Threat feed liveUpdated — 06.08.2026 10:36 CET100 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 06.08.2026 10:36 CET100 dossiersMITRE ATT&CK mapping

Editorial explainer · official source (NIST)medium

What to ask a supplier before signing: the NIST guide in five headings

In July 2026 NIST published Special Publication 1326, a quick-start guide on how to build a due diligence assessment of technology suppliers. It is a short and deliberately operational document, anchored to SP 800-161 revision 1, and it organises research on a supplier into five components: foreign ownership, control or influence; provenance; resilience; foundational cyber practices; and supply chain tiers. It introduces no obligations and is not a certification. Its value is as a structure for a question almost every organisation handles badly: what do I need to know about whoever is selling me a system, before I sign.

The moment when nearly everything is decided

There is a moment, in the life of any supplier-related cyber risk, when the cost of acting is low and the ability to act is at its highest: before signing.

Afterwards, everything gets harder. The system is installed, the data are in it, staff work with it, the contract has a term. Questions that could have been conditions become requests to be negotiated. And the most frequent answer, at that stage, is that it will be looked at on renewal.

In July 2026 NIST published a short document aimed at exactly that moment: Special Publication 1326, Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide.

What NIST means by due diligence

The definition in the document is spare: due diligence research is «the investigative process of researching all available, pertinent information about a given supplier or product so that informed decisions can be made on new acquisitions or existing systems».

Two elements of that sentence deserve attention.

The first is «all available» — information that can be obtained. This is not about gaining access to a supplier's trade secrets: it is about gathering and reading what is already gatherable, which is far more than most organisations do.

The second is «or existing systems». Due diligence is not only for choosing: it is also for reassessing what you already have. That is the part almost always skipped, because there is no natural moment at which it triggers.

The document explicitly sits within the framework of SP 800-161 revision 1, NIST's parent publication on supply chain risk, and is scoped to ICT suppliers — information and communications technology — even though the framework, as the document itself says, «can be applied to any type of supplier».

The five components

The guide's practical contribution is all here. The components of a due diligence assessment are, verbatim, «Foreign Ownership, Control, or Influence (FOCI); Provenance; Resilience; Foundational Cyber Practices; and Supply Chain Tiers».

  1. 01
    FOCI · Ownership and influence
    who really controls the supplier, and from which jurisdiction
  2. 02
    Provenance
    where the product comes from: components, code, places of development
  3. 03
    Resilience
    what happens to your service if the supplier stops

They are worth translating into questions, because that is how they are used.

Foreign ownership, control or influence. Who owns the company, who controls it, who can influence its decisions and under which legal system it operates. This is not geopolitics in the abstract: it is the question of who can ultimately compel that supplier to do something you did not ask for.

Provenance. Where what you are buying comes from. Which third-party components it contains, where it was developed, who wrote the parts the supplier did not write. This is the level at which a software bill of materials stops being a compliance item and becomes a tool.

Resilience. What happens if the supplier has an incident, is acquired, or simply shuts down. How much time you have, which data you can take with you, how realistic the alternative is.

Foundational cyber practices. The minimum level of hygiene: how it handles its own vulnerabilities, how it authenticates its people, how it responds to incidents, how it notifies you.

Supply chain tiers. The component almost nobody addresses: your supplier has suppliers of its own. The question is not to map the whole chain — that is not feasible — but to find out whether your supplier knows it, and how far.

Why the fifth point is the one that makes the difference

The first four headings appear, in various forms, in many supplier assessment questionnaires. The fifth usually does not, and in practice it is where the surprising incidents come from.

The reason is structural: responsibility does not move along the chain, but visibility does. An organisation knows its direct supplier well, knows the supplier's supplier vaguely, and does not know the third tier at all. Attacks in recent years against support platforms, remote management tools and widely used libraries have almost always landed at a tier the ultimate victim had never assessed — simply because it did not know it had one.

Asking a supplier how do you govern your own suppliers does not produce a map. It produces something more useful: you find out immediately whether an answer exists.

5
components
FOCI · provenance · resilience · foundational practices · supply chain tiers
1
the right moment
before signing, when questions are conditions rather than requests
0
obligations introduced
it is a voluntary guide, not a certification and not a regulation

How to use it without turning it into paperwork

The risk with any assessment framework is that it becomes a 200-line questionnaire nobody reads and the supplier fills in by copying last year's. Three criteria to avoid that.

Scale the depth to the risk, not to the contract value. A cheap service with access to your mail or your credentials deserves more attention than an expensive contract that touches nothing sensitive.

Ask the questions where they carry weight, namely in the tender and in the contract. An answer written during selection is worth more than a statement collected afterwards, because the supplier is still competing.

Repeat it on existing systems, at least for the few that really matter. This is the use the document explicitly points to and the one nobody performs. You do not need to redo everything: you need a short list of suppliers whose unavailability or compromise would stop you, and a periodic re-read for those.

What it is not

Worth stating, to avoid setting the wrong expectations. SP 1326 is a voluntary guide, not a binding regulation and not a certification scheme: nobody issues an «SP 1326 compliant» attestation. It is a Quick-Start Guide, that is, a short document designed as an entry point to SP 800-161r1, not a replacement for it: anyone needing the full framework has to read that one.

It is also scoped to ICT suppliers, and the absence of problems in a due diligence assessment is not a guarantee of security. It is a reduction in ignorance, which is a different and more modest thing — but it is also the only thing you can obtain before signing.

More dossiers