Revalidated public source record

NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices

Source scope

Final NIST C-SCRM guidance for identifying, assessing, and mitigating supply-chain risk across organizational levels and system life cycles.

Publisher, edition, and currentness

Source identity and K03 revalidation
PublisherNational Institute of Standards and Technology
Claim statusCURRENT TECHNICAL STANDARD
Version or editionRevision 1 Update 1
Publication statusFINAL
Publication date2024-11-01
Official locationhttps://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
K03 revalidated2026-08-15T23:30:00Z
Currentness assessmentPoint-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Superseded byNo successor is assigned in the current source catalog.

Claim-level support

Each row records the precise proposition this corpus draws from an official section. The citation does not authorize broader conclusions than the stated proposition.

Exact sections and supported propositions
SectionProposition supported in this corpusOfficial location
Abstract and C-SCRM program scopeThe publication integrates C-SCRM into multilevel risk-management activity, policy, plans, and product or service assessments.Official section

How this source may be used

  • Confirm that the official edition, jurisdiction, and status remain current before high-stakes reliance.
  • Cite the exact section supporting the proposition rather than the publication title alone.
  • Keep technical conformance separate from factual truth, legal authority, moral status, and institutional operation.
  • Record retrieval, correction, supersession, and purpose qualification.

Limitations

An official source can still be irrelevant, incomplete, stale, disputed, or unsuitable for a named decision. A standard can define an interchange or security mechanism without resolving personhood, citizenship, sovereignty, consciousness, consent, legal competence, or factual truth. A statute can regulate systems without recognizing Machine Intelligence as a legal person.

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Corrections, contradictions, and supersession

  • No source-specific correction, contradiction, or supersession record is active.

Where this source is used

No related records are assigned in this release.

Authority boundary

Publication by National Institute of Standards and Technology establishes source provenance and official status within the publisher’s scope. It does not transfer governance, registry, assurance, or legal authority to ᚲ.com. The source remains external; this page is a knowledge record and revalidation log.