Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SR

SR-6Supplier Assessments and Reviews

Assess and review the supply chain-related risks associated with suppliers or contractors and the system, system component, or system service they provide {{ insert: param, sr-06_odp }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (7)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-798Use of Hard-coded Credentials1,955Supplier risk reviews identify and discourage hard-coded credentials in delivered products or services.
CWE-321Use of Hard-coded Cryptographic Key277Assessments can uncover and prevent suppliers from shipping components that contain hard-coded cryptographic keys.
CWE-829Inclusion of Functionality from Untrusted Control Sphere254Supplier assessments directly reduce the likelihood of incorporating functionality from untrusted third-party control spheres.
CWE-494Download of Code Without Integrity Check242Supply-chain reviews verify that suppliers implement integrity checks before code or components are accepted.
CWE-259Use of Hard-coded Password187Reviews of supplier deliverables reduce the chance that hard-coded passwords are introduced into the system.
CWE-506Embedded Malicious Code80Reviews of suppliers and their deliverables can detect or deter introduction of embedded malicious code.
CWE-1104Use of Unmaintained Third Party Components19Assessments evaluate supplier maintenance practices, lowering exposure to unmaintained third-party components.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family SR

SR-1 SR-10 SR-11 SR-12 SR-2 SR-3 SR-4 SR-5 SR-7 SR-8 SR-9