> For the complete documentation index, see [llms.txt](https://guidance.ctag.org.uk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guidance.ctag.org.uk/supply-chain-security-july-2026.md).

# Supply Chain Security             July 2026

Approach to Third Party (Supply Chain) Risks, their Identification and mitigation derived from UK Public Sector fieldwork.

&#x20;

The **Integrated Supply Chain Security and Assurance Framework** structures supply chain risk into several core pillars, moving from evidence-based threat profiling to legal procurement controls and maturity tracking.                &#x20;

1\.     **Strategic Foundation and Threat Profiling** The framework is built on an evidence-based approach that mandates analysing historical supplier data breaches and attacks to inform dynamic threat profiles. These threat profiles prioritise public internet-facing services, which carry the highest risk of compromise. It identifies Identity and Access Management (IAM) exposure, Shared Responsibility Mapping (SRM) across cloud and on-premises deployment, and broader geopolitical risks. The  SRM is a key component as client organisations must fully understand where the supplier responsibility ends and their consumer responsibility starts. This is critical for good governance and data protection.  Table 4 summarises these risks.

&#x20;

&#x20;**Approach to Supply Chain Mapping**

| Threat Profile Priority                       | Description & Focus Area                                                                                                                                              |
| --------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Public Internet-Facing Services               | Identifies and profiles suppliers with services exposed to the public web, treating them as high-priority risk vectors.                                               |
| Identity and Access Management (IAM) Exposure | Analyses the risks associated with service-to-service authentication and human administrative access within the supply chain.                                         |
| Shared Responsibility Mapping                 | Distinguishes and clarifies risk ownership across different deployment scenarios, including on-premises, Software as a Service (SaaS), and cloud-native environments. |
| Geopolitical Risks                            | Factors broader political and economic stability contexts into the overall supplier risk scoring. This includes where data is processed & stored.                     |

Key software service Threat profiles and  Risks (Source: Author).

## &#x20;**Centralised Supplier Repository / Information Asset Register**&#x20;

A dynamic, relational **Central Supplier Catalogue** serves as the primary resilience tool, accommodating both standardised data and free-text fields. The catalogue/register is the absolute core of any supply chain security programme of work. The real power of this approach, comes when the community / eco-systems share them. Within a Local Authority in the UK, there could be upwards of 750 systems and services. This is highly complex and generates a mountain or lake of data. Where Councils share he same supplier, knowing which other Councils share that supplier and having a detailed inventory of that suppliers’ components, and versions can really help during an incident, immediately alerting who would be affected by an exploit. This is key to the “Defend as One” Programme of work. \[67] Table 5, provides an information asset template . This can be formatted as XML or other metadata to allow easy electronic sharing. The version number will ensure consistent mapping of any version changes I the structure. This template could become a standard for use within UK Local Government, this would facilitate information sharing and Cyber Incident Response. Th version number included to reflect this is the initial version 1.0 suggestion as of July 2026. There will need to be an accessible repository for the standard, such as the CTAG Guidance repository&#x20;

&#x20;

Information Asset Register (IAR) Template (Version 1.0 July 2026)

