Skip to content
Browse docs

Supply Chain Risk — FedRAMP KSI Domain

Generated from the official FedRAMP/rules GitHub repo. Source path: fedramp-consolidated-rules.json on main at blob 7d628b63fdd9. Consolidated Rules version: 2026.07.02.02 · upstream last_updated: 2026-07-02. Supporting narrative documentation is available from the official FedRAMP/2026-markdown repository.

Supply Chain Risk

Domain code: SCR · Domain ID: KSI-SCR · Web slug: supply-chain-risk

Indicators

KSI-SCR-MIT — Mitigating Supply Chain Risk

Persistently identify, review, and mitigate potential supply chain risks.

Mapped Rev5 controls: ac-20, ra-3.1, sa-9, sa-10, sa-11, sa-15.3, sa-22, si-7.1, sr-5, sr-6, ca-7.4, sc-18

Terms: Persistently

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-SCR-MON — Monitoring Supply Chain Risk

Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

Mapped Rev5 controls: ac-20, ca-3, ir-6.3, ps-7, ra-5, sa-9, si-5, sr-5, sr-6, sr-8

Terms: Information Resource, Vulnerability

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

URL copied to clipboard