DI-MGMT-82147B
Supply Chain Risk Management (SCRM) Process
This DID contains the format, content, and intended use information for the Supply Chain Risk Management (SCRM) process report resulting from the work task described in the contract.
Approval DateSeptember 22, 2025
AMSC NumberN10601
Preparing ActivityAS
Project NumberMGMT-2025-027
OPR—
DTIC ApplicableNo
GIDEP ApplicableYes
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Delivery Item contains the format, content and intended use information for the Supply Chain Risk Management (SCRM) process report resulting from the work task described in the contract. This DID should be used to compliment DI-MGMT-82144A PROGRAM PROTECTION IMPLEMENTATION PLAN which is the overarching DID for Program Protection this also includes Critical Program Information (Critical Components (CC) / Critical Program Information (CPI) / Critical Systems (CS) / Critical Technologies).
This DID contains the format, content, and intended use information for the data product resulting from the work task.
This DID supersedes DI-MGMT-82147A.
Preparation Instructions
1Referenced Documents:The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
1.1Individual program office program protection plan.
1.2National Institute of Standards and Technology (NIST) Special Publication (SP) 800-161, Supply Chain Risk Management (SCRM) Practices for Federal Information Systems and Organizations, April 2015.Copies of this document can be found at https://csrc.nist.gov/publications/detail/sp/800-161/final
1.3DoDI 5200.44 (20240216), Protection of Mission Critical Functions to Achieve Trusted Systems and Networks (TSN).Copies of this document can be found at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/520044p.pdf
2Format:Contractor format is acceptable. The Supply Chain Risk Management (SCRM) portion of the PPIP will include the establishment of a SCRM program tailored to fit the contractor's acquisition program identifying how supply chain risks are addressed across the entire system lifecycle through a defense-in breadth approach to managing the risks to the integrity of information and communications technology (ICT) within covered systems.
3Content:The report shall contain the following:
3.1Identify the SCRM lead
3.2Identify SCRM countermeasures for Critical Program Information and Critical Components
3.3Explain the Criticality Analysis Process
3.4Provide a list of Critical Components
3.5Provide supplier information for all critical components
3.6Provide assessment for any threats to critical components from suppliersand indicate countermeasures taken to mitigate the threat(s) and assessment of security architecture, threats, and vulnerabilities, risk, and countermeasures analysis.
3.7Provide a counterfeit prevention plan for protection of critical componentsincluding processes to detect the occurrence, reduce the likelihood of occurrence, and mitigate the consequences of products containing counterfeit components or malicious functions
3.8Specify assurance measures to ensure no malicious intent is designed into critical components
3.9Describe SCRM security controls implementation per NIST SP 800-161
3.10Objective Quality Evidence (OQE)is any statement of fact, either quantitative or qualitative, pertaining to the quality of a product or service based on observations, measurements, or tests, which can be verified and is required in sufficient detail to describe the data elements in the Statement of Work.
3.11Distribution Statement, as appropriate, in accordance with Department of Defense Instruction (DoDI) 5230.24, Distribution Statements on Technical Documents(Copies of this document can be obtained at: https://www.esd.whs.mil/.) Classification markings, as necessary, in accordance with DoD Manual (DoDM) 5200.01, Volume 2, DoD Information Security Program: Marking of Information. (Copies of this document can be obtained at: https://www.esd.whs.mil/.)
Schema v3.0Community-maintained · Verify against ASSIST