Supply Chain Security Assessment
SolarWinds, MOVEit, 3CX, XZ Utils — every major incident of the past five years has reached the victim through a trusted third party. We assess your supplier risk end-to-end: software composition, vendor security posture, contractual obligations, and the realistic attack paths an adversary would take through your supply chain.
The Regulatory Picture: NIS2, DORA, CRA, NIST
Supply chain security used to be a discretionary control. It isn't any more. NIS2 Article 21(2)(d) mandates supply chain security for any essential or important entity operating in the EU. DORA Chapter V requires financial entities to manage ICT third-party risk with contract obligations, register-keeping and resilience testing of critical providers. The forthcoming UK Cyber Security and Resilience Bill and the EU Cyber Resilience Act extend obligations to suppliers themselves. Regulators are starting to fine — and to require evidence.
A CDSEC supply chain assessment produces evidence in the form regulators recognise: a documented methodology, mapped findings, evidence of corrective action requested from suppliers, and a tracker for residual risk acceptance. It also identifies the genuine attack paths a determined adversary would take — the part procurement-led questionnaires miss.
The Five Layers We Assess
1. Software Bill of Materials (SBOM)
Generate or audit an SBOM in CycloneDX or SPDX format. Identify direct and transitive dependencies with known CVEs, unmaintained packages, packages with single-maintainer risk (the XZ Utils pattern), and components published from high-risk jurisdictions or compromised maintainer accounts.
2. Dependency Confusion & Typosquats
We test whether your internal package names are claimable on public registries (npm, PyPI, NuGet, Maven Central, RubyGems, Crates.io) — the dependency confusion attack that hit dozens of large enterprises in 2021 and continues to land. We also check for typosquatted variants of your dependencies in your lock files.
3. Vendor Security Posture
External attack surface scan of named critical suppliers, validation of their security questionnaire answers against observable reality (DMARC, TLS posture, exposed admin interfaces, breach history, dark web mentions of corporate credentials), and a comparative scoring against peers.
4. Integration & Access
For each critical supplier we map the integration: VPN access, SaaS-to-SaaS OAuth grants, API keys, federated identity, scheduled file transfers, RMM tooling. Each connection is rated for blast radius if the supplier itself is compromised — the question MOVEit raised for everyone using it.
5. Contractual & Governance Review
Review of cyber clauses in supplier contracts against your regulatory baseline: breach notification windows, right-to-audit, sub-processor disclosure, security control attestations, exit-and-data-portability obligations. Most enterprise contracts have weak or absent provisions on at least three of these.
Engagement Output
- Supplier risk register — every critical supplier ranked by inherent risk, residual risk, blast radius and observable security posture.
- SBOM with vulnerability annotations — exportable CycloneDX file ready to feed into your vulnerability management process.
- Dependency confusion claim list — internal package names you should defensively register on public registries today.
- Contract gap analysis — clause-by-clause review of supplier agreements against NIS2 / DORA / your internal baseline.
- Remediation playbook — sequenced actions, owners, and target dates, ready to drop into your GRC tooling.
- Regulator-ready evidence pack — methodology, findings register, supplier correspondence, and corrective action evidence.
Frameworks & Standards
- NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management Practices.
- ISO/IEC 27036 — Information security for supplier relationships.
- ISO/IEC 28000 — Security management for the supply chain.
- NIS2 Directive — Article 21 supply chain security obligations.
- DORA — ICT third-party risk register, contract obligations, oversight framework.
- UK Government Cyber Assessment Framework (CAF) — Principle B4 supply chain.
When to Run a Supply Chain Assessment
Whenever the regulator expects evidence and you don't currently have it. Whenever you onboard a new critical supplier. After any supplier-side incident, even if not yours. Before a material acquisition, where you inherit the acquired company's supplier estate. And annually for any organisation subject to NIS2 or DORA — those obligations don't sit still.
Related Services
- Compliance Auditing — ISO 27001, SOC 2 and Cyber Essentials Plus assessments.
- Threat-Led Penetration Testing — including supply chain attack scenarios for TIBER-EU / CBEST engagements.
- Red Team Exercises — adversary emulation that includes supplier compromise as a viable entry vector.
- All Penetration Testing Services — the full CDSEC service catalogue.
Get Ahead of Supply Chain Regulation
Most assessments scope within 24 hours of an initial call. Send a rough supplier count and your regulatory baseline (NIS2 essential, DORA, neither) and we'll come back with a structured proposal.
Request a ProposalGet In Touch
Ready to secure your business? Contact our team of certified experts today for a consultation.
Contact Us
Get in touch for questions about our services
Phone
+44131 460 4180
Speak directly with our security experts
Our Global Offices
Local expertise with global reach across three continents