For the complete documentation index, see llms.txt. This page is also available as Markdown.

Supply Chain Security July 2026

CTAG Supply Chain Security Resources

Approach to Third Party (Supply Chain) Risks, their Identification and mitigation derived from UK Public Sector fieldwork.

The Integrated Supply Chain Security and Assurance Framework structures supply chain risk into several core pillars, moving from evidence-based threat profiling to legal procurement controls and maturity tracking.

1. Strategic Foundation and Threat Profiling The framework is built on an evidence-based approach that mandates analysing historical supplier data breaches and attacks to inform dynamic threat profiles. These threat profiles prioritise public internet-facing services, which carry the highest risk of compromise. It identifies Identity and Access Management (IAM) exposure, Shared Responsibility Mapping (SRM) across cloud and on-premises deployment, and broader geopolitical risks. The SRM is a key component as client organisations must fully understand where the supplier responsibility ends and their consumer responsibility starts. This is critical for good governance and data protection. Table 4 summarises these risks.

Approach to Supply Chain Mapping

Threat Profile Priority

Description & Focus Area

Public Internet-Facing Services

Identifies and profiles suppliers with services exposed to the public web, treating them as high-priority risk vectors.

Identity and Access Management (IAM) Exposure

Analyses the risks associated with service-to-service authentication and human administrative access within the supply chain.

Shared Responsibility Mapping

Distinguishes and clarifies risk ownership across different deployment scenarios, including on-premises, Software as a Service (SaaS), and cloud-native environments.

Geopolitical Risks

Factors broader political and economic stability contexts into the overall supplier risk scoring. This includes where data is processed & stored.

Key software service Threat profiles and Risks (Source: Author).

Centralised Supplier Repository / Information Asset Register

A dynamic, relational Central Supplier Catalogue serves as the primary resilience tool, accommodating both standardised data and free-text fields. The catalogue/register is the absolute core of any supply chain security programme of work. The real power of this approach, comes when the community / eco-systems share them. Within a Local Authority in the UK, there could be upwards of 750 systems and services. This is highly complex and generates a mountain or lake of data. Where Councils share he same supplier, knowing which other Councils share that supplier and having a detailed inventory of that suppliers’ components, and versions can really help during an incident, immediately alerting who would be affected by an exploit. This is key to the “Defend as One” Programme of work. [67] Table 5, provides an information asset template . This can be formatted as XML or other metadata to allow easy electronic sharing. The version number will ensure consistent mapping of any version changes I the structure. This template could become a standard for use within UK Local Government, this would facilitate information sharing and Cyber Incident Response. Th version number included to reflect this is the initial version 1.0 suggestion as of July 2026. There will need to be an accessible repository for the standard, such as the CTAG Guidance repository

Information Asset Register (IAR) Template (Version 1.0 July 2026)

Field Category

Field Name

Description

Framework Mandated

Date entry created

The date the Asset record was created.

Framework Mandated

Date entry updated / reviewed

The Asset Record must be reviewed at least annually.

Framework Mandated

Unique Supplier ID (Unique Key)

A unique identifier that programmatically links the information asset to the Central Supplier Catalogue.

Framework Mandated

Processing / Hosting Supplier

Explicitly identifies the third-party supplier that is responsible for processing, managing, or hosting the information asset.

Framework Mandated

Product / Service version number

This is the product / service version number (Patch level).

Framework Mandated

Suppler Assertion Verification

Indicates whether the asset has been verified using automated discovery tools to validate the supplier's claims. Or that a CAF or similar audit exists

Framework Mandated

Supplier Cyber Essentials / Plus – or ISO 27001 etc. status recorded and verified

Record and verify the asserted security certifications held by the supplier.

(Review annually during contract)

Framework Mandated

DPIA Status

Tracks whether a standardised Data Protection Impact Assessment (DPIA) has been completed for the asset, particularly regarding supply chain changes. Whilst only mandated for complex systems, this is a very robust way to assure personal data, being processed and stored.

