SP 1326 turns supplier cybersecurity due diligence into a more structured C-SCRM workflow, pushing risk review closer to the moment a vendor is first considered.