SR-4(4) - Provenance | Supply Chain Integrity — Pedigree

Employ [Assignment: organization-defined controls] and conduct [Assignment: organization-defined analysis] to ensure the integrity of the system and system components by validating the internal composition and provenance of critical or mission-essential technologies, products, and services.


ID: SR-4(4)
Enhancement of : SR-4

Space Segment Guidance

Supply chain integrity, or “pedigree,” attests to the trustworthiness of a component’s entire manufacturing and handling lineage. Beyond identity and track-and-trace, pedigree requires thorough documentation of testing procedures, environmental certifications, code reviews, or background checks on the manufacturing workforce. It also often includes attestation from third-party labs (e.g., for rad-hardening or cryptographic compliance). Within high-assurance space systems, organizations may create whitelists of vetted vendors, apply rigorous acceptance inspections, and continuously re-verify items stored for future use. By mandating robust pedigree requirements, the space program reduces the possibility of latent backdoors or untested vulnerabilities creeping into flight hardware and software. This strategy shields spacecraft from direct sabotage and curtails unintentional faults arising from poor-quality components.