Skip to main content
Category: Software Supply Chain Security

SR Control Family

Also known as: SR, Supply Chain Risk Management control family, NIST SP 800-53 SR family
Simply put

The SR control family is a group of related security controls in NIST SP 800-53 that focus on managing supply chain risk for systems and services. It brings together policies and procedures intended to help organizations reduce risks arising from their suppliers, external vendors, and the products and services they provide.

Formal definition

In NIST SP 800-53 (Revision 5), 'SR' is the two-letter identifier for the Supply Chain Risk Management control family, one of the catalog's control families used to organize related security and privacy controls. The family was introduced in Revision 5 as a distinct control family to consolidate supply-chain risk management requirements that address hardware, software, and services across the supply chain, rather than information security alone. According to the evidence, the family comprises a set of controls (described in one source as 12) covering supply-chain policy and procedures, risk management planning, supplier assessment, and related safeguards; the evidence packet does not reliably enumerate each individual control identifier or title, so specific control-level details are not asserted here. As a control family within a broader catalog, SR is typically applied alongside organizational tailoring and baseline selection, and it defines controls to be implemented rather than conferring certification or compliance by itself.

Why it matters

Supply chain compromises can undermine even a well-secured organization, because risk enters through the products, components, and services an entity acquires rather than through its own systems alone. Before NIST SP 800-53 Revision 5, supply-chain concerns were scattered across other control families and treated largely as an extension of information security. Consolidating them into a dedicated SR family signaled that supply-chain risk warrants distinct, explicit treatment covering hardware, software, and services, not information security controls alone.

For risk, procurement, security, and compliance teams, the SR family provides a common reference point for building supply-chain safeguards into system security planning. Because it sits within the broader 800-53 catalog, it is typically applied through baseline selection and organizational tailoring rather than adopted wholesale, which lets programs scale the depth of supplier assurance to the sensitivity and risk tier of a given system or acquisition.

Who it's relevant to

Security and compliance teams using NIST SP 800-53
Teams implementing or assessing systems against the 800-53 catalog use the SR family to organize and select supply-chain controls. Because SR controls are applied through baseline selection and tailoring, these teams determine which controls are in scope for a given system rather than assuming the entire family applies uniformly.
Third-party risk and procurement professionals
Those evaluating suppliers and external vendors can map their diligence and monitoring activities to SR controls covering supplier assessment and supply-chain policy. It is worth noting the family addresses risks across hardware, software, and services, so its relevance extends beyond software-only supply chain concerns.
System owners and authorizing officials
System owners responsible for security planning integrate SR controls into their overall control set, applying them alongside other families. They should recognize that implementing SR controls supports risk reduction but does not, on its own, constitute certification or a guarantee of compliance.

Inside SR

SR-1 (Policy and Procedures)
Establishes and maintains the supply chain risk management policy and associated procedures that govern how the organization applies the rest of the SR family. It defines governance and documentation expectations but does not itself perform technical controls or verification.
SR-2 (Supply Chain Risk Management Plan)
Requires development, review, and updating of a plan for managing supply chain risks associated with the development, acquisition, and operation of systems, system components, and services. The plan is a planning artifact and does not by itself remediate identified risks.
SR-3 (Supply Chain Controls and Processes)
Addresses the establishment of processes and controls, coordinated across relevant stakeholders, to identify and protect against supply chain risks. Effectiveness depends on how the controls are implemented, not on the control's existence alone.
SR-4 (Provenance)
Concerns documenting, monitoring, and maintaining the provenance of systems, system components, and associated data, understanding origin and chain of custody. Provenance records support traceability but do not independently guarantee component integrity.
SR-5 (Acquisition Strategies, Tools, and Methods)
Covers the use of acquisition strategies, contract tools, and procurement methods to reduce supply chain risks. It shapes how risk is managed through acquisition but does not address risks arising after delivery.
SR-6 (Supplier Assessments and Reviews)
Addresses assessment and review of suppliers and, where relevant, their supply chain. Depending on program design, such assessments may be point-in-time and may rely on supplier-provided information rather than independent verification.
SR-7 (Supply Chain Operations Security)
Focuses on operations security (OPSEC) measures to protect supply chain-related information from adversaries. This is distinct from the tamper and authenticity controls addressed elsewhere in the family.
SR-8 (Notification Agreements)
Concerns establishing agreements and procedures with entities for notification of supply chain compromises, vulnerabilities, or related events. It supports information flow but does not itself detect or prevent compromise.
SR-9 (Tamper Resistance and Detection)
Addresses tamper-resistance and tamper-detection measures applied to systems and components across the supply chain and system life cycle. It is one layer of protection and does not by itself validate component authenticity.
SR-10 (Inspection of Systems or Components)
Covers inspection of systems or components to detect tampering. Inspections are typically performed at defined points and may not provide continuous assurance between inspection events.
SR-11 (Component Authenticity)
Addresses anti-counterfeit policies and procedures, including detection and reporting of counterfeit components. It targets authenticity specifically and is separate from tamper detection or provenance.
SR-12 (Component Disposal)
Concerns secure disposal of systems, components, and associated data to prevent information leakage or reuse-based risks. It addresses end-of-life handling rather than acquisition or operational-phase risks.

