The number that tells you nothing
Ask a risk function how many suppliers it assessed last year and you will get an exact figure. Ask which one of them could, on its own, stop invoicing for three days, and the answer takes a while to arrive.
That is the structural flaw of the discipline: it measures itself by response rate. Ninety-two per cent returns on the annual campaign presents beautifully to a board committee and teaches nobody anything, because the figure aggregates unverified declarations about suppliers whose criticality was never differentiated. Two full-time people, a real budget, and the three scenarios capable of stopping the business remain untouched.
Where NIS2 and DORA stop being optional
NIS2 covers supply-chain security in Article 21(2)(d): risk-management measures must extend to relationships with direct suppliers and service providers, taking account of each one's vulnerabilities and the quality of its practices. The real leverage sits elsewhere, in Article 20, which places approval and oversight of those measures with the management body and makes it liable. Supplier risk stops being a security-team topic the day a director signs for it.
DORA (Regulation (EU) 2022/2554) goes considerably further for financial entities and serves as a reference for everyone else: a register of information covering every contractual arrangement for ICT services, collected by the competent authorities and detailed enough to force documentation of the subcontracting behind critical functions; mandatory contractual provisions; a concentration-risk assessment and a written exit strategy. Plus direct oversight by the European Supervisory Authorities of ICT providers designated as critical — the first time a hyperscaler answers to a European supervisor rather than to its customers alone.
That register has a side effect teams discover while filling it in: it makes visible what nobody had mapped, and the subcontractor field is the one that hurts.
A questionnaire proves nothing unless you treat it as evidence
The self-declared questionnaire, returned as a spreadsheet, read by nobody, filed on a shared drive, is worthless. It produces an audit trail, not knowledge. The supplier ticks whatever gets it through, and it is right to: nothing in the process distinguishes an accurate answer from a convenient one.
Three requirements turn the exercise around. Attach evidence to the questions that matter, and only to those — "do you have an access management policy?" tells you something only when it arrives with the policy and a dated extract from an access review. Sample: eight verified answers beat a hundred read ones, provided you pick the ones your feared scenario depends on and draw elsewhere the following year. Read attestations instead of collecting them — there are plenty of perfectly valid ISO/IEC 27001 certificates whose scope covers a head office and a data centre that host nothing of the service you bought, and in a SOC 2 Type II report the two useful sections are the exceptions and the complementary user entity controls, meaning what the report assumes you are doing at your end.
The SIG from Shared Assessments, the Cloud Security Alliance's CAIQ and ISO/IEC 27036 save you from reinventing the question set. They are instruments; none of them decides what depth to apply to whom, and that decision is what makes a programme.
The risk isn't at onboarding
Almost every programme assesses at onboarding and never again. That is the inverse of where risk actually sits. At onboarding the supplier is engaged, procurement is paying attention, the contract is open. Conditions will never be that favourable again.
What follows escapes scrutiny entirely. Scope drifts — a tool bought for web analytics is processing HR data eighteen months later because a team found the integration convenient. A fund buys the supplier, support moves to a country that was never in the contract. A subcontractor is swapped without notice. The contract auto-renews on a Sunday.
The answer is not to assess more often but to replace the snapshot with signals: certification expiry, contractual incident notifications, a change of subcontractor, a published vulnerability in an exposed component, financial deterioration — a company in trouble cuts first where nothing is billed. External rating services have exactly one legitimate use: triggering a question. A trigger beats a calendar.
Concentration, the blind spot in every register
A well-kept register lists twenty providers behind one critical process and gives a comforting impression of spread dependency. Resolve each of them down to where it actually runs and all twenty sit in the same region of the same cloud provider. The redundancy was contractual, not technical.
Concentration never shows up on a row of the register. It appears in the column nobody created. The same identity provider. The same transactional email service, the one whose outage takes down your customer notifications and your password resets in the same minute. The same fourth-tier subcontractor behind three vendors who believe they compete. In smaller organisations, the same person: the one administrator who understands the architecture.
Run the analysis by function lost, not by supplier. Take a process you cannot stop, list everything holding it up, resolve each item down to hosting, critical subcontractors and country of operation, then look for the value that repeats. DORA requires this in Article 29; outside finance almost nobody does it, even though it is the cheapest analysis of the lot.
The audit right nobody exercises
The audit clause is fought over hard, appears in nearly every critical contract, and is never invoked. On the programmes we take over, "when did you last exercise this right?" usually goes unanswered. A clause you do not exercise is not a control, it is a line in a contract.
