Why suppliers matter
Many incidents start at a supplier: a compromised IT provider, a SaaS tool that leaks data or a software update that carries malware, known as a supply chain attack. A company's security is only as strong as the providers that can reach its systems and data.
The TPRM process
It starts with an inventory of suppliers, classified by how critical they are and what data they handle. Critical suppliers are assessed before contracting, through security questionnaires, certifications such as ISO 27001 or SOC 2 reports, and contract clauses on security, incident notification and audit rights. The relationship is then reviewed periodically, and access is removed when it ends.
What regulations require
NIS2 lists supply chain security among its mandatory risk management measures. DORA goes further for financial entities, with a register of information covering all ICT contracts and specific contract requirements, explained in the five pillars of DORA. ISO 27001 covers supplier relationships in Annex A 5.19 to 5.23.
The other side of the table
For suppliers, TPRM means answering more security questionnaires from customers. A recognised certification and a well organised set of evidence make those reviews faster and help close deals.