Common questions

Answers to the questions practitioners most commonly ask about SR.

Is the SR control family only about software supply chain security?
No. While software supply chain concerns are part of its scope, the SR (Supply Chain Risk Management) family in NIST SP 800-53 Rev. 5 addresses supply chain risks across hardware, software, and services. Treating it as limited to software understates its documented coverage, which spans provenance, tamper resistance, component authenticity, and supplier relationships for physical and service components as well as code.
Do SR-9, SR-10, and SR-11 cover supply chain operations security?
No. Supply Chain Operations Security is addressed by SR-7. SR-9 concerns tamper resistance and detection, SR-10 concerns inspection of systems or components, and SR-11 concerns component authenticity. Conflating these controls with operations security is a common mislabeling; each addresses a distinct objective within the family.
Which controls make up the SR family, and how should we account for all of them?
The SR family includes controls such as SR-1 (Policy and Procedures), SR-2 (Supply Chain Risk Management Plan), SR-3 (Supply Chain Controls and Processes), SR-4 (Provenance), SR-5 (Acquisition Strategies, Tools, and Methods), SR-6 (Supplier Assessments and Reviews), SR-7 (Supply Chain Operations Security), SR-8 (Notification Agreements), SR-9 (Tamper Resistance and Detection), SR-10 (Inspection of Systems or Components), SR-11 (Component Authenticity), and SR-12 (Component Disposal). When mapping your program, verify each control against the current NIST SP 800-53 source rather than working from a partial list, since omitting controls such as SR-1, SR-4, SR-7, or SR-8 leaves gaps in coverage.
How does the SR family relate to a broader third-party risk management program?
The SR family typically provides a control baseline for supply chain risk within a NIST SP 800-53-aligned system, but it is not a full third-party risk management program on its own. In many programs it is complemented by processes for supplier onboarding, ongoing monitoring, and contractual oversight. The controls address supply chain risk to systems and components; financial, ESG, or broader geopolitical supplier risks may fall outside their scope and require separate treatment.
Should every SR control be applied to every supplier relationship?
Not necessarily. The applicability and rigor of individual SR controls typically depend on the risk tier of the component or supplier and the assurance requirements of the system. Depending on the baseline and any organization-defined parameters, some controls may be tailored, scoped, or applied more stringently to critical components than to lower-risk ones. The framework leaves many implementation details to organization-defined values.
What are the practical limitations of relying on the SR family?
SR controls provide structure but do not by themselves guarantee visibility beyond the first tier of suppliers, and assessments such as supplier reviews under SR-6 can be point-in-time and become stale. Provenance and authenticity controls depend on the quality of information suppliers provide, and self-attestation is not equivalent to independent verification. Effective use typically pairs these controls with ongoing monitoring and validation rather than one-time onboarding checks.

Common misconceptions

The SR control family covers only software supply chain security.
In NIST SP 800-53 Rev. 5, the SR family addresses supply chain risk broadly across hardware, software, and services, including provenance, acquisition, tamper resistance, component authenticity, and disposal. Treating it as software-only understates its documented scope.
SR-9, SR-10, and SR-11 all concern supply chain operations security.
Supply Chain Operations Security is addressed by SR-7. SR-9 addresses tamper resistance and detection, SR-10 addresses inspection of systems or components, and SR-11 addresses component authenticity (anti-counterfeit). These are distinct control objectives.
Implementing the SR family, or having supplier assessments in place, provides independent verification that suppliers are secure.
Supplier assessments and reviews (SR-6) can be point-in-time and may rely on supplier-provided or self-reported information. The presence of a control such as a policy (SR-1) or plan (SR-2) reflects governance intent, not verified supplier security or a guarantee of risk elimination.

Best practices

Treat the SR family as covering hardware, software, and services rather than scoping it to software supply chain security, and map each control to the corresponding phases of your acquisition and system life cycle.
Distinguish related controls precisely in your implementation documentation, operations security (SR-7), tamper resistance/detection (SR-9), inspection (SR-10), and component authenticity (SR-11), so that objectives and evidence are not conflated.
Anchor your program in the governance controls (SR-1 policy and procedures, SR-2 SCRM plan) but recognize these establish intent and structure; pair them with assessment, inspection, and authenticity controls that generate evidence of actual conditions.
Where supplier assessments (SR-6) rely on self-reported information or are point-in-time, supplement them with ongoing monitoring and, for higher risk tiers, independent verification rather than treating attestations as verified fact.
Use notification agreements (SR-8) to establish clear channels for reporting compromises and vulnerabilities, and define expected timelines and responsibilities so information flow is actionable.
Extend provenance (SR-4) and disposal (SR-12) practices to end-of-life handling and chain-of-custody records, noting that provenance documentation supports traceability but does not by itself guarantee integrity or authenticity.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide