Solutions
Supply Chain Cybersecurity: Control Third-Party Risk
Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.
TL;DR
Supply chain cybersecurity covers the risk introduced by vendors, their own subcontractors and the software components you embed. It is explicitly required by NIS2 (Article 21), DORA and ISO/IEC 27001 (control A.5.21). CISAPP addresses it by connecting dependency mapping, security assessments and remediation tracking.
What is supply chain cybersecurity?
Supply chain cybersecurity is the control of cyber risk introduced by third parties: direct vendors, their subcontractors, and embedded software components. A growing share of incidents does not originate in the victim's own systems, but at a provider holding legitimate access.
Which vectors, which controls?
| Vector | Example | Control |
|---|---|---|
| Provider access | Support or remote maintenance account | Access review, MFA required by contract |
| Vendor compromise | Tampered software update | Signature verification, vendor monitoring |
| Software dependency | Vulnerable third-party library | SBOM and vulnerability tracking |
| Cascading subcontracting | Your vendor's hosting provider | Contractual disclosure of the chain |
| Concentration | Several services on one third party | Concentration risk analysis |
From a vendor list to a risk map
A plain vendor list says nothing about real criticality. CISAPP links each third party to the activities it supports, targets security assessments at the most critical, and tracks every identified risk in a shared register through to closure — aligned with NIS2 and DORA supply chain requirements.
See also NIS2 vendor compliance and the supply chain cyberattack guide.
FAQ
It is the control of cyber risk introduced by an organisation's third parties: direct vendors, their own subcontractors, and the software components embedded in your products. The scope therefore extends beyond the immediate contractual relationship.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 21 — supply chain security — EUR-Lex, 2022-12-14
- ISO/IEC 27001:2022, control A.5.21 — ICT supply chain security — ISO, 2022-10-25
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours