Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 22 of 29

Step 4: Review contractual clauses

If the contract with your supplier does not address the ability to assess during the contract term (or to understand the cyber security position of the sub-contractors), you need to understand what can be achieved on a ‘best endeavours’ basis until this can be contractually binding. Following this, the subsequent steps are the same as the last two described in Stage 3 Apply the approach to new supplier relationships.


Published

Reviewed

Version

1.0