NIST 800-53 REV 5 • SYSTEM AND SERVICES ACQUISITION
SA-22(1) — Alternative Sources for Continued Support
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
When a vendor discontinues support for a product you depend on, seek alternative sources for continued support — extended support contracts, third-party maintenance providers, or community-maintained patches.
Example 1: Before a product reaches end-of-life, research alternative support options: Microsoft Extended Security Updates (ESU) for Windows Server, Oracle Lifetime Support, or third-party providers like Rimini Street that offer extended support for products the original vendor no longer patches.
Example 2: For open-source components that are no longer actively maintained, evaluate community forks that have taken over development. If no alternative support exists, prioritize migration to a supported product and treat the unsupported component as a high-risk item in your risk register.