Solutions

Supply Chain Cybersecurity: Control Third-Party Risk

Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.

TL;DR

Supply chain cybersecurity covers the risk introduced by vendors, their own subcontractors and the software components you embed. It is explicitly required by NIS2 (Article 21), DORA and ISO/IEC 27001 (control A.5.21). CISAPP addresses it by connecting dependency mapping, security assessments and remediation tracking.

What is supply chain cybersecurity?

Supply chain cybersecurity is the control of cyber risk introduced by third parties: direct vendors, their subcontractors, and embedded software components. A growing share of incidents does not originate in the victim's own systems, but at a provider holding legitimate access.

Which vectors, which controls?

Main supply chain risk vectors and matching controls
VectorExampleControl
Provider accessSupport or remote maintenance accountAccess review, MFA required by contract
Vendor compromiseTampered software updateSignature verification, vendor monitoring
Software dependencyVulnerable third-party librarySBOM and vulnerability tracking
Cascading subcontractingYour vendor's hosting providerContractual disclosure of the chain
ConcentrationSeveral services on one third partyConcentration risk analysis

From a vendor list to a risk map

A plain vendor list says nothing about real criticality. CISAPP links each third party to the activities it supports, targets security assessments at the most critical, and tracks every identified risk in a shared register through to closure — aligned with NIS2 and DORA supply chain requirements.

See also NIS2 vendor compliance and the supply chain cyberattack guide.

FAQ

It is the control of cyber risk introduced by an organisation's third parties: direct vendors, their own subcontractors, and the software components embedded in your products. The scope therefore extends beyond the immediate contractual relationship.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Article 21 — supply chain security — EUR-Lex, 2022-12-14
  2. ISO/IEC 27001:2022, control A.5.21 — ICT supply chain security — ISO, 2022-10-25

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account