If the contract with your supplier does not address the ability to assess during the contract term (or to understand the cyber security position of the sub-contractors), you need to understand what can be achieved on a ‘best endeavours’ basis until this can be contractually binding. Following this, the subsequent steps are the same as the last two described in Stage 3 Apply the approach to new supplier relationships.