Supply Chain Assurance

Download the Preliminary Draft

The NCCoE has released the preliminary draft version of NIST Cybersecurity Practice Guide SP 1800-34, Validating the Integrity of Computing Devices. Use the button below to view Volume B. Work continues on Volume C of this practice guide.

Download PDF »

Current Status

The National Cybersecurity Center of Excellence is following an agile process to make each volume for the Validating the Integrity of Computing Devices project available as a preliminary draft  for public comment, as work continues on the system implementation and development of other sections of the publication.

Currently, the project team is reviewing the public comments on Volume B of this publication.

  • SP 1800-34A: Executive Summary (PDF)
  • SP 1800-34B: Approach, Architecture, and Security Characteristics (PDF)
  • SP 1800-34C: How-To-Guides (under development)

To receive news and updates about this project, please join the Supply Chain Assurance Community of Interest by sending an email to  

Additionally, you can learn more about the NCCoE project on supply chain assurance by reading the Validating the Integrity of Computing Devices Project Description


Organizations today face the challenge of identifying trustworthy products due to increased risk resulting from compromises in cyber supply chains.  Cyber Supply Chain Risk Management is an evolving approach to modernizing information technology (IT) systems, as information and operational technologies rely on complex, globally distributed and interconnected, supply chain ecosystems to provide highly refined, cost-effective, and reusable solutions.  

For this project, the NCCoE will produce example implementations to demonstrate how organizations can verify that the internal components of their purchased computing devices are genuine and have not been altered during the manufacturing and distribution processes.  Additionally, this project will demonstrate how to inspect the processes that verify that the components in a computing device match the attributes and measurements declared by the manufacturer.

This project will result in a publicly available NIST Cybersecurity Practice Guide, a detailed implementation guide of the practical steps needed to implement a cybersecurity reference architecture model that addresses the challenge.


Supply Chain Assurance Community of Interest Update

The NCCoE’s Supply Chain Assurance project team and collaborators provided an update on the Validating the Integrity of Computing Devices project during an NCCoE Collaborator Series Webinar on March 18th, 2021. The team discussed the scope of the project and the roles that each collaborator is playing in developing the sample solution.

Collaborating Vendors

Organizations participating in this project submitted their capabilities in response to an open call in the Federal Register for all sources of relevant security capabilities from academia and industry (vendors and integrators). The following respondents with relevant capabilities or product components (identified as “Technology Partners/Collaborators” herein) signed a Cooperative Research and Development Agreement to collaborate with NIST in a consortium to build this example solution.

Hewlett Packard Enterprise logo
RSA logo