Suppliers
Supplier and third-party risk management
Many incidents arrive through a supplier: IT support, a cloud service, finance software. NIS2 and DORA require you to manage that risk, and the responsibility stays with you. We tier your suppliers by criticality, check their contracts and leave a working process for new suppliers.
Scope and price are confirmed in writing before work starts.
Discuss your caseThe benefit for your organisation
- You know which suppliers are critical and what happens if one of them stops.
- You know which requirements are missing from critical suppliers’ contracts and what to renegotiate.
- New suppliers go through a clear check before they get access.
Supplier risk package
Up to 20 suppliers: a register and criticality tiers, a questionnaire matched to criticality, contract checks for up to 5 critical suppliers and an onboarding procedure.
from €3 900usually 3–4 weeks
Ongoing review
An annual review of critical suppliers, new suppliers and contract changes as part of an external expert role.
from €1 400 / monthwithin an external role
What the rules require
- NIS2 requires supply-chain security measures, taking into account each direct supplier’s vulnerabilities, the overall quality of its products and its security practices, including secure development (Art. 21(2)(d) and 21(3)).
- DORA requires an ICT third-party risk policy, a register of information covering all contracts, pre-contract assessment and documented exit strategies (Art. 28), plus mandatory contract provisions (Art. 30). Responsibility does not transfer to the provider.
- The GDPR requires a contract with every processor acting on your behalf (Art. 28).
How it works
- A supplier inventory from contracts, finance and IT: who provides what and which data and systems they can reach.
- Criticality tiers: which services stop if the supplier stops, and what access it has.
- A questionnaire matched to criticality and a review of answers and evidence for critical suppliers.
- Contract checks for critical suppliers: security obligations, incident notification, audit rights, subcontractors, data location and exit.
What you receive
- A supplier register with criticality tiers.
- An assessment of critical suppliers and a list of risks.
- A list of missing contract requirements to renegotiate. Legal wording and negotiation are a separate next step.
- A procedure for new suppliers and annual review. For financial entities: guidance on exit strategies.
After the review we can implement the agreed measures or coordinate your team or a suitable partner. Implementation is quoted separately.
We also know the other side: we prepare ICT providers for banks’ reviews. See the bank supplier pack.
Boundaries
- This is not a legal contract review.
- On-site checks at a supplier are agreed separately.
- Responsibility for supplier risk remains with your organisation.
General information, not a legal opinion.