NIST CSF supply chain risk got a promotion in 2024. When the Cybersecurity Framework moved to version 2.0, supply-chain risk management stopped being a sub-topic of Identify and became a named category under a brand-new Govern function — a signal that managing supplier risk is a board-level governance job, not a procurement footnote. This guide walks the GV.SC category, how it connects to third-party risk management, and the deeper practices in NIST SP 800-161r1.
In NIST CSF 2.0, supply-chain risk is handled by GV.SC — the Cybersecurity Supply Chain Risk Management category within the new Govern function — which sets ten outcomes for identifying, contracting with, monitoring, and offboarding suppliers, backed by the deeper practices in NIST SP 800-161r1.
The NIST Cybersecurity Framework is a voluntary, sector-agnostic framework from the US National Institute of Standards and Technology. It is not a law and not a certification — it is a common language for organising cybersecurity outcomes, and it is used well beyond the United States. Version 2.0, released in February 2024, is the current edition.
The framework's core is a hierarchy of Functions, Categories, and Subcategories, tailored through Tiers and Profiles. The headline change in 2.0 was structural. The original framework had five functions — Identify, Protect, Detect, Respond, Recover. Version 2.0 adds a sixth and places it at the centre of the wheel: Govern (GV). Govern is where strategy, roles, policy, oversight, and risk appetite live — the decisions that direct everything the other five functions do. Profiles let an organisation describe its current and target state, and Tiers describe how rigorous and repeatable its practices are; neither mechanism changed in 2.0 — what changed is where supply chain sits within the core.
In CSF 1.1, supply-chain risk was a single category under Identify, labelled ID.SC. In 2.0 it moved up and expanded into GV.SC — Cybersecurity Supply Chain Risk Management — one of six categories under Govern, alongside organizational context, risk-management strategy, roles and responsibilities, policy, and oversight.
The relocation is the message. Placing supplier risk under Govern says that managing the risk your third parties carry is a governance responsibility owned at the top and wired into enterprise risk management — not a task buried in asset inventory. It is the same shift NIS2 and DORA make from the regulatory side: supplier risk belongs on the board's desk.
GV.SC sets out ten outcomes — subcategories GV.SC-01 through GV.SC-10. In plain terms, they ask you to:
Read together, the ten describe a full lifecycle: know who your suppliers are, size them by criticality, contract well, watch them continuously, plan for incidents jointly, and exit cleanly. It is a compact statement of what good third-party risk management looks like.
GV.SC is deliberately outcome-oriented — it says what to achieve, not how. For the how, NIST points to SP 800-161r1, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations." It is the deep reference behind the category: a full treatment of C-SCRM practices, processes, and controls.
800-161r1 frames cybersecurity supply-chain risk management across three levels — enterprise; mission and business process; and operational, at the level of individual systems — so strategy set at the top flows down into how systems are built and run. It supplies a dedicated set of supply-chain controls that enhance the familiar SP 800-53 catalogue, and its Revision 1 folded in software-supply-chain concerns and the direction of US Executive Order 14028. Where GV.SC gives you the ten outcomes, 800-161r1 gives you the control detail to evidence them. It also treats suppliers, developers, system integrators, and other third parties as distinct sources of risk, each warranting its own controls rather than one blanket assessment.
The gap most organisations hit is between the framework and the day-to-day. GV.SC-04 says prioritise suppliers by criticality; GV.SC-07 says carry that risk understanding across the whole relationship. Both assume something many programmes lack: a live, ranked view of who your suppliers are and what each one can actually reach. This is the same problem supply-chain risk management exists to solve. A flat vendor list treats a payroll processor and a marketing plugin as equals; criticality is exactly the ranking a static inventory cannot express on its own.
It is also where an inside-out approach earns its place. Instead of scoring every vendor on a generic outside-in scale, inside-out classification ranks each supplier by your own exposure — what they hold, touch, or could disrupt for you, across your access vectors. That is GV.SC-04's "prioritise by criticality" expressed as an operating model, and it makes the later outcomes — continuous monitoring, incident inclusion, clean offboarding — land where the risk actually concentrates rather than spreading effort evenly across a flat list.
A closing caveat: the NIST CSF is voluntary and descriptive. It maps neatly onto obligations elsewhere — from DORA's ICT third-party rules to NIS2's supply-chain duty — without being any of them. Treat GV.SC as a well-built scaffold for a supplier-risk programme, then evidence it with the practices in 800-161r1.
It tiers every vendor in your register by your own exposure across six access vectors — not their scan grade — so GV.SC-04's "prioritise by criticality" becomes the default, and the risky supplier nobody nominated still surfaces.
See inside-out classification →GV.SC — Cybersecurity Supply Chain Risk Management — is the category within the CSF 2.0 Govern function that sets ten outcomes for managing supplier and third-party cyber risk across the full relationship lifecycle.
Under the new Govern function, as the GV.SC category. In the earlier CSF 1.1 it lived under Identify as ID.SC; version 2.0 moved and expanded it to signal that supplier risk is a governance responsibility.
"Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations" — NIST's in-depth C-SCRM guidance across enterprise, mission, and system levels, with supply-chain controls that enhance SP 800-53. It is the detailed how behind GV.SC's what.
No. The CSF is a voluntary, sector-agnostic framework, not a law or certification. It is widely adopted because it organises cybersecurity outcomes clearly and maps onto obligations such as DORA and NIS2 without replacing them.