Software supply chain security is rapidly building its own risk-management toolbox: software bills of materials (SBOMs), provenance and build-integrity frameworks such as SLSA, dependency graphs, and repository-health scorecards. Physical supply chain risk management (SCRM) has spent decades developing structurally similar instruments, including multi-tier visibility programs, criticality and single-source analysis, cascading-failure and disruption-propagation models, supplier audits and ratings, and standards such as ISO 28000 and ISO 31000. Yet the two literatures remain almost entirely disconnected, and the software security community risks re-deriving known results, repeating documented failures, or overlooking mature methods that could transfer. This paper systematizes knowledge across both fields. We place physical SCRM methods and software supply chain security mechanisms in a common risk-management reference frame spanning risk identification, assessment, mitigation, and monitoring, and construct an explicit mapping between the two, for example bill of materials and SBOM, supplier audit and attestation, tier visibility and transitive dependency depth. For each physical-side method we assess whether it transfers directly, transfers with adaptation, or fails to transfer, identify one transfer that runs in reverse, and analyze why, drawing on structural differences such as the zero marginal cost of software replication, adversarial rather than predominantly stochastic disruptions, and dependency graphs of far larger scale and faster dynamics. From this analysis we derive a research agenda identifying which validated SCRM instruments are ready for evaluation in software ecosystems and where software-native methods are genuinely required.