| Field Category           | Field Name                                                                        | Description                                                                                                                                                                                                                                                                    |
| ------------------------ | --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Framework Mandated       | Date entry created                                                                | The date the Asset record was created.                                                                                                                                                                                                                                         |
| Framework Mandated       | Date entry updated / reviewed                                                     | The Asset Record must be reviewed at least annually.                                                                                                                                                                                                                           |
| Framework Mandated       | Unique Supplier ID (Unique Key)                                                   | A unique identifier that programmatically links the information asset to the Central Supplier Catalogue.                                                                                                                                                                       |
| Framework Mandated       | Processing / Hosting Supplier                                                     | Explicitly identifies the third-party supplier that is responsible for processing, managing, or hosting the information asset.                                                                                                                                                 |
| Framework Mandated       | Product / Service version number                                                  | This is the product / service version number (Patch level).                                                                                                                                                                                                                    |
| Framework Mandated       | Suppler Assertion Verification                                                    | Indicates whether the asset has been verified using automated discovery tools to validate the supplier's claims. Or that a CAF or similar audit exists                                                                                                                         |
| Framework Mandated       | Supplier Cyber Essentials / Plus – or ISO 27001 etc. status recorded and verified | <p>Record and verify the asserted security certifications  held by the supplier. </p><p>(Review annually during contract)</p>                                                                                                                                                  |
| Framework Mandated       | DPIA Status                                                                       | Tracks whether a standardised Data Protection Impact Assessment (DPIA) has been completed for the asset, particularly regarding supply chain changes. Whilst only mandated for complex systems, this is a very robust way to assure personal data, being processed and stored. |
| *Standard Best Practice* | *Asset ID / Reference Number*                                                     | *A unique internal alphanumeric identifier assigned to the specific asset.*                                                                                                                                                                                                    |
| *Standard Best Practice* | *Asset Name & Description*                                                        | *A clear title and brief summary of what the information asset is and its business purpose (e.g., "Customer Payment Gateway").*                                                                                                                                                |
| *Standard Best Practice* | *Information Asset Owner (IAO)*                                                   | *The internal role, department, or individual who is ultimately accountable for the asset's security and lifecycle. A named individual is best, by default it will be the service owner.*                                                                                      |
| *Standard Best Practice* | *Data Classification*                                                             | *The sensitivity level of the data contained in the asset (e.g., Public, OFFICIAL, Internal, Confidential, Restricted).*                                                                                                                                                       |
| *Standard Best Practice* | *Format and Location*                                                             | *Where and how the asset is stored (e.g., AWS Cloud, On-Premises Server, Physical Records).*                                                                                                                                                                                   |
| *Standard Best Practice* | *Business Criticality (CIA)*                                                      | *An assessment of the impact on the business if the asset's Confidentiality, Integrity, or Availability is compromised.*                                                                                                                                                       |
| *Standard Best Practice* | *Modelling harm*                                                                  | *Understand the harm caused in the event of a data breach, to an individual, community or other group, includes, physical, financial, reputational. This can align with the UK Data Classification Guidelines.*                                                                |
| *Standard Best Practice* | *Retention Period & Disposal*                                                     | *The required legal or operational lifespan of the data and the approved method for secure disposal at the end of its lifecycle. Remember data isn’t gone until the last backup is deprecated.*                                                                                |

&#x20;Information Asset Register Template (Source: Author)

&#x20;

Suppliers must actively maintain standardised assertions \[63]  regarding their patching status, encryption protocols, compliance certificates, and product liability. To ensure transparency, suppliers are also required to have a formal **Vulnerability Disclosure Policy (VDP)**  so the organization is alerted to critical bugs before exploitation.\[65] There are a number of commercial tools available that do this.

**Technical Architecture and Asset Management**&#x20;

Scalable, real-time assurance is achieved through an **API-driven architecture** where either the organisation pulls data from supplier endpoints, or suppliers push updates to a central API. The architecture also explores using **blockchain** for non-repudiation, utilizing immutable timestamps to prevent suppliers from backdating compliance evidence after an incident.

Furthermore, an **Information Asset Register (IAR)** must be programmatically linked to the supplier catalogue using a Unique Supplier ID. An integrated Assurance Toolkit leverages open-source automated discovery tools to verify local network assets against supplier claims, establishing a "ground truth".

**Governance and Compliance Alignment** Policy governance is driven by the **LACES** framework (Local Authority Cyber Eco-System). \[66] Supplier risks—such as IAM exposure and service criticality—are formally tracked in a dedicated Supply Chain Risk Register. To avoid "compliance fatigue," the framework maps requirements to a targeted, risk-proportional subset of the **NCSC Cyber Assessment Framework (CAF)** and **EU NIS/NIS2** regulations. \[63]&#x20;

**Procurement and Legal Integration** Security is embedded into the procurement lifecycle using model contract clauses, rigorous tender questionnaires, and structured dropdown answers to enable automated scoring. Crucially, the framework enforces **Legally Binding Assertions (LBAs)**, which tie a supplier's security claims directly to contractual limits of liability and insurance recourse. \[64]&#x20;

**Maturity Modelling and Implementation** Organisations evaluate their supplier assurance capabilities on a **0-to-5 maturity scale**, progressing from non-existent/reactive checks (0-1) up to full lifecycle automated assurance and predictive risk modelling (5). The framework concludes with a four-phase roadmap for operationalisation, spanning research, tooling development, governance drafting, and alignment with GDS/DCMS architecture standards.

