Feature 3 of 6 · Supply chain
Suppliers in view Whoever has access gets assessed too.
Many attacks come in through service providers. That is why NIS2 and ISO 27001 require you to know your suppliers and assess their security regularly.

What it is about
Supplier assessments often end up in a spreadsheet that nobody touches after the first round. Then, in the audit, nobody knows when an important provider was last checked or with what result.
What you do with it
- Record for each supplier how critical it is for your services.
- Capture which controls are in place and which are missing.
- Have a risk score calculated and set a review cycle.
- Take suppliers over from the inventory without creating them twice.
What you get out of it
- You always know which supplier is due for review next.
- The supply chain shows up with its status in the dashboard and the reports.
Part of these steps
Where the requirements come from
- BSIG section 30(2) no. 4: supply chain security
- ISO/IEC 27001, Annex A 5.19 to 5.22: information security in supplier relationships
The references show where the requirements come from. They do not replace a legal assessment.
See it with your own questions.
In half an hour we show you what this feature looks like in your day-to-day work. Or check first where you stand with the quick check.
