[{"data":1,"prerenderedAt":316},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-supply-chain-cybersecurity":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":15,"entities":262,"extension":264,"faq":265,"keywords":283,"meta":288,"navigation":289,"ogImage":290,"path":14,"persona":291,"publishedAt":290,"regulation":290,"relatedFeatures":292,"relatedPages":296,"seo":299,"shortTitle":13,"slug":300,"sources":301,"stem":312,"tldr":313,"updatedAt":314,"__hash__":315},"solutions_en\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity.md","Supply Chain Cybersecurity: Control Third-Party Risk | CISAPP","CISAPP",{"type":108,"value":109,"toc":255},"minimark",[110,115,123,142,146,237,241,244],[111,112,114],"h2",{"id":113},"what-is-supply-chain-cybersecurity","What is supply chain cybersecurity?",[116,117,118,122],"p",{},[119,120,121],"strong",{},"Supply chain cybersecurity is the control of cyber risk introduced by third parties: direct vendors, their subcontractors, and embedded software components."," A growing share of incidents does not originate in the victim's own systems, but at a provider holding legitimate access.",[124,125,126],"key-takeaways",{},[127,128,129,133,136,139],"ul",{},[130,131,132],"li",{},"The scope extends past the direct vendor: the chain has tier 2 and tier 3.",[130,134,135],{},"NIS2 (Art. 21), DORA and ISO\u002FIEC 27001 (A.5.21) require it explicitly.",[130,137,138],{},"A vendor list says nothing about criticality: it must be tied to the activities supported.",[130,140,141],{},"Without remediation tracking, an assessment reduces no risk.",[111,143,145],{"id":144},"which-vectors-which-controls","Which vectors, which controls?",[147,148,150],"comparison-table",{"caption":149},"Main supply chain risk vectors and matching controls",[151,152,153,169],"table",{},[154,155,156],"thead",{},[157,158,159,163,166],"tr",{},[160,161,162],"th",{},"Vector",[160,164,165],{},"Example",[160,167,168],{},"Control",[170,171,172,184,195,211,222],"tbody",{},[157,173,174,178,181],{},[175,176,177],"td",{},"Provider access",[175,179,180],{},"Support or remote maintenance account",[175,182,183],{},"Access review, MFA required by contract",[157,185,186,189,192],{},[175,187,188],{},"Vendor compromise",[175,190,191],{},"Tampered software update",[175,193,194],{},"Signature verification, vendor monitoring",[157,196,197,200,203],{},[175,198,199],{},"Software dependency",[175,201,202],{},"Vulnerable third-party library",[175,204,205,210],{},[206,207,209],"a",{"href":208},"\u002Fen\u002Fglossary\u002Fsbom","SBOM"," and vulnerability tracking",[157,212,213,216,219],{},[175,214,215],{},"Cascading subcontracting",[175,217,218],{},"Your vendor's hosting provider",[175,220,221],{},"Contractual disclosure of the chain",[157,223,224,227,230],{},[175,225,226],{},"Concentration",[175,228,229],{},"Several services on one third party",[175,231,232,236],{},[206,233,235],{"href":234},"\u002Fen\u002Fglossary\u002Fconcentration-risk","Concentration risk"," analysis",[111,238,240],{"id":239},"from-a-vendor-list-to-a-risk-map","From a vendor list to a risk map",[116,242,243],{},"A plain vendor list says nothing about real criticality. CISAPP links each third party to the activities it supports, targets security assessments at the most critical, and tracks every identified risk in a shared register through to closure — aligned with NIS2 and DORA supply chain requirements.",[116,245,246,247,250,251,254],{},"See also ",[206,248,249],{"href":10},"NIS2 vendor compliance"," and the ",[206,252,253],{"href":76},"supply chain cyberattack"," guide.",{"title":256,"searchDepth":257,"depth":257,"links":258},"",2,[259,260,261],{"id":113,"depth":257,"text":114},{"id":144,"depth":257,"text":145},{"id":239,"depth":257,"text":240},[67,209,263],"Vendor SPOF","md",[266,268,271,274,277,280],{"q":114,"a":267},"It is the control of cyber risk introduced by an organisation's third parties: direct vendors, their own subcontractors, and the software components embedded in your products. The scope therefore extends beyond the immediate contractual relationship.",{"q":269,"a":270},"Why is supply chain cybersecurity a regulatory topic?","NIS2 and DORA explicitly require control of the cyber risk posed by critical vendors and providers, and ISO\u002FIEC 27001:2022 devotes control A.5.21 to ICT supply chain security.",{"q":272,"a":273},"How do you handle the risk from your vendors' subcontractors?","Through declaration: the contract requires the vendor to disclose its subcontracting chain and any changes to it. This is [fourth-party risk](\u002Fen\u002Fglossary\u002Ffourth-party-risk) — you cannot assess it directly, but you can make it visible.",{"q":275,"a":276},"What is an SBOM for in this context?","An [SBOM](\u002Fen\u002Fglossary\u002Fsbom) lists the software components of a product. It lets you answer the question 'are we exposed to this vulnerability?' in hours rather than weeks when a flaw is published in a widely used library.",{"q":278,"a":279},"Does CISAPP track remediation after an assessment?","Yes. Every identified risk is tracked to closure, with remediation evidence attached to the vendor concerned and an enforceable deadline.",{"q":281,"a":282},"Where do you start when no mapping exists?","With activities, not vendors: list the processes whose interruption would be unacceptable, then work back to the third parties supporting them. The resulting list is far shorter than the procurement inventory and is enough to get started.",[284,285,286,287],"supply chain cybersecurity","vendor cyber risk","supply chain security","third-party cyber risk",{},true,null,"entreprise",[293,294,295],"Dependency mapping","Risk register","Assessment campaigns",[297,298],"nis2-vendor-compliance","vendor-risk-management",{"title":105,"description":15},"supply-chain-cybersecurity",[302,307],{"label":303,"url":304,"publisher":305,"date":306},"Directive (EU) 2022\u002F2555 (NIS2), Article 21 — supply chain security","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2022\u002F2555\u002Foj","EUR-Lex","2022-12-14",{"label":308,"url":309,"publisher":310,"date":311},"ISO\u002FIEC 27001:2022, control A.5.21 — ICT supply chain security","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fsolutions\u002Fsupply-chain-cybersecurity","Supply chain cybersecurity covers the risk introduced by vendors, their own subcontractors and the software components you embed. It is explicitly required by NIS2 (Article 21), DORA and ISO\u002FIEC 27001 (control A.5.21). CISAPP addresses it by connecting dependency mapping, security assessments and remediation tracking.","2026-08-16","QTBOt-Vf51gqljeDJOJppuFXZddLGywkN7KcO8Ws434",1791391138947]