Guide · Foundations

Where supply-chain risk lives in NIST CSF 2.0.

Foundations · 8 min read · Updated July 2026

NIST CSF supply chain risk got a promotion in 2024. When the Cybersecurity Framework moved to version 2.0, supply-chain risk management stopped being a sub-topic of Identify and became a named category under a brand-new Govern function — a signal that managing supplier risk is a board-level governance job, not a procurement footnote. This guide walks the GV.SC category, how it connects to third-party risk management, and the deeper practices in NIST SP 800-161r1.

In one sentence

In NIST CSF 2.0, supply-chain risk is handled by GV.SC — the Cybersecurity Supply Chain Risk Management category within the new Govern function — which sets ten outcomes for identifying, contracting with, monitoring, and offboarding suppliers, backed by the deeper practices in NIST SP 800-161r1.

A quick primer on CSF 2.0

The NIST Cybersecurity Framework is a voluntary, sector-agnostic framework from the US National Institute of Standards and Technology. It is not a law and not a certification — it is a common language for organising cybersecurity outcomes, and it is used well beyond the United States. Version 2.0, released in February 2024, is the current edition.

The framework's core is a hierarchy of Functions, Categories, and Subcategories, tailored through Tiers and Profiles. The headline change in 2.0 was structural. The original framework had five functions — Identify, Protect, Detect, Respond, Recover. Version 2.0 adds a sixth and places it at the centre of the wheel: Govern (GV). Govern is where strategy, roles, policy, oversight, and risk appetite live — the decisions that direct everything the other five functions do. Profiles let an organisation describe its current and target state, and Tiers describe how rigorous and repeatable its practices are; neither mechanism changed in 2.0 — what changed is where supply chain sits within the core.

Why supply chain moved to Govern

In CSF 1.1, supply-chain risk was a single category under Identify, labelled ID.SC. In 2.0 it moved up and expanded into GV.SC — Cybersecurity Supply Chain Risk Management — one of six categories under Govern, alongside organizational context, risk-management strategy, roles and responsibilities, policy, and oversight.

The relocation is the message. Placing supplier risk under Govern says that managing the risk your third parties carry is a governance responsibility owned at the top and wired into enterprise risk management — not a task buried in asset inventory. It is the same shift NIS2 and DORA make from the regulatory side: supplier risk belongs on the board's desk.

The ten GV.SC outcomes

GV.SC sets out ten outcomes — subcategories GV.SC-01 through GV.SC-10. In plain terms, they ask you to:

  1. Establish a supply-chain risk-management programme, strategy, and policies agreed by stakeholders (GV.SC-01)
  2. Set and coordinate cybersecurity roles for suppliers, customers, and partners (GV.SC-02)
  3. Integrate supply-chain risk into your wider cyber and enterprise risk management (GV.SC-03)
  4. Know your suppliers and prioritise them by criticality (GV.SC-04)
  5. Build security requirements into contracts and agreements (GV.SC-05)
  6. Do due diligence before entering a relationship (GV.SC-06)
  7. Understand, record, and monitor supplier risk across the life of the relationship (GV.SC-07)
  8. Include suppliers in incident planning, response, and recovery (GV.SC-08)
  9. Monitor supply-chain security throughout the product and service life cycle (GV.SC-09)
  10. Plan for the end — secure offboarding after a contract concludes (GV.SC-10)

Read together, the ten describe a full lifecycle: know who your suppliers are, size them by criticality, contract well, watch them continuously, plan for incidents jointly, and exit cleanly. It is a compact statement of what good third-party risk management looks like.

The depth behind GV.SC: SP 800-161r1

GV.SC is deliberately outcome-oriented — it says what to achieve, not how. For the how, NIST points to SP 800-161r1, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations." It is the deep reference behind the category: a full treatment of C-SCRM practices, processes, and controls.

800-161r1 frames cybersecurity supply-chain risk management across three levels — enterprise; mission and business process; and operational, at the level of individual systems — so strategy set at the top flows down into how systems are built and run. It supplies a dedicated set of supply-chain controls that enhance the familiar SP 800-53 catalogue, and its Revision 1 folded in software-supply-chain concerns and the direction of US Executive Order 14028. Where GV.SC gives you the ten outcomes, 800-161r1 gives you the control detail to evidence them. It also treats suppliers, developers, system integrators, and other third parties as distinct sources of risk, each warranting its own controls rather than one blanket assessment.

Turning outcomes into practice

The gap most organisations hit is between the framework and the day-to-day. GV.SC-04 says prioritise suppliers by criticality; GV.SC-07 says carry that risk understanding across the whole relationship. Both assume something many programmes lack: a live, ranked view of who your suppliers are and what each one can actually reach. This is the same problem supply-chain risk management exists to solve. A flat vendor list treats a payroll processor and a marketing plugin as equals; criticality is exactly the ranking a static inventory cannot express on its own.

It is also where an inside-out approach earns its place. Instead of scoring every vendor on a generic outside-in scale, inside-out classification ranks each supplier by your own exposure — what they hold, touch, or could disrupt for you, across your access vectors. That is GV.SC-04's "prioritise by criticality" expressed as an operating model, and it makes the later outcomes — continuous monitoring, incident inclusion, clean offboarding — land where the risk actually concentrates rather than spreading effort evenly across a flat list.

A closing caveat: the NIST CSF is voluntary and descriptive. It maps neatly onto obligations elsewhere — from DORA's ICT third-party rules to NIS2's supply-chain duty — without being any of them. Treat GV.SC as a well-built scaffold for a supplier-risk programme, then evidence it with the practices in 800-161r1.

GV.SC, made operational
Polestead turns GV.SC outcomes into a live register.

It tiers every vendor in your register by your own exposure across six access vectors — not their scan grade — so GV.SC-04's "prioritise by criticality" becomes the default, and the risky supplier nobody nominated still surfaces.

See inside-out classification →
FAQ

Common questions.

What is GV.SC in the NIST CSF?+

GV.SC — Cybersecurity Supply Chain Risk Management — is the category within the CSF 2.0 Govern function that sets ten outcomes for managing supplier and third-party cyber risk across the full relationship lifecycle.

Where is supply-chain risk in NIST CSF 2.0?+

Under the new Govern function, as the GV.SC category. In the earlier CSF 1.1 it lived under Identify as ID.SC; version 2.0 moved and expanded it to signal that supplier risk is a governance responsibility.

What is NIST SP 800-161r1?+

"Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations" — NIST's in-depth C-SCRM guidance across enterprise, mission, and system levels, with supply-chain controls that enhance SP 800-53. It is the detailed how behind GV.SC's what.

Is the NIST Cybersecurity Framework mandatory?+

No. The CSF is a voluntary, sector-agnostic framework, not a law or certification. It is widely adopted because it organises cybersecurity outcomes clearly and maps onto obligations such as DORA and NIS2 without replacing them.

Keep reading
Third-party risk management
The program GV.SC describes in outcomes.
Supply-chain risk management
The wider discipline, beyond one framework.
Inside-out risk →
Prioritise suppliers by your own exposure.