Supplier Security Management Policy
Risk assessment, contractual requirements, monitoring and supply chain audits
1. Scope and Purpose
This policy covers all suppliers, subcontractors and external partners with access to the organisation's systems, data or locations. Particular attention is paid to suppliers of critical services (ICT, cloud, telecommunications, OT).
⚠️
Art. 21(2)(d) NIS2: Essential and important entities must manage supply chain security, including assessment of vulnerabilities and security practices of suppliers. An incident at an ICT supplier may trigger a CSIRT reporting obligation.
2. Supplier Classification
| Category | Description | Examples | Control level |
|---|---|---|---|
| Critical | Direct access to key systems or secret data | Cloud provider, telecom operator, SCADA supplier, IT outsourcing | Full security assessment + annual audit |
| Important | Access to internal systems or confidential data | IT service companies, software suppliers, courier companies with office access | Security questionnaire + contract review |
| Standard | No access to IT systems / limited office access | Office supplies suppliers, air-conditioning service | Standard contractual terms |
3. Supplier Security Assessment Process (before signing contract)
- Supplier classification (Critical / Important / Standard).
- Security questionnaire – sent to supplier (template: Annex A).
- Response evaluation – CISO assesses supplier's security maturity level.
- Certificate verification – e.g. ISO 27001, SOC 2, CSA STAR.
- Decision – approve / reject / conditional approval (with required remediation actions).
⚠ Critical – supplier register
Critical supplier register: ▸ [register location]
Number of critical suppliers: ▸ [number]
| Supplier name | Service | Category | Assessment date | Next assessment date | Status |
|---|---|---|---|---|---|
| ▸ | ▸ | ▸ Critical | ▸ | ▸max. 12 months | ▸ |
| ▸ | ▸ | ▸ | ▸ | ▸ | ▸ |
4. Required Contractual Clauses
Every contract with a supplier having access to the organisation's systems or data must contain:
| Clause | Mandatory for | Minimum content |
|---|---|---|
| Confidentiality (NDA) | All | Prohibition on disclosing confidential information, contractual penalties |
| Security requirements | Important and Critical | Obligation to apply security measures compliant with NIS2, right to audit |
| Incident reporting | Critical | Supplier reports incidents affecting the organisation within ▸ [24h]max. 24h |
| Subprocessing | Important and Critical | Prohibition on subprocessing without organisation's consent; same security requirements for subcontractors |
| Right to audit | Critical | Organisation's right to audit supplier's security ▸ [once a year] |
| SLA and penalties | Critical | ▸ [availability, response times, penalties for breaches] |
| Contract termination | All | Return or destruction of data, revocation of access within ▸ [24h from termination] |
5. Supplier Monitoring
| Activity | Frequency | Responsible |
|---|---|---|
| Security review of critical suppliers | ▸ every 12 monthsmin. 1×/year | ▸ CISO |
| Security audit at supplier (on-site or remote) | ▸ every 2 years (critical)min. every 3 years | ▸ CISO / Auditor |
| Monitoring supplier access to systems | Continuous | ▸ IT Admin / SIEM |
| Certificate verification (ISO 27001, SOC2) | ▸ at supplier certificate renewal | ▸ CISO |
Annex A – Supplier Security Questionnaire (excerpt)
Sent to new Important and Critical category suppliers before contract signing.
| # | Question | Expected answer |
|---|---|---|
| 1 | Does the organisation hold ISO 27001 or SOC 2 certification? | ▸ [supplier's answer + verification] |
| 2 | Is encryption of data at rest and in transit applied? | ▸ |
| 3 | What is the security incident response time (SLA)? | ▸ |
| 4 | Are penetration tests conducted? How often? | ▸ |
| 5 | Is there a procedure for reporting incidents to customers? | ▸ |
| 6 | Is the organisation's data stored in the EU / EEA? | ▸ [GDPR requirement] |
Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ | ▸ | ▸ Initial release | ▸ Board |
DOC-015 Supplier Management Policy | v1.0 | NIS2/ISMS