A supplier questionnaire is useful only when it changes a sourcing, architecture or risk decision.
NIST SP 1326, published in July 2026, identifies five due-diligence components for ICT suppliers: foreign ownership, control or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers. The framework helps buyers move beyond generic assurances.
What good engineering looks like
Tailor evidence to the product and consequence. A low-impact collaboration tool does not require the same depth as software controlling payments or critical operations. Verify material claims and record residual risk, compensating controls and ownership.
-
Ownership and control relevant to access or continuity.
-
Provenance of components, development and distribution.
-
Resilience of service, support and recovery.
-
Evidence of foundational security practices.
-
Visibility into important subcontractors and dependencies.
A practical starting point
-
Classify the intended system by business impact.
-
Request evidence against the five areas.
-
Validate high-impact claims with technical specialists.
-
Document acceptance conditions and ongoing monitoring.
The decision to make
Due diligence is complete when evidence supports an explicit decision, not when every questionnaire field contains an answer.