Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 1 of 29

iStock.com/elenabs

This guidance describes practical steps to help organisations better assess cyber security in their supply chains. It’s aimed at medium to large organisations who need to gain confidence or assurance that mitigations are in place for vulnerabilities associated with working with suppliers.

More specifically, this guidance:

  • describes typical supplier relationships, and ways that organisations are exposed to vulnerabilities and cyber attacks via the supply chain
  • defines expected outcomes and key steps to help you assess your supply chain’s approach to cyber security
  • answers common questions you may encounter as you work through the guidance
  • supplements the NCSC’s Supply Chain Principles (published in 2020) which is referenced throughout

Note:

For guidance about how to implement cyber security with your own organisation, please refer to the NCSC’s 10 Steps to Cyber Security guidance. Smaller organisations should refer to our Cyber Action Toolkit. 


Cross Market Operational Resilience Group logoThis guidance was created in conjunction with the cross market operational resilience group (cmorg) which supports the improvement of the operational resilience of the financial sector through public-private collective action.


Published

Reviewed

Version

1.0