THIRD PARTYCURRENT
U.S. government technical guidance

NIST SP 1326

An implementation-oriented guide for conducting due-diligence research on ICT suppliers and products before acquisition or during an existing relationship. Its assessment components are foreign ownership, control, or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers.

What the authority establishes

An implementation-oriented guide for conducting due-diligence research on ICT suppliers and products before acquisition or during an existing relationship. Its assessment components are foreign ownership, control, or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers.

It converts a broad C-SCRM obligation into a repeatable minimum-research model for supplier due diligence. The five assessment components can become explicit evidence fields, analyst questions, and scoring dimensions in provider profiles and buyer tools.

The record is written for operational interpretation, not legal advice. Applicability depends on entity type, jurisdiction, relationship, service, data, criticality, contractual commitments, and later authority guidance.

Who should read it

The primary audiences named in this review are technology procurement and acquisition teams, cybersecurity supply-chain risk teams, third-party risk analysts, government agencies and contractors, enterprise architecture and product-security teams. Those roles may divide responsibility differently, but the operating record should still show scope, accountable ownership, evidence, review, exceptions, and the final decision.

Third-party lifecycle implications

Planning

Teams should determine what this authority expects at the planning stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Due Diligence And Selection

Teams should determine what this authority expects at the due diligence and selection stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Periodic Reassessment

Teams should determine what this authority expects at the periodic reassessment stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Capabilities that may support the work

These links identify relevant operating capabilities; they do not state that any product creates compliance.

Intake And Inventory

establishing an accountable record of relationships, products, owners, and critical services. Buyers should test the workflow against their own scope and evidence requirements.

Inherent Risk Tiering

using relationship context to determine proportional diligence and review. Buyers should test the workflow against their own scope and evidence requirements.

Due Diligence And Assessments

collecting and reviewing evidence before and during a relationship. Buyers should test the workflow against their own scope and evidence requirements.

Evidence Collection

preserving source material, responses, and reviewer context. Buyers should test the workflow against their own scope and evidence requirements.

Fourth-Party Visibility

identifying and explaining important downstream dependencies. Buyers should test the workflow against their own scope and evidence requirements.

Reporting

turning program activity into operator, executive, and board-ready information. Buyers should test the workflow against their own scope and evidence requirements.

What software cannot decide

Software can structure records, route work, preserve evidence, surface change, and support reporting. It cannot determine legal applicability, set risk appetite, negotiate accountable contract terms, validate every external claim, accept residual risk, or make management responsible for an outcome. Those remain organizational decisions.

Related market changes

NIST finalizes its C-SCRM Due Diligence Assessment Quick-Start Guide

The guide gives buyers a neutral baseline for testing whether intake, evidence, review, escalation, and decision records support a defensible supplier-diligence process.

NIST publishes SP 800-18 Revision 2

Third-party findings increasingly need to connect with systems, controls, owners, and planning records instead of remaining isolated in a vendor file.