## **References:**

1. Integrating Machine Learning and Business Intelligence into Supply Chain Risk Management for a Comprehensive Cybersecurity Framework: A Systematic Literature Review - MDPI, [https://www.mdpi.com/2227-7080/14/4/194](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mdpi.com%2F2227-7080%2F14%2F4%2F194)
2. Third-Party Risk Management: Ensuring Vendor and Partner Compliance with Data Protection Laws - ResearchGate, [https://www.researchgate.net/publication/395476764\_Third-Party\_Risk\_Management\_Ensuring\_Vendor\_and\_Partner\_Compliance\_with\_Data\_Protection\_Laws](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F395476764_Third-Party_Risk_Management_Ensuring_Vendor_and_Partner_Compliance_with_Data_Protection_Laws)
3. Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports, [https://www.researchgate.net/publication/351567274\_Cyber\_Third-Party\_Risk\_Management\_A\_Comparison\_of\_Non-Intrusive\_Risk\_Scoring\_Reports](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F351567274_Cyber_Third-Party_Risk_Management_A_Comparison_of_Non-Intrusive_Risk_Scoring_Reports)
4. Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports - Scholars Archive, [https://scholarsarchive.library.albany.edu/cgi/viewcontent.cgi?article=1002\&context=ehc\_fac\_scholar](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fscholarsarchive.library.albany.edu%2Fcgi%2Fviewcontent.cgi%3Farticle%3D1002%26context%3Dehc_fac_scholar)
5. The development of supply chain management cybersecurity risks: What past incidents - Iowa State University, [https://dr.lib.iastate.edu/bitstreams/bbbea3cc-d43d-4b13-ab44-51c2e7a78eb8/download](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdr.lib.iastate.edu%2Fbitstreams%2Fbbbea3cc-d43d-4b13-ab44-51c2e7a78eb8%2Fdownload)
6. Deciphering the Supply Chain Chessboard: The Science of Decision-Making in Risk Management - CyberRisk Alliance, [https://www.cyberriskalliance.com/blog/deciphering-the-supply-chain-chessboard-the-science-of-decision-making-in-risk-management](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.cyberriskalliance.com%2Fblog%2Fdeciphering-the-supply-chain-chessboard-the-science-of-decision-making-in-risk-management)
7. Supply chain cybersecurity & compliance - Star | Global, [https://star.global/posts/supply-chain-cybersecurity-compliance/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fstar.global%2Fposts%2Fsupply-chain-cybersecurity-compliance%2F)
8. NIST 800-161: Cybersecurity Supply Chain Risk Management Steps - ComplianceForge, [https://complianceforge.com/compliance/nist-800-161-compliance](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fcomplianceforge.com%2Fcompliance%2Fnist-800-161-compliance)
9. Third-Party Risk Statistics 2026: Vendor & Supply Chain Risk - DeepStrike, [https://deepstrike.io/blog/third-party-risk-statistics](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdeepstrike.io%2Fblog%2Fthird-party-risk-statistics)
10. Supply Chain Risk Management: A Strategic Guide for Modern Resilience - Panorays, [https://panorays.com/blog/supply-chain-risk-management-strategies/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpanorays.com%2Fblog%2Fsupply-chain-risk-management-strategies%2F)
11. Third-Party Risk Management in Cybersecurity Reference | Advanced Security Authority, [https://advancedsecurityauthority.com/third-party-risk-management-reference/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fadvancedsecurityauthority.com%2Fthird-party-risk-management-reference%2F)
12. What Is Third Party Risk Management? 2025 Complete Guide - Isora GRC, [https://www.saltycloud.com/blog/third-party-risk-management/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.saltycloud.com%2Fblog%2Fthird-party-risk-management%2F)
13. TPRM Maturity Model for Third-Party Risk: Complete Guide \[2026] | Isora GRC, [https://www.saltycloud.com/blog/tprm-maturity-model/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.saltycloud.com%2Fblog%2Ftprm-maturity-model%2F)
14. Third-Party Risk Management Frameworks: The Guide - Mitratech, [https://mitratech.com/resource-hub/blog/third-party-risk-management-frameworks/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmitratech.com%2Fresource-hub%2Fblog%2Fthird-party-risk-management-frameworks%2F)
15. Supply Chain Risk Management: Best Practices - Drata, [https://drata.com/learn/tprm/supply-chain-best-practices](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fdrata.com%2Flearn%2Ftprm%2Fsupply-chain-best-practices)