Two honest options. Exercise it, once a year, on a tier 1 supplier picked by rotation, with a narrow and announced scope: privileged access review, evidence of the last restore test, three months of change logs. A single remote day teaches you more than a two-hundred-line questionnaire. Or replace it with rights you will actually use — audit report and remediation plan by a fixed date, the right to test your own tenant under rules of engagement agreed in advance, pooled audits where the supplier refuses individual visits.
The lesson comes free either way: how a supplier receives a scoped audit request tells you a great deal before the audit starts.
Match depth to criticality
A tier is not a property of the supplier, it is a property of the use. The same vendor sits in tier 3 for a meeting-room booking tool and in tier 1 for the component that authenticates your staff. Classifying by legal entity is what derails most dashboards.
| Tier | What puts a supplier there | Depth | Rhythm |
|---|---|---|---|
| 1 — critical | Process stops within 24 h, privileged access to production, sensitive data at volume | Audit or deep documentary review, evidence of restore tests, penetration test results, subcontracting mapped, exit plan tested | Continuous signals, annual reassessment, reopened on any change |
| 2 — important | Sensitive data or system interconnection; process degraded, not stopped | Questionnaire with evidence on a sample, certification scope actually read, clauses verified | Every 18 to 24 months, and on any change |
| 3 — standard | Limited data, no interconnection | Short questionnaire, attestations, contractual baseline | At renewal |
| 4 — incidental | No data, no access | Register entry | No dedicated campaign |
The allocation rule is blunt, which is exactly what makes it work: tiers 1 and 2 absorb most of the assessment budget. A programme that treats three hundred suppliers with equal diligence handles none of the eight that matter properly.
Clauses you can actually enforce
A security clause you cannot measure reassures only the committee that approved it. What makes it enforceable: a defined trigger, a stated deadline, a named recipient, a consequence.
"Without undue delay" is not enforceable. Write twenty-four hours from detection, to a named address, with an obligation to notify even when the impact on your data is not yet established: that last part is what prevents three weeks of silence while the supplier qualifies the event. On subcontracting, no blanket consent, but prior notice and a right to object within thirty days for critical functions. On security level, reference a named baseline — CIS Benchmarks, ISO/IEC 27002, your own technical annex — rather than "state of the art", which can be argued either way.
All of this is negotiated before signature, or not at all. Security requirements belong in the tender pack; a CISO who first sees the contract afterwards has no leverage left.
Write the exit before you sign
The most neglected phase of the life cycle is the last one. Contracts end; access survives. Months after an engagement finishes you still find the application assigned in the identity directory, API keys that still work, the supplier's consultants sitting in the guest directory of your collaboration suite, data in their backups well past the stated retention period. Nothing was ever wired between the end of a contract and the revocation of rights. The fix is cheap — a named procedure, an owner, a deadline, evidence — but it is operations rather than strategy, and operations never gets prioritised.
The exit plan itself is written before signature, while you still have something to trade. Four questions: in what format and how quickly you get your data back, who holds the encryption keys, how long a transition the supplier commits to, and whether a fallback has already been qualified. An export you have never tested is not an exit plan. Test it once, while the relationship is good — the only time the supplier will help you do it.
Ninety days to a programme that works
An order of march that holds when everything is still to build:
- Build the register from the accounts payable ledger and the application list in your identity directory, never from a self-declared survey: spend and logins reveal the providers nobody declares.
- Tier by use. Two criteria are enough to start: impact of an outage, sensitivity of the data reachable.
- Test tier 1 and tier 2 contracts against the clauses above and order the gaps by renewal date. The next renewal is your renegotiation window.
- Map tier 1 subcontracting down to the level that actually holds the data.
- Exercise an audit right, once. The programme changes character that day.
- Wire offboarding into the contract-termination process.
None of this needs a tool. The tool becomes necessary afterwards, to hold campaigns, evidence, scores and contractual deadlines for two hundred suppliers without losing them in spreadsheets.
What we bring
At Wavatec we approach third-party risk through the ecosystem rather than the list. Workshop 3 of EBIOS RM, which rates stakeholders on their exposure and their cyber reliability, produces a tier justified by risk analysis and an argument a management body can genuinely approve — which is what NIS2 now asks of it. We then verify what needs verifying: penetration testing against a provider's exposed interfaces, configuration review against the CIS Benchmarks, a critical reading of attestations. Elyys360, the GRC platform we publish, carries the long run: campaigns, evidence, tiered scoring, clause and deadline tracking.
The programme that holds is not the one that assesses the most suppliers. It is the one that knows, at any moment, which of them can stop it, and what it will do the day one of them goes down.
