ID.RA-10 ID · Identify · ID.RA Risk Assessment

ID.RA-10 — Critical supplier assessment

Critical suppliers are assessed prior to acquisition.

Also written as ID-RA-10, ID.RA-10, CSF 2.0 ID.RA-10, NIST CSF ID.RA.

What NIST CSF ID.RA-10 means

ID.RA-10 is one of 21 subcategories in the Identify (ID) function, under the Risk Assessment category (ID.RA). The Core states: “Critical suppliers are assessed prior to acquisition.” Identify outcomes are prerequisites rather than protections — if the underlying inventory or risk analysis is incomplete, every downstream Protect and Detect outcome inherits that gap.

Evidence that supports ID.RA-10

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Critical supplier security assessments prior to acquisition
  • Supplier risk scores feeding procurement decisions
  • Assessment refresh records

ISO 27001 mapping

ID.RA-10 has no direct one-to-one ISO 27001:2022 Annex A equivalent — it is a governance or process outcome that ISO 27001 addresses at the management-system level (Clauses 4–10) rather than through a specific Annex A control. Treat it as its own requirement in your CSF profile.

Map ID.RA-10 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against ID.RA-10 in the Risk Register.

Other Risk Assessment subcategories

ID.RA-01 Vulnerability identification ID.RA-02 Threat intelligence received ID.RA-03 Internal and external threats identified ID.RA-04 Threat impact and likelihood ID.RA-05 Risk prioritization from threats, vulnerabilities, impacts ID.RA-06 Risk responses chosen and tracked ID.RA-07 Changes and exceptions risk-assessed ID.RA-08 Vulnerability disclosure handling ID.RA-09 Hardware and software integrity verified pre-use

All 21 Identify subcategories →

Frequently asked questions

Is NIST CSF ID.RA-10 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. ID.RA-10 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is ID.RA-10 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns ID.RA-10?

The Identify function is normally owned by the security or IT function, but ID.RA-10 still needs a specific named owner. Assessors treat an outcome with no owner as not achieved regardless of the tooling behind it, so record ownership in your profile alongside the assessment.