16. A Multicriteria Decision-Making Approach to Building Resilience Along the Indian Medical Equipment Supply Chain | Request PDF - ResearchGate, [https://www.researchgate.net/publication/389302015\_A\_Multicriteria\_Decision-Making\_Approach\_to\_Building\_Resilience\_Along\_the\_Indian\_Medical\_Equipment\_Supply\_Chain](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F389302015_A_Multicriteria_Decision-Making_Approach_to_Building_Resilience_Along_the_Indian_Medical_Equipment_Supply_Chain)
17. Key Practices in Cyber Supply Chain Risk Management: Observations from Industry - NIST Technical Series Publications, [https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8276.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fnvlpubs.nist.gov%2Fnistpubs%2Fir%2F2021%2FNIST.IR.8276.pdf)
18. The Anatomy of a Good Concept: A Systematic Review on Cyber Supply Chain Risk Management - MDPI, [https://www.mdpi.com/2071-1050/18/3/1151](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.mdpi.com%2F2071-1050%2F18%2F3%2F1151)
19. Conduct an Effective Supply Chain Cybersecurity Risk Assessment - Onspring Technologies, [https://onspring.com/resources/blog/conduct-an-effective-supply-chain-cybersecurity-risk-assessment/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fonspring.com%2Fresources%2Fblog%2Fconduct-an-effective-supply-chain-cybersecurity-risk-assessment%2F)
20. SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties, [https://arxiv.org/html/2406.10109v1](https://www.google.com/url?sa=E\&q=https%3A%2F%2Farxiv.org%2Fhtml%2F2406.10109v1)
21. Defending Against Software Supply Chain Attacks - CISA, [https://www.cisa.gov/sites/default/files/publications/defending\_against\_software\_supply\_chain\_attacks\_508.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.cisa.gov%2Fsites%2Fdefault%2Ffiles%2Fpublications%2Fdefending_against_software_supply_chain_attacks_508.pdf)
22. The Benefits of a Software Bill of Materials Program at Nuclear Facilities - INL Digital Library - Idaho National Laboratory, [https://inldigitallibrary.inl.gov/sites/sti/sti/Sort\_65326.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Finldigitallibrary.inl.gov%2Fsites%2Fsti%2Fsti%2FSort_65326.pdf)
23. Organisation-Level SCF Certifications | SCF CAP Guide, [https://securecontrolsframework.com/scf-certified/organisation-level-scf-certifications](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsecurecontrolsframework.com%2Fscf-certified%2Forganization-level-scf-certifications)
24. A Complete Guide to Third-Party Security Assessment - SPOG, [https://blog.spog.ai/a-complete-guide-to-third-party-security-assessment/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fblog.spog.ai%2Fa-complete-guide-to-third-party-security-assessment%2F)
25. (PDF) Information Security Risk Management Model for Big Data - ResearchGate, [https://www.researchgate.net/publication/362562040\_Information\_Security\_Risk\_Management\_Model\_for\_Big\_Data](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F362562040_Information_Security_Risk_Management_Model_for_Big_Data)
26. Modelling the conundrums to cyber-risks management in logistics firms for supply chain social sustainability - Emerald Publishing, [https://www.emerald.com/jeim/article/37/6/1885/1227695/Modelling-the-conundrums-to-cyber-risks-management](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.emerald.com%2Fjeim%2Farticle%2F37%2F6%2F1885%2F1227695%2FModelling-the-conundrums-to-cyber-risks-management)
27. A Supply Chain Game Theory Framework for Cybersecurity ..., [https://supernet.isenberg.umass.edu/Articles/SupplyChain-Cybersecurity-Investments-Network-Vulnerability.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupernet.isenberg.umass.edu%2FArticles%2FSupplyChain-Cybersecurity-Investments-Network-Vulnerability.pdf)
28. Assured Cyber Supply Chain Provenance Using Permissioned Blockchain, [https://iti.illinois.edu/credc/researchactivity/assured-cyber-supply-chain-provenance-using-permissioned-blockchain](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fiti.illinois.edu%2Fcredc%2Fresearchactivity%2Fassured-cyber-supply-chain-provenance-using-permissioned-blockchain)
29. Managing cyber risk in supply chains: A review and research agenda, [https://researchportal.hw.ac.uk/files/25264894/SCMIJ\_AAP.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fresearchportal.hw.ac.uk%2Ffiles%2F25264894%2FSCMIJ_AAP.pdf)
