Why: The practice's core — knowing what suppliers and components bring in, and holding suppliers to security expectations — is this requirement's substance: a running process for finding supply chain weaknesses and defined security requirements applied to the suppliers that matter.
What this does not claim: Supports implementation of the requirement rather than completing it: enforcement presumes agreements that carry the requirements, and in OT the sole-source vendor frequently holds the leverage, so 'enforce' degrades to 'document and compensate' more often than the requirement's language admits. The process must also cover suppliers of the broader CUI system, not only those that reach the plant.
- Tier suppliers by consequence and review the critical tier on a cadence
- Track supplier weaknesses like vulnerabilities: recorded, rated, assigned, closed or formally accepted
- Verify component integrity on receipt for the systems that matter most
- Supplier tiering and review records
- A tracked supplier-weakness log with dispositions
- Receipt-verification records for critical components
Where this holds: Strongest for plant-bound suppliers and components; supplier processes for enterprise IT and cloud services need owners outside this practice.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06