# IR-06 (03) Supply Chain Coordination — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ir-6.3

Canonical id: `ir-6.3` · family `IR`

> Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-INR-RIR` — Reviewing Incident Response Procedures (Incident Response)
  The effectiveness of documented incident response procedures is persistently reviewed.
- `KSI-SCR-MON` — Monitoring Supply Chain Risk (Supply Chain Risk)
  Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

## FedRAMP guidance

{
  "guidance": [
    "Follow the FedRAMP Incident Evaluation and Communication rules."
  ]
}
