Skip to main content
Back to insights

Supplier Due Diligence for ICT: Five Evidence Areas

NIST's 2026 guide frames ICT supplier due diligence around ownership, provenance, resilience, cyber practices and supply-chain tiers.

  • Software engineering
  • Architecture
  • Engineering leadership

Arinao Tshamano24 September 20261 min read

A supplier questionnaire is useful only when it changes a sourcing, architecture or risk decision.

NIST SP 1326, published in July 2026, identifies five due-diligence components for ICT suppliers: foreign ownership, control or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers. The framework helps buyers move beyond generic assurances.

What good engineering looks like

Tailor evidence to the product and consequence. A low-impact collaboration tool does not require the same depth as software controlling payments or critical operations. Verify material claims and record residual risk, compensating controls and ownership.

  • Ownership and control relevant to access or continuity.

  • Provenance of components, development and distribution.

  • Resilience of service, support and recovery.

  • Evidence of foundational security practices.

  • Visibility into important subcontractors and dependencies.

A practical starting point

  1. Classify the intended system by business impact.

  2. Request evidence against the five areas.

  3. Validate high-impact claims with technical specialists.

  4. Document acceptance conditions and ongoing monitoring.

The decision to make

Due diligence is complete when evidence supports an explicit decision, not when every questionnaire field contains an answer.

Sources and further reading

Apply the thinking

Working through a related technology decision?

Share the operational context, current systems, constraints, and decision you need to make.

Discuss a requirement