Supplier assurance: having confidence in your suppliers

| This content was last reviewed on 05/03/2025 |
This blog post outlines some of the thinking which has gone into our Supplier Assurance Questions, a set of basic cyber security questions which will help you to understand how much confidence you can have in the security of your suppliers.
While the questions we’ve developed can be used by any organisation, they’re likely to be most useful for SMEs new to supplier assurance, providing a guide on areas to consider when taking on a new supplier.
We recommend that the questions are used by your IT team, working together with your business, procurement, and cyber security teams.
What counts as ‘supply chain’?
Most organisations rely upon suppliers to deliver products, systems, and services. It's how we do business. But supply chains can be large and complex, involving many contractors and sub-contractors, all doing different things. This makes them difficult to secure effectively.
Despite the challenge, it’s essential to secure your supply chain. A vulnerable supply chain can cause damage and disruption to your business. One thing you can’t outsource is accountability for your security to your suppliers. You remain the overall risk owner for your IT systems and information assets.
The supply chain can manifest itself in different ways: for example, through procurement, integration between technologies, third party or open source code, or training data for AI systems.
All these aspects can potentially harbour vulnerabilities that need to be considered and risks that must be mitigated.
Suppliers may be small start-ups with little resource or budget for cyber security, but they could still be a critical node in the supply chain of your product or system.
How much confidence do you need?
Determining whether your supply chain meets your cyber security requirements can be difficult. But there is a process you can follow, which can make things easier.
First, you need to understand what your supply chain looks like. Then you have to work out the relative criticality of each supplier to your business and what risk they pose, were they to exploit vulnerabilities in your defences (accidentally or deliberately) or suffer exploits themselves.
Then you need to work out what would count as proportionate security requirements.
The NCSC supplier assurance questionnaire
Having decided what your suppliers ‘should’ do, you then have the task of finding a suitable means to assess whether what they actually have done meets your requirements, and whether this will continue to be so during the lifetime of the contract.
The logical thing to do is to talk to your suppliers to try to understand their security measures.
To help with this process, we’ve developed a set of basic cyber-security questions which can guide this discussion, so that you end up with structured and useful information about your suppliers’ cyber security.
Note, this is not a check list. A box ticking approach often leads to a false sense of cyber security.
Using the questions
The questions cover themes which you should consider when procuring a supplier, along with some sample questions for each topic. There are also links to relevant guidance. These questions supplement our 12 Supply chain security principles.
When thinking about the questions, you may find some sections more relevant than others, depending on the product or service a supplier is providing to you. In this case, you should tailor the questions to your organisation’s specific needs.
Evaluating the responses
Once you have a set of responses from the supplier, you will need to assess the level of evidence you need to support the answers. This will depend on the supplier’s criticality and the associated risk to your organisation.
This risk can depend on factors such as:
- whether the supplier has any direct or indirect connectivity to your IT
- whether they are a critical single point of failure – for example, if they provide a unique service or product to you, or if it would be hard to find a replacement in short order
- the amount and/or sensitivity of your data which they process, transmit or store
- the extent to which they can impact your critical business functions, such as Mission Delivery, Production, HR, Site, Finance, IT
- whether there are likely to be strict information and/or service availability requirements
- the supplier’s strategic importance to your organisation.
Bear in mind that the risk profile of a supplier relationship can change over time, for example when:
- the volume of data being processed by the supplier increases significantly
- new technology is implemented (such as mobile access platforms)
- different types of data are introduced (such as personal data or commercially sensitive information)
- the organisation’s wider threat profile alters
When the underlying risk profile of the supplier relationship changes, cyber security arrangements should be reviewed.
So, although asking a supplier these questions can be useful in understanding their security posture, the assurance and evidence obtained will represent a point in time. This means you will need to consider how to keep the responses (and any evidence) up to date.
Asking and completing questions about security can be resource-intensive, for suppliers and for the procuring organisation. Often, suppliers will be asked about the same areas of security in slightly different ways by different organisations, so it’s important that the assurance sought is pragmatic and proportionate to the risk they present to your organisation.


