GV.SC-01 GV · Govern · GV.SC Cybersecurity Supply Chain Risk Management

GV.SC-01 — Supply chain risk management program

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders.

Also written as GV-SC-01, GV.SC-1, CSF 2.0 GV.SC-01, NIST CSF GV.SC.

What NIST CSF GV.SC-01 means

GV.SC-01 is one of 31 subcategories in the Govern (GV) function, under the Cybersecurity Supply Chain Risk Management category (GV.SC). The Core states: “A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders.” Govern is the function CSF 2.0 added, and it is the one most organisations score lowest on: the outcome is not a tool you deploy but a decision someone with authority has to make, record, and revisit.

Evidence that supports GV.SC-01

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • C-SCRM program / policy document approved by stakeholders
  • Supply chain risk objectives and processes
  • Program review records

How to implement GV.SC-01

  1. Treat C-SCRM as a programme with an ownerThe outcome asks for a programme, strategy, objectives, policies and processes — the plural is the point. A vendor questionnaire process alone is not a programme. Name an owner and give it a documented scope covering suppliers, products, and the development supply chain.
  2. Extend beyond vendors to componentsSupply chain risk in CSF 2.0 includes the software you build with, not just the companies you buy from. Software bills of materials, dependency provenance and build pipeline integrity all sit inside this outcome and are what distinguish it from ordinary vendor management.
  3. Get stakeholder agreement across functionsProcurement, legal and engineering all execute parts of this, so agreement has to span them. A programme owned solely by security will fail at the point where a team buys something with a corporate card.
  4. Integrate into procurement as a gateThe most reliable enforcement is a purchasing process that cannot complete without a security step for the relevant tiers. Documented and applied, this single change does more than any policy statement.
  5. Review the programme itself, not just the vendorsThe outcome includes program review records. Something has to demonstrate the programme is assessed for effectiveness — coverage, cycle times, findings — rather than just running.

Common assessment findings for GV.SC-01

What actually gets raised against GV.SC-01, in rough order of how often it comes up:

Assessing GV.SC-01 in a profile

GV.SC is the category most organisations score lowest on in a first CSF 2.0 assessment, largely because supply chain moved here from Identify in CSF 1.1 and the scope widened. Expect a genuine gap rather than a mapping exercise.

ISO 27001 mapping

GV.SC-01 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.19. Evidence collected for one framework typically supports the other.

Map GV.SC-01 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against GV.SC-01 in the Risk Register.

Other Cybersecurity Supply Chain Risk Management subcategories

GV.SC-02 Supplier roles and responsibilities GV.SC-03 Supply chain risk in ERM GV.SC-04 Suppliers prioritized by criticality GV.SC-05 Supply chain requirements in contracts GV.SC-06 Due diligence before supplier relationships GV.SC-07 Ongoing supplier risk monitoring GV.SC-08 Suppliers in incident planning GV.SC-09 Supply chain security throughout lifecycle GV.SC-10 Post-relationship supply chain plans

All 31 Govern subcategories →

Frequently asked questions

Is NIST CSF GV.SC-01 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. GV.SC-01 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is GV.SC-01 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns GV.SC-01?

Govern outcomes sit with leadership rather than with the security team — executives, risk owners, and in many organisations the board. If GV.SC-01 has no named owner outside IT, that is usually the finding, because CSF 2.0 introduced Govern precisely to make cybersecurity a management-level accountability.

Does NIST CSF GV.SC-01 map to ISO 27001?

Yes — GV.SC-01 corresponds to ISO 27001:2022 Annex A control(s) A.5.19. Evidence collected for one framework typically supports the other, so a single control library can serve both.

What are the most common audit findings for GV.SC-01?

Vendor security assessment exists but there is no programme document, strategy or defined objectives behind it. Software supply chain — dependencies, build integrity, SBOM — entirely absent from a programme that only covers commercial vendors.