Standard Best Practice

Asset ID / Reference Number

A unique internal alphanumeric identifier assigned to the specific asset.

Standard Best Practice

Asset Name & Description

A clear title and brief summary of what the information asset is and its business purpose (e.g., "Customer Payment Gateway").

Standard Best Practice

Information Asset Owner (IAO)

The internal role, department, or individual who is ultimately accountable for the asset's security and lifecycle. A named individual is best, by default it will be the service owner.

Standard Best Practice

Data Classification

The sensitivity level of the data contained in the asset (e.g., Public, OFFICIAL, Internal, Confidential, Restricted).

Standard Best Practice

Format and Location

Where and how the asset is stored (e.g., AWS Cloud, On-Premises Server, Physical Records).

Standard Best Practice

Business Criticality (CIA)

An assessment of the impact on the business if the asset's Confidentiality, Integrity, or Availability is compromised.

Standard Best Practice

Modelling harm

Understand the harm caused in the event of a data breach, to an individual, community or other group, includes, physical, financial, reputational. This can align with the UK Data Classification Guidelines.

Standard Best Practice

Retention Period & Disposal

The required legal or operational lifespan of the data and the approved method for secure disposal at the end of its lifecycle. Remember data isn’t gone until the last backup is deprecated.

Information Asset Register Template (Source: Author)

Suppliers must actively maintain standardised assertions [63] regarding their patching status, encryption protocols, compliance certificates, and product liability. To ensure transparency, suppliers are also required to have a formal Vulnerability Disclosure Policy (VDP) so the organization is alerted to critical bugs before exploitation.[65] There are a number of commercial tools available that do this.

Technical Architecture and Asset Management

Scalable, real-time assurance is achieved through an API-driven architecture where either the organisation pulls data from supplier endpoints, or suppliers push updates to a central API. The architecture also explores using blockchain for non-repudiation, utilizing immutable timestamps to prevent suppliers from backdating compliance evidence after an incident.

Furthermore, an Information Asset Register (IAR) must be programmatically linked to the supplier catalogue using a Unique Supplier ID. An integrated Assurance Toolkit leverages open-source automated discovery tools to verify local network assets against supplier claims, establishing a "ground truth".

Governance and Compliance Alignment Policy governance is driven by the LACES framework (Local Authority Cyber Eco-System). [66] Supplier risks—such as IAM exposure and service criticality—are formally tracked in a dedicated Supply Chain Risk Register. To avoid "compliance fatigue," the framework maps requirements to a targeted, risk-proportional subset of the NCSC Cyber Assessment Framework (CAF) and EU NIS/NIS2 regulations. [63]

Procurement and Legal Integration Security is embedded into the procurement lifecycle using model contract clauses, rigorous tender questionnaires, and structured dropdown answers to enable automated scoring. Crucially, the framework enforces Legally Binding Assertions (LBAs), which tie a supplier's security claims directly to contractual limits of liability and insurance recourse. [64]

Maturity Modelling and Implementation Organisations evaluate their supplier assurance capabilities on a 0-to-5 maturity scale, progressing from non-existent/reactive checks (0-1) up to full lifecycle automated assurance and predictive risk modelling (5). The framework concludes with a four-phase roadmap for operationalisation, spanning research, tooling development, governance drafting, and alignment with GDS/DCMS architecture standards.

References:

  1. Integrating Machine Learning and Business Intelligence into Supply Chain Risk Management for a Comprehensive Cybersecurity Framework: A Systematic Literature Review - MDPI, https://www.mdpi.com/2227-7080/14/4/194

  2. Third-Party Risk Management: Ensuring Vendor and Partner Compliance with Data Protection Laws - ResearchGate, https://www.researchgate.net/publication/395476764_Third-Party_Risk_Management_Ensuring_Vendor_and_Partner_Compliance_with_Data_Protection_Laws

  3. Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports - Scholars Archive, https://scholarsarchive.library.albany.edu/cgi/viewcontent.cgi?article=1002&context=ehc_fac_scholar