30. Cyber Risks: Systematic Literature Analysis - International Institute of Informatics and Cybernetics, [https://www.iiisci.org/journal/PDV/sci/pdfs/SA153UQ24.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.iiisci.org%2Fjournal%2FPDV%2Fsci%2Fpdfs%2FZA153UQ24.pdf)
31. Cyber Supply Chain Risk Management: From Threats to Treatment | Scilit, [https://www.scilit.com/publications/e3d0699efee879e39d63eabe9a91a08a](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.scilit.com%2Fpublications%2Fe3d0699efee879e39d63eabe9a91a08a)
32. The relationship between cybersecurity awareness, cybersecurity supply chain risk management and firm performance - Emerald Insight, [https://www.emerald.com/scm/article/30/5/497/1265668/The-relationship-between-cybersecurity-awareness](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.emerald.com%2Fscm%2Farticle%2F30%2F5%2F497%2F1265668%2FThe-relationship-between-cybersecurity-awareness)
33. CyberSecurity Readiness: A Model for SMEs based on the Socio-Technical Perspective, [https://www.researchgate.net/publication/367645669\_CyberSecurity\_Readiness\_A\_Model\_for\_SMEs\_based\_on\_the\_Socio-Technical\_Perspective](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F367645669_CyberSecurity_Readiness_A_Model_for_SMEs_based_on_the_Socio-Technical_Perspective)
34. Full article: A combined Blockchain and sero-knowledge model for healthcare B2B and B2C data sharing - Taylor & Francis, [https://www.tandfonline.com/doi/full/10.1080/25765299.2023.2188701](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.tandfonline.com%2Fdoi%2Ffull%2F10.1080%2F25765299.2023.2188701)
35. The MARISMA- CPS pattern - Essex Research Repository, [https://repository.essex.ac.uk/33036/1/1-s2.0-S0166361522001129-main.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Frepository.essex.ac.uk%2F33036%2F1%2F1-s2.0-S0166361522001129-main.pdf)
36. Evaluation of the Feasibility of Utilising a Low-Cost UWB Radar for Hardware Implant & Counterfeit Device Detection - INFO - Oak Ridge National Laboratory, [https://info.ornl.gov/sites/publications/Files/Pub182146.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Finfo.ornl.gov%2Fsites%2Fpublications%2FFiles%2FPub182146.pdf)
37. Proceedings of the Cyber Supply Chain Risk Management for Critical Systems (CySCRM '24) - Pacific Northwest National Laboratory, [https://www.pnnl.gov/sites/default/files/media/file/Final%20CySCRM%20Proceedings.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.pnnl.gov%2Fsites%2Fdefault%2Ffiles%2Fmedia%2Ffile%2FFinal%2520CySCRM%2520Proceedings.pdf)
38. Cyber Supply Chain Risk Management in the Netherlands ..., [https://essay.utwente.nl/fileshare/file/96796/weiss\_MA\_eemcs.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fessay.utwente.nl%2Ffileshare%2Ffile%2F96796%2Fweiss_MA_eemcs.pdf)
39. DORA: Managing Third-Party Risk in the Supply Chain | Eraneos, [https://www.eraneos.com/articles/the-digital-operational-resilience-act-dora-and-the-management-of-third-party-risks-in-the-supply-chain-part-3/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.eraneos.com%2Farticles%2Fthe-digital-operational-resilience-act-dora-and-the-management-of-third-party-risks-in-the-supply-chain-part-3%2F)
40. Key Strategies for Managing Third-Party Risk Under DORA - Omada, [https://omadaidentity.com/resources/blog/strategies-third-party-risk-dora/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fomadaidentity.com%2Fresources%2Fblog%2Fstrategies-third-party-risk-dora%2F)
41. Digital Operational Resilience Act (DORA) - eiopa - European Union, [https://www.eiopa.europa.eu/digital-operational-resilience-act-dora\_en](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.eiopa.europa.eu%2Fdigital-operational-resilience-act-dora_en)
42. Third-Party Risk Management under DORA | SAP LeanIX, [https://www.leanix.net/en/wiki/trm/third-party-risk-management-under-dora](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.leanix.net%2Fen%2Fwiki%2Ftrm%2Fthird-party-risk-management-under-dora)
43. DORA Third-Party Risk Management Compliance | Prevalent - Mitratech, [https://mitratech.com/resource-hub/rc-use-case/eu-digital-operational-resilience-act-compliance/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fmitratech.com%2Fresource-hub%2Frc-use-case%2Feu-digital-operational-resilience-act-compliance%2F)
