to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

03.17.01Supply Chain Risk Management Plan in Rev. 3

New in Revision 3 — no Revision 2 equivalent. Nothing in NIST SP 800-171 Rev. 2 maps onto this number, so it has no Rev. 2 page and no side-by-side; the Rev. 3 text is below in full. It carries organization-defined parameters.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

The requirement

Rev. 3 · not adopted 03.17.01 Supply Chain Risk Management Plan

a. Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system, system components, or system services.

b. Review and update the supply chain risk management plan [Assignment: organization-defined frequency].

c. Protect the supply chain risk management plan from unauthorized disclosure.

NIST SP 800-171 Rev. 3, verbatim, with organization-defined blanks highlighted. Rev. 2 has no counterpart to place beside it.

Determination statements

What an assessor would check under NIST SP 800-171A Rev. 3. 13 statements, each one answered yes or no.

  1. 03.17.01.a[01] a plan for managing supply chain risks is developed.
  2. 03.17.01.a[02] the SCRM plan addresses risks associated with the research and development of the system, system components, or system services.
  3. 03.17.01.a[03] the SCRM plan addresses risks associated with the design of the system, system components, or system services.
  4. 03.17.01.a[04] the SCRM plan addresses risks associated with the manufacturing of the system, system components, or system services.
  5. 03.17.01.a[05] the SCRM plan addresses risks associated with the acquisition of the system, system components, or system services.
  6. 03.17.01.a[06] the SCRM plan addresses risks associated with the delivery of the system, system components, or system services.
  7. 03.17.01.a[07] the SCRM plan addresses risks associated with the integration of the system, system components, or system services.
  8. 03.17.01.a[08] the SCRM plan addresses risks associated with the operation of the system, system components, or system services.
  9. 03.17.01.a[09] the SCRM plan addresses risks associated with the maintenance of the system, system components, or system services.
  10. 03.17.01.a[10] the SCRM plan addresses risks associated with the disposal of the system, system components, or system services.
  11. 03.17.01.b[01] the SCRM plan is reviewed <A.03.17.01.ODP[01]: frequency>.
  12. 03.17.01.b[02] the SCRM plan is updated <A.03.17.01.ODP[01]: frequency>.
  13. 03.17.01.c the SCRM plan is protected from unauthorized disclosure.

NIST SP 800-171A Rev. 3, verbatim.

Organization-defined parameters

Blanks the organization fills in. Defining each value is itself a determination in 800-171A Rev. 3.

  • A.03.17.01.ODP[01] the frequency at which to review and update the supply chain risk management plan is defined.

What NIST says

  • New security requirement based on SR-02 (SP 800-53, Rev 5)
  • Added new ODP: frequency to review and update supply chain risk management plan

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “New requirement”. At adoption, Bedrock files this under “New”.

NIST's Rev. 3 discussion for 03.17.01

Dependence on the products, systems, and services of external providers and the nature of the relationships with those providers present an increasing level of risk to an organization. Threat actions that may increase security risks include unauthorized production, the insertion or use of counterfeits, tampering, poor manufacturing and development practices in the supply chain, theft, and the insertion of malicious software, firmware, and hardware. Supply chain risks can be endemic or systemic within a system, component, or service. Managing supply chain risks is a complex, multifaceted undertaking that requires a coordinated effort across an organization to build trust relationships and communicate with internal and external stakeholders. Supply chain risk management (SCRM) activities include identifying and assessing risks, determining appropriate risk response actions, developing SCRM plans to document response actions, and monitoring performance against the plans. The system-level SCRM plan is implementation-specific and provides constraints, policy implementation, requirements, and implications. It can either be stand-alone or incorporated into system security plans. The SCRM plan addresses the management, implementation, and monitoring of SCRM requirements and the development or sustainment of systems across the system development life cycle to support mission and business functions. Because supply chains can differ significantly across and within organizations, SCRM plans are tailored to individual program, organizational, and operational contexts.

Supply Chain Risk Management in Rev. 3

SR Supply Chain Risk Management is one of the three families Rev. 3 adds; none of its requirements has a Rev. 2 number.

Supply Chain Risk Management in the catalog comparison

What this means for you now

Nothing. Until a class deviation or a published rule adopts Rev. 3, no assessor asks about 03.17.01 and SPRS has no score for it. If you already do what it describes, note where the evidence lives and what value you use for the parameters above; that costs nothing and answers the question later.

Bedrock CMMC carries the Rev. 3 catalog beside your Rev. 2 package, so the day adoption lands the new requirements are a to-do list, not a surprise.

Where this page's facts come from
Rev. 3 03.17.01 text, determination statements, parameters, class and note
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]