THIRD PARTYCURRENT
ICT Due Diligence · Official NIST guidance analysis

NIST SP 1326 gives ICT diligence five evidence questions

NIST's final July 2026 quick-start guide separates foreign influence, provenance, resilience, foundational cyber practices, and supply-chain tiers in ICT supplier assessment. A single supplier score cannot show which of those questions was evidenced, unresolved, or relevant to a specific acquisition.

Third Party Current editorial graphic. Source material: NIST SP 1326; analysis and presentation by Third Party Current.

Choose the ICT object before collecting evidence

The direct answer is to ask five named questions about a defined ICT acquisition or installed dependency, rather than attach one undifferentiated due-diligence grade to a legal supplier. NIST's final SP 1326 quick-start guide describes investigative due diligence for information and communications technology suppliers in the context of SP 800-161 Revision 1. Its five component labels are foreign ownership, control, or influence (FOCI), provenance, resilience, foundational cyber practices, and supply-chain tiers. Those labels structure inquiry; the source does not assess any actual company or mandate one scoring formula.

Record the acquiring organization, supplier legal entity, product and service, contract, version, deployment environment, integration, data classes, critical business service, location, customer and downstream dependency, procurement stage, owner, and intended decision. A cloud service, device, software component, and reseller arrangement may require different evidence even when the vendor name is the same. Determine whether the ICT scope applies to the evaluated object; do not silently present the guide as a complete food, facilities, healthcare, or ordinary commodity-supplier framework.

Keep the five evidence lanes independent

A useful workpaper gives each NIST component its own source, observation date, covered entity or asset, method, confidence, limitation, conflicting record, follow-up, reviewer, and decision consequence. FOCI inquiry concerns relevant ownership and influence evidence, not a sanction or illegality conclusion from a company name. Provenance concerns origin and chain evidence for the supplied object, which is not solved by seeing that the legal vendor is established. Resilience concerns continuity and recovery assumptions for the acquired dependency; a broad supplier assurance can leave the buyer's exact service path untested.

Foundational cyber practices require evidence at the relevant organization, product, or service level, including the period and assurance method rather than a badge copied across components. Supply-chain tiers ask which subcontractors, components, operators, and geographic dependencies lie behind the named offering. Mark unknown, access guarded, provider asserted, independently observed, out of scope, and conflicting separately. An outside-in cyber rating, questionnaire completion, or contract clause may contribute to one lane, but none automatically disposes of the other four.

Turn a gap into an accountable acquisition decision

A gap register should preserve the original question and artifact, affected ICT object, exposure path, significance, request to the supplier, alternative evidence, deadline, interim control, escalation, assigned owner, residual uncertainty, and authorization decision. If a source contradicts another, retain both and seek reconciliation; averaging them into an apparently precise rating can remove the most important operating signal. A narrow unanswered provenance question may affect one component; an unexamined recovery dependency may affect the whole critical operation. The buyer must decide those cases in context.

Before onboarding or renewal, connect each question to a contract provision, technical architecture, inventory, acceptance test, monitoring rule, change trigger, contingency option, and accountable disposition. The guide is not a substitute for financial-sector third-party guidance or a buyer's own sector obligations. It also differs from the prior SAP Ariba tenant-specific test question: SP 1326 identifies what ICT supply-chain evidence to request, whereas an environment-specific product test proves only the particular control behavior observed in that tenant. Do not let a completed framework map stand in for either decision.

Test a sourced component with an unseen lower tier

Use a synthetic purchase of a connected device with embedded software and a hosted management service. The manufacturer, distributor, firmware developer, cloud operator, and business-service owner are different roles. Change the embedded component source, introduce a sub-tier contractor, remove one recovery location, and ask reviewers to show which of the five workpaper lanes changes, which evidence is stale, who must approve an exception, and how monitoring detects a later shift. Preserve a supplier refusal or inaccessible source as uncertainty, not an invented pass or failure.

NIST SP 1326 supports its final publication status, ICT quick-start scope, relationship to SP 800-161 Revision 1, and the five named components. It does not establish one supplier's ownership, product provenance, cyber posture, resilience, lower tiers, legality, certification, compliance, procurement approval, or risk acceptance. No supplier, device, software, contract, service, ownership graph, assurance, deployment, or control was tested here. Qualified procurement, technology, security, business, continuity, compliance, and legal owners retain the underlying evidence and decisions.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: NIST SP 1326 · Final NIST cybersecurity supply-chain quick-start guidance.

Source boundary: Independent analysis of NIST SP 1326's official final record reviewed September 15, 2026. NIST did not review or sponsor this article. The guide is not binding certification or a supplier verdict. No actual ownership, supplier, product, cyber control, lower-tier relationship, service resilience, purchase, deployment, compliance state, or outcome was independently established; this is not procurement, cybersecurity, financial-supervision, compliance, or legal advice.

Editorial record: Published September 15, 2026; last reviewed September 15, 2026. Corrections policy.