Skip to main content

Supply Chain Security Evidence Checklist

Use this checklist to decide whether supply chain security evidence is strong enough to support a supplier, product, update, vulnerability, audit, or lifecycle decision.

The checklist helps turn supplier answers, product records, SBOMs, attestations, vulnerability statements, update records, and audit materials into review criteria. Evidence should be scoped, source-attributed, version-bound, lifecycle-aware, verifiable, retained, and tied to a decision.

Use Supplier Security Questions for request wording. Use the Evidence Package Template to package the decision, evidence, verification notes, gaps, exceptions, and retention owner.

Start With the Decision

Before reviewing evidence, name the decision it must support.

Examples:

  • approve, reject, or conditionally approve a supplier;
  • accept, quarantine, reject, or conditionally accept a product;
  • approve, delay, exclude, or remediate an update;
  • continue operation, mitigate, update, or accept residual vulnerability risk;
  • prepare an audit, customer assurance, or lifecycle review package.

Evidence is weaker when it is collected without a visible decision, scope, owner, or verification path.

Evidence areaReview questionsAcceptance signal
IdentityWhat identity is being claimed, who issued it, and how is it bound to the device, component, platform, supplier, or service?Identity can be verified against an expected issuer, product, component, or trust anchor
Provenance
SP 800-161 SR-3
What origin, custody, sourcing, manufacturing, logistics, repair, or transfer records exist?Chain gaps and custody changes are visible and explained
IntegrityWhat measurements, manifests, signatures, or attestation results show expected state?Current state can be compared to a trusted baseline or policy
Transparency
CRA Art. 13 §§ 3, 6
SSDF PW.4
What SBOM, xBOM, firmware, hardware, or component artifacts are available?Artifacts are tied to product versions and updated after changes
Updates
CRA Art. 13 § 8
What records show updates were authorized, delivered, installed, and recoverable?Update state and rollback status can be confirmed
Vulnerability handling
CRA Art. 13 §§ 6-10
CRA Art. 14
What evidence shows known exposures are tracked, remediated, accepted, or mitigated?Vulnerability status is tied to products, versions, and remediation decisions
Lifecycle state
CRA Art. 13 §§ 8-10
What records show whether an asset is active, repaired, transferred, revoked, retired, or decommissioned?Lifecycle status can be verified and is retained for later decisions
Verification
SP 800-161 SR-6
Can the recipient verify origin, integrity, freshness, consistency, and lifecycle relevance?Evidence has a clear verifier, trust anchor, policy, or audit path
Retention
CRA Art. 31
How long will the evidence remain available and useful?Retention, access, refresh, supersession, and revocation are defined

Minimum Useful Evidence

For most assurance decisions, useful evidence should show:

  • what decision it supports;
  • what supplier, product, component, release, service, or lifecycle stage it covers;
  • who produced it;
  • when it was generated or last reviewed;
  • how origin, integrity, freshness, scope, or consistency can be checked;
  • what gaps, exceptions, or risk acceptances remain;
  • where the evidence will be retained and when it must be refreshed.

Checklist Use

  1. Name the decision.
  2. Identify the lifecycle stage.
  3. Name the failure mode or assurance concern.
  4. Select the relevant evidence areas.
  5. Request artifacts, owners, scope, dates, and verification paths.
  6. Record whether the answer is weak, better, stronger, or still incomplete.
  7. Decide whether evidence is sufficient, conditional, rejected, or needs remediation.
  8. Record retention, refresh, supersession, and exception handling.