SR Control Family
The SR control family is a group of related security controls in NIST SP 800-53 that focus on managing supply chain risk for systems and services. It brings together policies and procedures intended to help organizations reduce risks arising from their suppliers, external vendors, and the products and services they provide.
In NIST SP 800-53 (Revision 5), 'SR' is the two-letter identifier for the Supply Chain Risk Management control family, one of the catalog's control families used to organize related security and privacy controls. The family was introduced in Revision 5 as a distinct control family to consolidate supply-chain risk management requirements that address hardware, software, and services across the supply chain, rather than information security alone. According to the evidence, the family comprises a set of controls (described in one source as 12) covering supply-chain policy and procedures, risk management planning, supplier assessment, and related safeguards; the evidence packet does not reliably enumerate each individual control identifier or title, so specific control-level details are not asserted here. As a control family within a broader catalog, SR is typically applied alongside organizational tailoring and baseline selection, and it defines controls to be implemented rather than conferring certification or compliance by itself.
Why it matters
Supply chain compromises can undermine even a well-secured organization, because risk enters through the products, components, and services an entity acquires rather than through its own systems alone. Before NIST SP 800-53 Revision 5, supply-chain concerns were scattered across other control families and treated largely as an extension of information security. Consolidating them into a dedicated SR family signaled that supply-chain risk warrants distinct, explicit treatment covering hardware, software, and services, not information security controls alone.
For risk, procurement, security, and compliance teams, the SR family provides a common reference point for building supply-chain safeguards into system security planning. Because it sits within the broader 800-53 catalog, it is typically applied through baseline selection and organizational tailoring rather than adopted wholesale, which lets programs scale the depth of supplier assurance to the sensitivity and risk tier of a given system or acquisition.
Who it's relevant to
Inside SR
Common questions
Answers to the questions practitioners most commonly ask about SR.
