Acquisition Strategies, Tools, and Methods is a net-new requirement in R3 that puts supply chain protection into the purchasing process itself. It is part of the Supply Chain Risk Management (03.17) family, which did not exist in R2 at all. Acquisition Strategies, Tools, and Methods (03.17.02) requires developing and implementing acquisition strategies, contract tools, and procurement methods to identify, protect against, and mitigate supply chain risks. Per the NIST discussion, the acquisition process provides an important vehicle for protecting the supply chain, and useful tools and techniques include obscuring the end use of a system or system component, using blind purchases, requiring tamper-evident packaging, or using trusted or controlled distribution.
A common difficulty with this requirement is treating supply chain risk as a security team concern that never reaches purchasing. This requirement lives where contracts get written and orders get placed, so it usually needs people outside the security function. The other common gap is developing strategies on paper without implementing them, since R3 assesses developing and implementing as separate objectives for each of the three purposes.
Where things stand for companies facing the transition from NIST 800-171 R2 to R3:
The following is reproduced verbatim from NIST 800-171 R3, requirement 03.17.02 Acquisition Strategies, Tools, and Methods. Only the formatting has been adjusted for readability. This is a single statement with no lettered parts:
The source control is SR-05 from NIST 800-53. There are no Organization-Defined Parameters (ODPs). Per the NIST discussion, the results from a supply chain risk assessment can inform the strategies, tools, and methods that are most applicable to the situation, and organizations also consider providing incentives for suppliers to implement safeguards, promote transparency in their processes and security practices, provide contract language that addresses the prohibition of tainted or counterfeit components, and restrict purchases from untrustworthy suppliers. You can read the requirement directly at NIST 800-171 R3, 03.17.02 (p. 73).
None (0). Requirement 03.17.02 contains no bracketed assignment, so there is no organization-defined value to select and nothing for the DoD to specify. The requirement applies as written.
Your System Security Plan (SSP) narrative for 03.17.02 therefore records how the requirement is implemented rather than a parameter you chose.
NIST 800-171A R3 breaks 03.17.02 into six (6) determination statements, and it has no Organization-Defined Parameters (ODPs). These AOs are:
The structure is a three-by-two grid: identify, protect against, and mitigate, each assessed for both developing ([01] through [03]) and implementing ([04] through [06]). The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.17.02 (p. 96).
Examine: SCRM policy and procedures; SCRM plan; system and services acquisition policy and procedures; procedures for supply chain protection; procedures for the integration of information security requirements into the acquisition process; solicitation documentation; acquisition documentation (including purchase orders); service-level agreements; acquisition contracts for the system, system components, or services; documentation of identified supply chain risks; mitigation plans for supply chain risks; documentation of training, education, and awareness programs for personnel regarding supply chain risk; system security plan.
Interview: personnel with acquisition responsibilities; personnel with SCRM responsibilities; personnel with information security responsibilities.
Test: processes for defining and employing tailored acquisition strategies, contract tools, and procurement methods; mechanisms for implementing tailored acquisition strategies, contract tools, and procurement methods.
03.17.02 is net new for R3 and has no corresponding requirement in NIST 800-171 R2, which had no supply chain risk management family:
Mapped against the six (6) AOs, all six (6) are net new (significant effort), with none direct, indirect, or unmapped. The source control, SR-05, has no R2 predecessor. There is no transition path here, so build the acquisition practices rather than looking for existing R2 evidence to repurpose.
Source Control in NIST 800-53 R5:
Secure Controls Framework (SCF) Crosswalk
Organizations running a single control set across multiple frameworks can satisfy 03.17.02 through the following SCF controls:
The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.
The pitfalls for this net-new requirement are about implementation and reach beyond the security team, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:
Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.17.02 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.17.02 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.
Alongside these, keep the System Security Plan (SSP) narrative for 03.17.02.
With all six (6) AOs net new, 03.17.02 is a significant lift that depends on cross-functional cooperation. A realistic sequence:
How many assessment objectives does NIST 800-171 R3 03.17.02 have? NIST 800-171A R3 breaks 03.17.02 into six (6) assessment objectives. An assessor works through each one separately, so each needs its own evidence.
Which NIST 800-53 R5 control does NIST 800-171 R3 03.17.02 come from? SR-05.
How many Organization-Defined Parameters (ODPs) does NIST 800-171 R3 03.17.02 have? None (0). The requirement contains no bracketed assignment, so there is no organization-defined value and nothing for the DoD to specify.
Where does NIST 800-171 R3 03.17.02 sit in the NIST 800-171 R3 Kill Chain? Phase 4c, Risk Management Practices. The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.
03.17.02 Acquisition Strategies, Tools, and Methods develops and implements acquisition strategies, contract tools, and procurement methods that identify, protect against, and mitigate supply chain risks. It is net new for R3 with no R2 predecessor, so all six (6) objectives are new work, split evenly between developing and implementing. The recurring problem is a policy that never reaches the people placing orders. Let your supply chain risk assessment pick the techniques, put them into contract language and procurement practice, and keep the purchase records that prove they are actually used.
Authoritative sources:
Authoritative sources:
This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.