  4. The development of supply chain management cybersecurity risks: What past incidents - Iowa State University, https://dr.lib.iastate.edu/bitstreams/bbbea3cc-d43d-4b13-ab44-51c2e7a78eb8/download

  5. Deciphering the Supply Chain Chessboard: The Science of Decision-Making in Risk Management - CyberRisk Alliance, https://www.cyberriskalliance.com/blog/deciphering-the-supply-chain-chessboard-the-science-of-decision-making-in-risk-management

  6. Supply chain cybersecurity & compliance - Star | Global, https://star.global/posts/supply-chain-cybersecurity-compliance/

  7. NIST 800-161: Cybersecurity Supply Chain Risk Management Steps - ComplianceForge, https://complianceforge.com/compliance/nist-800-161-compliance

  8. Third-Party Risk Statistics 2026: Vendor & Supply Chain Risk - DeepStrike, https://deepstrike.io/blog/third-party-risk-statistics

  9. Supply Chain Risk Management: A Strategic Guide for Modern Resilience - Panorays, https://panorays.com/blog/supply-chain-risk-management-strategies/

  10. Third-Party Risk Management in Cybersecurity Reference | Advanced Security Authority, https://advancedsecurityauthority.com/third-party-risk-management-reference/

  11. What Is Third Party Risk Management? 2025 Complete Guide - Isora GRC, https://www.saltycloud.com/blog/third-party-risk-management/

  12. TPRM Maturity Model for Third-Party Risk: Complete Guide [2026] | Isora GRC, https://www.saltycloud.com/blog/tprm-maturity-model/

  13. Third-Party Risk Management Frameworks: The Guide - Mitratech, https://mitratech.com/resource-hub/blog/third-party-risk-management-frameworks/

  14. Supply Chain Risk Management: Best Practices - Drata, https://drata.com/learn/tprm/supply-chain-best-practices

  15. A Multicriteria Decision-Making Approach to Building Resilience Along the Indian Medical Equipment Supply Chain | Request PDF - ResearchGate, https://www.researchgate.net/publication/389302015_A_Multicriteria_Decision-Making_Approach_to_Building_Resilience_Along_the_Indian_Medical_Equipment_Supply_Chain

  16. Key Practices in Cyber Supply Chain Risk Management: Observations from Industry - NIST Technical Series Publications, https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8276.pdf

  17. The Anatomy of a Good Concept: A Systematic Review on Cyber Supply Chain Risk Management - MDPI, https://www.mdpi.com/2071-1050/18/3/1151

  18. Conduct an Effective Supply Chain Cybersecurity Risk Assessment - Onspring Technologies, https://onspring.com/resources/blog/conduct-an-effective-supply-chain-cybersecurity-risk-assessment/

  19. SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties, https://arxiv.org/html/2406.10109v1

  20. The Benefits of a Software Bill of Materials Program at Nuclear Facilities - INL Digital Library - Idaho National Laboratory, https://inldigitallibrary.inl.gov/sites/sti/sti/Sort_65326.pdf

  21. A Complete Guide to Third-Party Security Assessment - SPOG, https://blog.spog.ai/a-complete-guide-to-third-party-security-assessment/

  22. (PDF) Information Security Risk Management Model for Big Data - ResearchGate, https://www.researchgate.net/publication/362562040_Information_Security_Risk_Management_Model_for_Big_Data

  23. Modelling the conundrums to cyber-risks management in logistics firms for supply chain social sustainability - Emerald Publishing, https://www.emerald.com/jeim/article/37/6/1885/1227695/Modelling-the-conundrums-to-cyber-risks-management

  24. Managing cyber risk in supply chains: A review and research agenda, https://researchportal.hw.ac.uk/files/25264894/SCMIJ_AAP.pdf

  25. Cyber Risks: Systematic Literature Analysis - International Institute of Informatics and Cybernetics, https://www.iiisci.org/journal/PDV/sci/pdfs/SA153UQ24.pdf

