NIST 800-53 REV 5 • SYSTEM AND SERVICES ACQUISITION

SA-22(1)Alternative Sources for Continued Support

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

When a vendor discontinues support for a product you depend on, seek alternative sources for continued support — extended support contracts, third-party maintenance providers, or community-maintained patches.

Example 1: Before a product reaches end-of-life, research alternative support options: Microsoft Extended Security Updates (ESU) for Windows Server, Oracle Lifetime Support, or third-party providers like Rimini Street that offer extended support for products the original vendor no longer patches.

Example 2: For open-source components that are no longer actively maintained, evaluate community forks that have taken over development. If no alternative support exists, prioritize migration to a supported product and treat the unsupported component as a high-risk item in your risk register.