K06 assurance and procurement architecture

NIST, NTIA, and CISA supply-chain assurance Official-Source Review

Direct answer

NIST publishes multilevel C-SCRM guidance and a final 2026 supplier due-diligence quick-start guide.

Authority and evidence boundary. K06 publishes reference architecture, source review, machine-checkable dependencies, procurement scope, and test-evidence formats. These records do not certify a facility, award a contract, authorize an operation, prove deployment, establish current operation, or transfer regulatory or command authority.

Supported bounded propositions

  • NIST publishes multilevel C-SCRM guidance and a final 2026 supplier due-diligence quick-start guide.
  • NTIA and CISA publish software and hardware bill-of-materials transparency guidance.

Unavailable or unresolved

  • Bills of materials do not prove absence of defects, compromise, counterfeit components, or installed-state equivalence.
  • Contract-specific completeness and data rights remain unresolved until acquisition.

Official source records

NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices · NIST SP 1326 — Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide · NTIA — The Minimum Elements for a Software Bill of Materials · CISA Hardware Bill of Materials Framework for Supply Chain Risk Management

Currentness qualification

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Machine-readable review