
The practice of assessing and monitoring the cyber security of third parties, so that risk introduced through the supply chain is understood and managed.
Supplier assurance is how an organisation gains confidence that the third parties it depends on are managing cyber security adequately. It covers assessing suppliers before contract, monitoring them during the relationship, and acting when their security position changes.
It is also referred to as third-party risk management, or TPRM. The underlying problem is straightforward: an organisation can be compromised through a supplier’s weaknesses as easily as its own, and its internal controls stop at the contract boundary.
Done well, it is proportionate and continuous. Done badly, it becomes an annual questionnaire exercise that consumes effort without materially reducing risk.
A questionnaire answered at onboarding describes the supplier on the day they completed it. Staff, systems, subcontractors, certifications and ownership all change, sometimes significantly, well before the next annual review comes round.
Continuous approaches re-check key signals during the relationship — certification status, externally observable posture, breach disclosures and material changes — so that the assurance position reflects the supplier as they are now, not as they were at onboarding.
Supply chain security appears explicitly in the NCSC Cyber Assessment Framework as principle A4, and supply chain expectations run throughout UK government procurement. Departments completing GovAssure need supplier evidence to assess systems their suppliers operate or support.
Data protection law adds separate obligations where a supplier processes personal data, requiring appropriate technical and organisational measures and written terms governing that processing.