A supplier breach can be as damaging as a direct attack on your own systems — and it is your problem to manage, not theirs. This guide walks you through identifying critical vendors, sending questionnaires, scoring responses, and maintaining a live risk register.
Not every supplier is a security risk. Focus your effort on vendors who have access to your systems, your data, or whose failure would disrupt your operations. Start by listing all your third-party relationships and scoring them against three criteria.
Does the vendor handle, store, or process personal data, financial data, or confidential business information on your behalf?
Does the vendor have access to your IT systems, networks, source code, or infrastructure — remotely or on-site?
Would your operations be significantly disrupted if this vendor had an outage or security incident? Cloud providers, payment processors, and logistics platforms often qualify.
What they look for
ISO 27001 clause 8.1.4 and NIS2 Article 21 both require documented supply chain risk management. If audited or questioned by a client, you should be able to produce your vendor list with risk ratings, the criteria used to tier them, and a date showing when it was last reviewed.
Once you have a list, classify vendors into tiers. Tiering determines how much due diligence to apply and how often to review. Most organisations use three tiers.
High data access or business dependency. Requires full security questionnaire, annual review, and evidence of their own certifications (CE+, ISO 27001, SOC 2).
Moderate access or dependency. Streamlined questionnaire, biennial review, and review of their public security posture.
Minimal access, easily replaceable. Lightweight check at onboarding, no ongoing review unless circumstances change.
What they look for
Your vendor tiering criteria should be documented — not just applied. Clients and auditors will ask how you decided a vendor was Tier 1 vs Tier 2. A one-page document explaining your criteria (data access, system access, business dependency) and your review cadence satisfies this.
A security questionnaire asks your vendor to self-report their controls across the areas that matter to you. The goal is not a perfect score — it is to identify material gaps and surface conversations you need to have.
How do they manage access to systems that hold your data? Do they use MFA? Do they have a joiners/movers/leavers process?
Where is your data stored? Is it encrypted at rest and in transit? Who can access it? Is it shared with sub-processors?
Do they have a documented incident response plan? What is their process for notifying customers of a breach? What is their average detection-to-notification time?
Do they hold CE+, ISO 27001, SOC 2, or equivalent? When was their last penetration test? Are they willing to share the executive summary?
What is their RTO and RPO? Do they have documented DR plans? Have they been tested in the last 12 months?
What they look for
A completed questionnaire response from each critical vendor, with your date of receipt. For ISO 27001 and NIS2, this is mandatory for significant suppliers. If a vendor has ISO 27001 certification, request their certificate as a shortcut — but check the scope covers the services they provide to you.
Responses need to be evaluated, not just collected. Score each vendor against your minimum expectations and document any gaps — including whether the gap is acceptable given compensating controls, or whether it is a blocker.
What is the minimum standard you expect from a Tier 1 vendor? MFA, encryption at rest, incident notification within 72 hours, and a security contact are reasonable starting points.
Green/amber/red or a numeric score against each domain. The goal is to see the overall picture at a glance and identify vendors that need follow-up.
For vendors with amber or red findings, document whether you accepted the risk, required remediation, or chose not to proceed. The record is the evidence.
What they look for
Your scoring record and the decision you made: accepted, remediation required, or not proceeded. For amber and red findings, the documented decision and rationale is the evidence. Saying 'we were aware and chose to proceed for these reasons' is defensible; having no record of the gap is not.
Vendor risk is not static — suppliers change their infrastructure, get acquired, suffer breaches, or lose certifications. Your register needs to stay live.
Tier 1 annually, Tier 2 every two years, Tier 3 at a material change. Calendar the reviews and track them the same way you track other compliance tasks.
When a vendor suffers a breach or outage, reassess their tier and review their questionnaire before the next scheduled date.
When a vendor relationship ends, confirm data deletion, revoke access, and close the register entry with a date and evidence of data removal.
What they look for
A dated vendor register with risk rating, last review date, and DPA status. For GDPR, you also need DPAs with every processor — your vendor risk register and your GDPR processor list should cross-reference. Clients doing due diligence on you will ask for evidence of your vendor risk management process.
Where people go wrong
Assessing vendors at onboarding and never again
Vendors change: they get acquired, they suffer breaches, they migrate to new cloud infrastructure. A vendor that was low-risk at onboarding may have changed significantly in two years. Annual reviews for Tier 1 vendors are not optional.
Accepting 'we are ISO 27001 certified' without checking scope
ISO 27001 certification is scoped. A vendor may be certified for their development team but not for the hosting environment that stores your data. Always ask for the certificate and check what it covers.
No record of the decision when proceeding with a high-risk vendor
Proceeding with a vendor who has amber or red findings is sometimes a reasonable business decision. But without a documented risk acceptance — naming who approved it and why — you have no defensible position if that vendor's gap causes a breach.
Forgetting sub-processors — vendors your vendors use
If your CRM uses AWS and AWS suffers a breach affecting your data, you are still liable. Your vendor questionnaire should ask about sub-processors, and your DPAs should require notification if sub-processors change.
Do we need to assess every supplier we use?
No. Focus on vendors with data access, system access, or critical business dependency. A stationery supplier or a coffee delivery service is not a cyber risk; your cloud storage provider or payroll bureau is. Tiering lets you apply proportionate effort.
What if a vendor refuses to complete a questionnaire?
Refusal is itself useful information. For Tier 1 vendors, it should be a significant concern. You can ask for their ISO 27001 certificate or SOC 2 report in lieu, but an outright refusal to engage with security due diligence should factor into your decision to use them.
What does NIS2 require for supply chain risk?
NIS2 Article 21 explicitly requires essential and important entities to manage information security risks in their supply chains. This means documented supplier risk assessments, contractual security requirements, and ongoing monitoring — not just a one-time questionnaire.
How do we handle a vendor that has been breached?
First, confirm whether your data was affected. Then review whether the vendor met their breach notification obligations. Reassess their tier and questionnaire responses. If material gaps are identified, require a remediation plan or consider an alternative supplier.
Send customisable security questionnaires to suppliers, score responses, and maintain a live vendor risk register — with evidence attached and review dates tracked.