NIST embeds C-SCRM planning in SP 800-18 Rev. 2
The useful part is also the uncomfortable part: supply chain risk is harder to park outside core authorization documentation.
TL;DR
NIST released Special Publication 800-18 Rev. 2, replacing 2006 federal system-security-plan guidance with a three-plan model for security, privacy and cybersecurity supply chain risk management (C-SCRM). Federal agencies, state CISOs tracking NIST-based authorization models, primes and contractors should expect authorization packages to map C-SCRM requirements to NIST Risk Management Framework tasks. What NIST does not specify is the transition clock for existing plans.

NIST’s update to Special Publication 800-18 Rev. 2 is more than a paperwork refresh for the system security plan. It pulls the system security plan, system privacy plan and cybersecurity supply chain risk management (C-SCRM) plan into one planning architecture for assets, individuals, data flows, system components and controls within an authorization boundary. NIST’s public materials describe those plans as a centralized reference for system information and risk management decisions, and the replacement matters because the prior federal guidance dated to 2006.
The consequential move is where NIST places C-SCRM: inside the authorization boundary and alongside privacy and security planning, tied to NIST Risk Management Framework tasks and the controls planned or in place. That changes the evidence package an authorizing official reads. Supply chain risk can still have acquisition, vendor-risk and mission-owner pieces, but SP 800-18 Rev. 2 makes it much harder to treat those pieces as a side workstream that never reaches the authorization file.
For contractors, the publication does not itself add a contract clause. It gives agencies cleaner planning language to demand system-level information about suppliers, commercial off-the-shelf products, turnkey solutions and support services when they build or refresh authorization packages. Primes bidding on federal work should read this as an early warning about the documentation shape future C-SCRM requirements may take, especially where agency system plans become the basis for contract-specific controls.
NIST leaves the operational question open. The update explains the three-plan model and supplemental materials, including examples and roles and responsibilities, but the public materials do not give a transition deadline for existing system security plans or say whether the Office of Management and Budget will force one through authorization reviews. That is the piece practitioners need before they can schedule the rewrite: which systems move first, which packages can wait, and who signs when C-SCRM evidence stops living outside the authorization to operate file.
Published ·Deep Fathom