Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.17.02OFFICIAL TITLEPENDING NIST SME REVIEW

03.17.02Acquisition Strategies, Tools, and Methods

03.17 Supply Chain Risk Management · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Develop and implement acquisition strategies, contract tools, and procurement methods to identify, protect against, and mitigate supply chain risks.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Supply chain risk is cheapest to handle at purchase time. This requirement moves security into the buying process itself — the questions asked before a product or supplier is chosen, the obligations the contract carries, and the sourcing choices (authorized channels, provenance expectations) that reduce the chance of counterfeit or compromised components ever arriving.

Across revisions

New in Rev. 3 as part of the new Supply Chain Risk Management family; no Rev. 2 counterpart requirement existed.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: The practice puts security into plant purchasing — vetting vendors before selection, expecting component provenance, involving OT in procurement decisions — which is this requirement's acquisition-time machinery applied to the OT slice of the supply chain.

What this does not claim: May partially address the requirement, whose scope is organization-wide acquisition strategy, contract tooling, and procurement method; purchases outside the plant — enterprise software, cloud services, IT hardware — need the same machinery from other owners. OT vendor reality also limits leverage: sole-source control system suppliers accept contract terms that large buyers can demand and small manufacturers often cannot.

Practice-side activities
  • Vet suppliers and components before purchase, with OT input on consequence
  • Carry security terms — notification, provenance, support commitments — into OT purchase agreements where negotiable
Evidence this produces
  • Pre-purchase vetting records for OT acquisitions
  • Purchase agreements carrying security terms, with documented residual risk where terms were refused

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Add a security gate to procurement that scales with consequence: a component destined for the CUI environment earns provenance and support-lifecycle scrutiny a printer cable does not.
  • Build the contract language once — security requirements, vulnerability disclosure, incident notification, right to assess — and reuse it across purchases.
  • Buy through authorized channels for anything touching the CUI environment; grey-market sourcing is where counterfeit components enter.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The procurement checklist or gate showing security applied before purchase
  • Contract templates or clauses carrying supply chain obligations
  • A sampled acquisition showing the strategy operating end to end

Suggested owners, derived from the mapped practices and artifacts: Procurement + OT · IT leader or compliance lead. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

No direct Rev. 2 counterpart — this requirement is new in Rev. 3. Open the transition crosswalk →

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated