev5 Baselines: Class BClass CClass D

Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the [Selection: one or more of: notification of supply chain compromises].


FedRAMP Guidance

Follow the FedRAMP Incident Evaluation and Communication rules.


External Link for Additional Information: myctrl.tools


SR-09 (Tamper Resistance and Detection)

FedRAMP Rev5 Baselines: Class D

Implement a tamper protection program for the system, system component, or system service.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-09 (01) (Multiple Stages of System Development Life Cycle)

FedRAMP Rev5 Baselines: Class D

Employ anti-tamper technologies, tools, and techniques throughout the system development life cycle.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-10 (Inspection of Systems or Components)

FedRAMP Rev5 Baselines: Class BClass CClass D

Inspect the following systems or system components [Selection: one or more of: at random; at; upon] to detect tampering: [Assignment: organization-defined systems or system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-11 (Component Authenticity)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and
  • b. Report counterfeit system components to [Selection: one or more of: source of counterfeit component].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-11 (01) (Anti-counterfeit Training)

FedRAMP Rev5 Baselines: Class BClass CClass D

Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware).


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-11 (02) (Configuration Control for Component Service and Repair)

FedRAMP Rev5 Baselines: Class BClass CClass D

Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-11 (03) (Anti-counterfeit Scanning)

Scan for counterfeit system components [Assignment: organization-defined frequency].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SR-12 (Component Disposal)

FedRAMP Rev5 Baselines: Class BClass CClass D

Dispose of [Assignment: organization-defined data, documentation, tools, or system components] using the following techniques and methods: [Assignment: organization-defined techniques and methods].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


Comments