  26. Cyber Supply Chain Risk Management: From Threats to Treatment | Scilit, https://www.scilit.com/publications/e3d0699efee879e39d63eabe9a91a08a

  27. The relationship between cybersecurity awareness, cybersecurity supply chain risk management and firm performance - Emerald Insight, https://www.emerald.com/scm/article/30/5/497/1265668/The-relationship-between-cybersecurity-awareness

  28. Full article: A combined Blockchain and sero-knowledge model for healthcare B2B and B2C data sharing - Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/25765299.2023.2188701

  29. The MARISMA- CPS pattern - Essex Research Repository, https://repository.essex.ac.uk/33036/1/1-s2.0-S0166361522001129-main.pdf

  30. Evaluation of the Feasibility of Utilising a Low-Cost UWB Radar for Hardware Implant & Counterfeit Device Detection - INFO - Oak Ridge National Laboratory, https://info.ornl.gov/sites/publications/Files/Pub182146.pdf

  31. Proceedings of the Cyber Supply Chain Risk Management for Critical Systems (CySCRM '24) - Pacific Northwest National Laboratory, https://www.pnnl.gov/sites/default/files/media/file/Final%20CySCRM%20Proceedings.pdf

  32. Cyber Supply Chain Risk Management in the Netherlands ..., https://essay.utwente.nl/fileshare/file/96796/weiss_MA_eemcs.pdf

  33. Key Strategies for Managing Third-Party Risk Under DORA - Omada, https://omadaidentity.com/resources/blog/strategies-third-party-risk-dora/

  34. Digital Operational Resilience Act (DORA) - eiopa - European Union, https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en

  35. Third-Party Risk Management under DORA | SAP LeanIX, https://www.leanix.net/en/wiki/trm/third-party-risk-management-under-dora

  36. DORA Third-Party Risk Management Compliance | Prevalent - Mitratech, https://mitratech.com/resource-hub/rc-use-case/eu-digital-operational-resilience-act-compliance/

  37. CMMC 2.0 Compliance Templates - ComplianceForge, https://complianceforge.com/compliance/cmmc-compliance-dfars-252-204-7021

  38. BOMs Away! Inside the Minds of Stakeholders:A ... - Oscar Chaparro, https://ojcchar.github.io/files/27-icse24-sboms.pdf

  39. How to choose mitigation measures for supply chain risks | Request PDF - ResearchGate, https://www.researchgate.net/publication/265557093_How_to_choose_mitigation_measures_for_supply_chain_risks

  40. (PDF) Risk‑Based Counterparty Due Diligence Framework for the Crude Segment: Case Study of PT Pertamina (Persero) - ResearchGate, https://www.researchgate.net/publication/401940558_Risk-Based_Counterparty_Due_Diligence_Framework_for_the_Crude_Segment_Case_Study_of_PT_Pertamina_Persero

  41. A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability, https://supernet.isenberg.umass.edu/visuals/POMS-May%202016.pdf

  42. Cybersecurity and Supply Chain Risk Management Are Not ... - RAND, https://www.rand.org/content/dam/rand/pubs/research_reports/RRA500/RRA532-1/RAND_RRA532-1.pdf

  43. Multi-criteria risk classification to enhance complex supply networks performance - PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC8561686/

  44. Risk assessment of maritime container shipping blockchain-integrated systems: An analysis of multi-event scenarios | Request PDF - ResearchGate, https://www.researchgate.net/publication/360935055_Risk_assessment_of_maritime_container_shipping_blockchain-integrated_systems_An_analysis_of_multi-event_scenarios

  45. Blockchain based cyber supply chain provenance, https://ws.engr.illinois.edu/sitemanager/getfile.asp?id=3163

  46. Third-Party Risk in 2026: The Hidden Cyber Threat - SureCloud, https://www.surecloud.com/blog-hub/third-party-risk-cybersecurity-2026

  47. MDB Fast time comms paper [xxxxx]

  48. UK Energy Cyber attacks. [xxxxxxx]

Last updated

Was this helpful?