Step 2 · Inventory

Supply chain security Managing providers by criticality.

An incident at a service provider can hit your own services. The BSI Act therefore requires you to manage supply chain security, and ISO 27001 provides specific controls for it: assess suppliers and put security requirements into contracts.

What it is about

The BSI Act explicitly lists supply chain security as a minimum measure (Section 30(2) No. 4), including the security aspects of relationships with direct suppliers and service providers. ISO/IEC 27001 covers it in Annex A 5.19 to 5.23, up to the use of cloud services.

Step 2Inventory
Customer portalWeb serverDatabaseCloud hostLogsCustomersContractsBackup
  • Service
  • System
  • Data
  • Supplier

Sample values

How to go about it

  1. 01

    Start with the suppliers in your inventory.

  2. 02

    Rate them by criticality for your services.

  3. 03

    Write security requirements and incident reporting into contracts.

  4. 04

    Review critical suppliers regularly: questionnaires, evidence, certificates.

Common mistakes

  • All suppliers are treated the same.
  • Contracts contain no duty to report incidents.
  • The review happens once and never again.

What an auditor wants to see

  • Supplier register with criticality
  • Assessments with review dates
  • Contract clauses on security and incident reporting

How UniqSuite helps

The supplier check in UniqSuite records criticality, the controls in place and missing, and the review cycle for each supplier.

References

  • Section 30(2) No. 4 BSIG
  • ISO/IEC 27001, Annex A 5.19 to 5.23

Frequently asked questions

Is a supplier’s ISO certificate enough?

It is good evidence if its scope covers the service you buy. Check the scope of the certificate.

Do we have to review every supplier?

Graded by criticality: critical ones thoroughly, non-critical ones with little effort.

What belongs in the contract?

At least security requirements, a duty to report incidents without undue delay, a right to audit or access to audit reports, and rules for subcontractors. Implementing Regulation (EU) 2024/2690 lists these points explicitly for the digital services it covers.

Does NIS2 apply to our suppliers too?

Directly only if they are in scope themselves. Your requirements reach them anyway: through your contracts and your assessment under Section 30(2) No. 4 BSIG.

How often do we review critical suppliers?

Regularly and whenever the service changes. ISO 27001 Annex A 5.22 provides for supplier services to be monitored and reviewed, and for changes to be managed.

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.