Supplier Cyber Assurance: How to Assess Third Parties Sensibly
Published 20 July 2026
Why most supplier assurance fails
We see two anti-patterns. Either organisations send identical 200-question security questionnaires to every supplier (and rarely read the answers), or they do nothing at all and rely on the supplier's website badge. The CSR Bill raises the bar for regulated buyers, but the right answer is proportionate, not exhaustive.
Step 1: Tier your suppliers
- Tier 1 – Critical: Hold customer data, process payments, run core production systems, or single-source dependency. Outage hurts revenue immediately.
- Tier 2 – Important: Handle staff or commercial data, integrate with core systems, or operationally awkward to replace.
- Tier 3 – Standard: No sensitive data, no system integration, easily substitutable.
Step 2: Evidence requirements per tier
| Tier | Minimum evidence | Frequency |
|---|---|---|
| Critical | ISO 27001 / SOC 2 Type II / CE Plus + CA Level 2 + DPA + sub-processor list | Annual review, contract change triggers |
| Important | CE Plus or CA Level 1, recent pen test summary, DPA | Annual confirmation |
| Standard | CE certificate, DPA if any data shared | Annual confirmation |
Step 3: A short, reusable questionnaire
Keep the questions to what is not already on the certificate:
- Do you hold a current CE or CE+ certificate? (link or upload)
- Where are our data and backups stored geographically?
- Who has admin access to our data on your side?
- How quickly will you notify us of a breach affecting our data?
- Do you sub-contract any processing? List the sub-processors.
- When was your last pen test? Provide the executive summary.
Step 4: Contract clauses that pull the weight
- Maintain CE/CE+ throughout the contract
- Notify within 24 hours of a breach involving customer data
- Right to audit on reasonable notice (or accept ISO/SOC reports in lieu)
- Pre-approval for sub-processor changes
- Data return and deletion obligations on termination
Step 5: Annual review, not annual reassessment
Use the supplier's certificate renewal date as your annual checkpoint. Confirm the certificate is still valid, the scope still matches what they do for you, and ask only about changes since last year. This keeps supplier fatigue down and your evidence current.
How CSR Bill changes the picture
Regulated buyers under the CSR Bill become formally responsible for supplier cyber posture in their reporting and incident-handling chain. The buyer's regulator will not care that "the supplier said they were secure". Have evidence, dated, tiered, on file.
