Skip to main content
    NixInfinity-AI
    Supply Chain

    Supplier Cyber Assurance: How to Assess Third Parties Sensibly

    Published 20 July 2026

    Why most supplier assurance fails

    We see two anti-patterns. Either organisations send identical 200-question security questionnaires to every supplier (and rarely read the answers), or they do nothing at all and rely on the supplier's website badge. The CSR Bill raises the bar for regulated buyers, but the right answer is proportionate, not exhaustive.

    Step 1: Tier your suppliers

    • Tier 1 – Critical: Hold customer data, process payments, run core production systems, or single-source dependency. Outage hurts revenue immediately.
    • Tier 2 – Important: Handle staff or commercial data, integrate with core systems, or operationally awkward to replace.
    • Tier 3 – Standard: No sensitive data, no system integration, easily substitutable.

    Step 2: Evidence requirements per tier

    TierMinimum evidenceFrequency
    CriticalISO 27001 / SOC 2 Type II / CE Plus + CA Level 2 + DPA + sub-processor listAnnual review, contract change triggers
    ImportantCE Plus or CA Level 1, recent pen test summary, DPAAnnual confirmation
    StandardCE certificate, DPA if any data sharedAnnual confirmation

    Step 3: A short, reusable questionnaire

    Keep the questions to what is not already on the certificate:

    • Do you hold a current CE or CE+ certificate? (link or upload)
    • Where are our data and backups stored geographically?
    • Who has admin access to our data on your side?
    • How quickly will you notify us of a breach affecting our data?
    • Do you sub-contract any processing? List the sub-processors.
    • When was your last pen test? Provide the executive summary.

    Step 4: Contract clauses that pull the weight

    • Maintain CE/CE+ throughout the contract
    • Notify within 24 hours of a breach involving customer data
    • Right to audit on reasonable notice (or accept ISO/SOC reports in lieu)
    • Pre-approval for sub-processor changes
    • Data return and deletion obligations on termination

    Step 5: Annual review, not annual reassessment

    Use the supplier's certificate renewal date as your annual checkpoint. Confirm the certificate is still valid, the scope still matches what they do for you, and ask only about changes since last year. This keeps supplier fatigue down and your evidence current.

    How CSR Bill changes the picture

    Regulated buyers under the CSR Bill become formally responsible for supplier cyber posture in their reporting and incident-handling chain. The buyer's regulator will not care that "the supplier said they were secure". Have evidence, dated, tiered, on file.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions