The pattern is familiar because it is everywhere. Procurement runs a security questionnaire before signature, security gives an opinion, the contract is signed, and the vendor disappears from view. Two years later the same vendor holds more data, more access and more of your process than anyone decided on purpose. ENISA measured supply-chain attacks growing 38% in its 2024 Threat Landscape; the attacker has noticed what the register has not.
The texts have caught up with the pattern. NIS2 Article 21(2)(d) lists supply-chain security among the mandatory risk-management measures, explicitly including the security aspects of the relationships between an entity and its direct suppliers. DORA Article 28 requires financial entities to keep a register of information on all their ICT third-party arrangements, current and producible on request, and its oversight logic assumes continuous assessment cycles rather than a one-off questionnaire. The common point is simple: the risk you inherit from suppliers is your risk, and someone in your organisation signs it off.
Meeting that expectation takes a workflow that continues after signature:
The zones make the state legible at a glance: trust means assessed and within appetite with periodic review, watch means enhanced due diligence and follow-up, danger means immediate remediation or escalation.
Onboarding is where supplier risk management starts. Regulators, and attackers, are interested in everything that happens after.
In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.