NIST publishes SP 800-18 Revision 2
NIST's revision coordinates security, privacy, and cybersecurity supply-chain risk management planning within the system risk record.
What changed
NIST's revision coordinates security, privacy, and cybersecurity supply-chain risk management planning within the system risk record.
This ledger entry preserves a dated market event separately from the maintained company and capability dataset. That distinction matters because an announcement, publication, acquisition, incident update, or research release can be material before there is enough evidence to alter a product comparison or provider classification.
Market consequence
Third-party findings increasingly need to connect with systems, controls, owners, and planning records instead of remaining isolated in a vendor file.
Buyers should use the event to sharpen diligence and demonstration questions, not to infer an automatic winner or loser. The useful test is whether later evidence shows a change in the governed workflow, data available to the customer, accountability, implementation boundary, or decision record.
Capabilities to revisit
Evidence Collection
Review the maintained definition, then ask affected providers to demonstrate how the change alters inputs, reviewer judgment, action, evidence retention, and exportability for evidence collection.
Issue Remediation
Review the maintained definition, then ask affected providers to demonstrate how the change alters inputs, reviewer judgment, action, evidence retention, and exportability for issue remediation.
Regulatory Mapping
Review the maintained definition, then ask affected providers to demonstrate how the change alters inputs, reviewer judgment, action, evidence retention, and exportability for regulatory mapping.
Reporting
Review the maintained definition, then ask affected providers to demonstrate how the change alters inputs, reviewer judgment, action, evidence retention, and exportability for reporting.
Questions for operators
- Which relationships, systems, services, locations, or decision records could this change affect?
- Does the event alter policy, evidence, workflow, monitoring, ownership, or only market positioning?
- What later documentation or direct observation would be required before changing a shortlist or control conclusion?
- Who owns the follow-up, by when, and what evidence will close or supersede the review?
- Should prior decisions remain valid, receive targeted reassessment, or be reopened for the complete affected population?
A mature response is proportional. Not every market event should trigger broad reassessment, but every material event should have an accountable disposition and a dated explanation of why the program did or did not act.
How this record will be maintained
Third Party Current will append later evidence when it changes the source claim, scope, availability, affected entities, or market consequence. The original event remains visible so readers can distinguish what was known at the time from what later reporting, documentation, or testing established.
Evidence boundary
The source class for this entry is government standard-setting authority. It establishes the statements explicitly supported by the linked record at the effective date. It does not establish claims that require direct product testing, an independent investigation, customer outcome data, or later integration evidence.

