SP 800-18 Rev. 2, Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems
In effectNIST · NIST Special Publication · June 30, 2026
Summary
Guides organizations in writing and maintaining three system plans, for security, privacy, and cybersecurity supply chain risk management, that describe each system, the status of its controls, and the duties of people who run and use it.
Replaces
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- National Institute of Standards and Technology (NIST)
- Type
- NIST Special Publication
- Number
- SP 800-18 Rev. 2
- Issued
- June 30, 2026
- Status
- In effect
Still in force, possibly with amendments.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.