Unsupported Software Findernotice of vendor support

NIST SP 800-53: what it asks of unsupported software

SA-22 asks that system components are replaced when support is no longer available from the developer, vendor or manufacturer, or that alternative sources of continued support are provided. CM-8 asks for an accurate component inventory; SI-2 asks that security-relevant updates are installed within an organisation-defined period.

Scheme
NIST SP 800-53 Rev 5
When it is placed
Placed when you say NIST SP 800-53 is your control set.
Held text
NIST SP 800-53 Rev 5 on the standards site, read 30 Sep 2026

Findings that cite it

9 of 10

The clauses cited

3 clauses
NIST SP 800-53 CM-8System Component Inventory

CM-8 System Component Inventory. a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].

What an assessor asks to see: Configuration management policy; Procedures addressing system component inventory; Configuration management plan; System security plan; System design documentation; System component inventory; Inventory reviews and update records; Test of Organizational processes for managing the system component inventory; mechanisms supporting and/or implementing system component inventory
Where software lists usually fall short: The component inventory omits components found on the network, or double-counts components assigned to other systems; The inventory lacks the defined accountability information and is not reviewed and updated at the defined frequency
Source: NIST SP 800-53 Rev 5, read 30 Sep 2026
NIST SP 800-53 SA-22Unsupported System Components

SA-22 Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support for unsupported components [Selection (one or more): in-house support; [Assignment: organization-defined support from external providers]].

What an assessor asks to see: System and services acquisition policy; Procedures addressing the replacement or continued use of unsupported system components; Documented evidence of replacing unsupported system components; Documented approvals (including justification) for the continued use of unsupported system components; System security plan; Supply chain risk management plan; Test of Organizational processes for replacing unsupported system components; mechanisms supporting and/or implementing the replacement of unsupported system components
Where software lists usually fall short: Components past developer or vendor end of support remain in service without a replacement plan; No in-house or external alternative support arrangement is documented for unsupported components still in use
Source: NIST SP 800-53 Rev 5, read 30 Sep 2026
NIST SP 800-53 SI-2Flaw Remediation

SI-2 Flaw Remediation. a. Identify, report, and correct system flaws; b. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and d. Incorporate flaw remediation into the organizational configuration management process.

What an assessor asks to see: System and information integrity policy; System and information integrity procedures; Procedures addressing flaw remediation; Procedures addressing configuration management; List of flaws and vulnerabilities potentially affecting the system; List of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws); Test results from the installation of software and firmware updates to correct system flaws; Installation/change control records for security-relevant software and firmware updates; System security plan; Test of Organizational processes for identifying, reporting, and correcting system flaws; organizational process for installing software and firmware updates; mechanisms supporting and/or implementing the reporting and correcting of system flaws; mechanisms supporting and/or implementing testing software an
Where software lists usually fall short: Security-relevant updates installed outside the organization-defined time period with no recorded exception or risk acceptance; Updates deployed to production without the testing for effectiveness and side effects that SI-2 b requires
Source: NIST SP 800-53 Rev 5, read 30 Sep 2026

See the specimen list runCheck your own list