44. CMMC 2.0 Compliance Templates - ComplianceForge, [https://complianceforge.com/compliance/cmmc-compliance-dfars-252-204-7021](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fcomplianceforge.com%2Fcompliance%2Fcmmc-compliance-dfars-252-204-7021)
45. BOMs Away! Inside the Minds of Stakeholders:A ... - Oscar Chaparro, [https://ojcchar.github.io/files/27-icse24-sboms.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fojcchar.github.io%2Ffiles%2F27-icse24-sboms.pdf)
46. How to choose mitigation measures for supply chain risks | Request PDF - ResearchGate, [https://www.researchgate.net/publication/265557093\_How\_to\_choose\_mitigation\_measures\_for\_supply\_chain\_risks](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F265557093_How_to_choose_mitigation_measures_for_supply_chain_risks)
47. (PDF) Risk‑Based Counterparty Due Diligence Framework for the Crude Segment: Case Study of PT Pertamina (Persero) - ResearchGate, [https://www.researchgate.net/publication/401940558\_Risk-Based\_Counterparty\_Due\_Diligence\_Framework\_for\_the\_Crude\_Segment\_Case\_Study\_of\_PT\_Pertamina\_Persero](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F401940558_Risk-Based_Counterparty_Due_Diligence_Framework_for_the_Crude_Segment_Case_Study_of_PT_Pertamina_Persero)
48. A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability, [https://supernet.isenberg.umass.edu/visuals/POMS-May%202016.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fsupernet.isenberg.umass.edu%2Fvisuals%2FPOMS-May%25202016.pdf)
49. Cybersecurity and Supply Chain Risk Management Are Not ... - RAND, [https://www.rand.org/content/dam/rand/pubs/research\_reports/RRA500/RRA532-1/RAND\_RRA532-1.pdf](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.rand.org%2Fcontent%2Fdam%2Frand%2Fpubs%2Fresearch_reports%2FRRA500%2FRRA532-1%2FRAND_RRA532-1.pdf)
50. Multi-criteria risk classification to enhance complex supply networks performance - PMC, [https://pmc.ncbi.nlm.nih.gov/articles/PMC8561686/](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fpmc.ncbi.nlm.nih.gov%2Farticles%2FPMC8561686%2F)
51. Risk assessment of maritime container shipping blockchain-integrated systems: An analysis of multi-event scenarios | Request PDF - ResearchGate, [https://www.researchgate.net/publication/360935055\_Risk\_assessment\_of\_maritime\_container\_shipping\_blockchain-integrated\_systems\_An\_analysis\_of\_multi-event\_scenarios](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.researchgate.net%2Fpublication%2F360935055_Risk_assessment_of_maritime_container_shipping_blockchain-integrated_systems_An_analysis_of_multi-event_scenarios)
52. Blockchain based cyber supply chain provenance, [https://ws.engr.illinois.edu/sitemanager/getfile.asp?id=3163](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fws.engr.illinois.edu%2Fsitemanager%2Fgetfile.asp%3Fid%3D3163)
53. Third-Party Risk in 2026: The Hidden Cyber Threat - SureCloud, [https://www.surecloud.com/blog-hub/third-party-risk-cybersecurity-2026](https://www.google.com/url?sa=E\&q=https%3A%2F%2Fwww.surecloud.com%2Fblog-hub%2Fthird-party-risk-cybersecurity-2026)
54. NCSC Supply Chain Risk <https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies>
55. &#x20;MDB Fast time comms paper \[xxxxx]&#x20;
56. UK Energy Cyber attacks. \[xxxxxxx]&#x20;
57. Practise Based Research <https://www.creativityandcognition.com/wp-content/uploads/2011/04/PBR-Guide-1.1-2006.pdf>
58. CTAG [https://www.ctag.gov.uk](https://www.ctag.gov.uk/)
59. &#x20;NLAWARP [https://www.nlawarp.net](https://www.nlawarp.net/)
60. NFCC WARP: <https://nfcc.org.uk/our-services/ddat/>
61. Socitm Supply Cain Risk: <https://socitm.net/resource-hub/webinars/260513-gca-hardware-market-volatility/>
62. [https://www.essexdigitalpartnership.org.uk](https://www.essexdigitalpartnership.org.uk/)
63. NCSC CAF: <https://www.ncsc.gov.uk/collection/cyber-assessment-framework>
64. <https://www.gov.uk/government/publications/supplier-code-of-conduct/supplier-code-of-conduct-html>
65. Vulnerability Disclosure Policy: <https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit>
66. LACES: <https://hstalks.com/article/10273/a-holistic-approach-to-cyber-security-in-local-gov/>
67. <https://www.localdigital.gov.uk/cyber/defend-as-one/>

&#x20;


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://guidance.ctag.org.uk/supply-chain-security-july-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
