DEV Community

Cover image for A Five-Part Evidence Check for ICT Supplier Due Diligence
Enoch Chan
Enoch Chan

Posted on

A Five-Part Evidence Check for ICT Supplier Due Diligence

Supplier questionnaires are useful, but completion is not the same as due diligence.

NIST SP 1326, finalised on 8 July 2026, defines five Due Diligence Assessment components for ICT suppliers: Foreign Ownership, Control, or Influence (FOCI); Provenance; Resilience; Foundational Cyber Practices; and Supply Chain Tiers.

Turn each component into an evidence test. For FOCI, record the relevant evidence and any uncertainty. For provenance, record the evidence available about origin. For resilience, capture the evidence the review relies on. For foundational cyber practices, record concrete supporting material. For supply-chain tiers, identify the evidence available about relevant upstream dependencies.

Before approval, a practical internal rule is to record one of three things for each component: an evidence note, an explicit gap, or a named risk acceptance. That creates a clearer decision record than treating questionnaire completion as the end of the review.

SP 1326 is NIST guidance scoped to ICT supplier due diligence. It should not be presented as a universal legal requirement.

VendorOS can be used as evidence-workflow context for questionnaire review and explicit approval. The five-part framework itself comes from NIST.

Top comments (0)