Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Supplier Security Risk Register

Holds the assessed supplier population with tier, assessment status, findings, expiry dates and residual risk.

Available soon

Format
Excel
Size
130 KB
Length
11 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Register
  • Findings
  • Critical Services
  • Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30, the example quarter end; replace it with today's date, or type =TODAY() to keep it current. Status, days past due and deadline flags use this date. Set the appetite level for third-party dependency from your approved P05 Cyber Risk Appetite Statement Template there too.
2On the Critical Services sheet, list your critical services (the ones your business impact analysis or continuity plan names) and their owners. The register counts how many of them each supplier supports; two or more makes it a concentration provider (TPM-04).
3Add one row per supplier: no supplier may be engaged, and no contract renewed, until intake screening is done and a tier is recorded (TP-01). Give it a Supplier ref (SUP-001, SUP-002 …) that never changes. Name its Business owner: [[the manager who buys and relies on the service]]. List the critical services it supports, separated by semicolons, using the names on the Critical Services sheet.
4Tier it with the Supplier Criticality & Tiering Model (TP-02): choose the tier each criterion reaches (TC-1 service, TC-2 data, TC-3 access, TC-4 substitutability) and any override (an ICT service supporting a critical or important function of a DORA financial entity: at least Tier 1; a processor of personal data under GDPR Article 28: at least Tier 2). Tier, Tier set by, Questionnaire set and Reassess every calculate (Tier 1 Critical: set A, every 12 months; Tier 2 Important: set B, every 24 months; Tier 3 Standard: set C, every 36 months; Tier 4 Minimal: set D, only when the service changes).
5Plan and record the assessment with the Supplier Security Assessment Procedure. Before the first assessment, enter the Planned assessment date. After it, enter Last assessed, whether the evidence was validated against the service you buy (TP-04), the residual impact and likelihood on the P05 scale (TP-06), and the Decision the business owner signed on the Supplier Security Review Report Template (TP-05). Next due and Assessment status calculate.
6Enter each finding on the Findings sheet with its supplier ref, severity and the date raised (the review report date). The deadline calculates (High 90 calendar days, Medium 180 calendar days, Low at the next assessment), and the open counts come back to the register. When a High finding passes its deadline, escalate it to the business owner and record the date (TP-08).
7Read the Position against appetite. A supplier outside appetite is escalated: enter it in the P05 Information Security Risk Register and put that register's reference here (TP-06). Record whether the contract carries the tier's clauses from the Supplier Contract Security Clause Library (TP-07) and whether an exit plan exists (TP-11).
8Clear every Record check that does not say OK. Reassess each supplier by its Next due date, and sooner after a material change, an incident or a breach at the supplier (TP-09). Take the Summary figures to [[e.g. Executive Committee]] every quarter (TP-12).
9Delete the EXAMPLE rows on the Register, Findings and Critical Services sheets, and the EXAMPLE portfolio counts on the Summary sheet, before the register is approved. Do not type over the white calculated columns.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30 (Q3 2026). It has 112 suppliers: 14 Tier 1, 22 Tier 2, 31 Tier 3, 45 Tier 4. To keep the example readable, only the 14 Tier 1 suppliers have rows here; the others are counted in the portfolio table on the Summary sheet. Your register lists every supplier, one row each.

In the EXAMPLE, 9 of the 14 Tier 1 suppliers have been assessed in the last 12 months (TPM-01; the board measure BM-05 in the P03 pack). The three logistics suppliers were assessed this quarter and the other five are planned for Q4. The managed IT service provider (SUP-001) is P05 risk R-06. F-01, a High finding at the ERP provider, is past its deadline and was escalated to the business owner.

Tailoring — small organisation: start with the suppliers that would stop a critical service or hold customer data; tier the rest at the next renewal. One person may assess, but the business owner still signs each decision (TP-05).

Tailoring — regulated entity: NIS2 Art 21(2)(d) and 21(3) expect supply chain security to take account of each direct supplier's vulnerabilities and security practice; the tier, evidence and findings here are that record. A DORA financial entity must keep a register of information on all contractual arrangements for ICT services, distinguishing those supporting critical or important functions (Art 28(3)), and assess concentration (Art 29(1)): add columns for the function supported and the contract reference and keep this register reconciled with it. Mark each processor of personal data with the GDPR override (Art 28(1)).

Tailoring — IT run by a service provider: the provider is a supplier in this register, usually Tier 1, and so are the providers it relies on for your service where you can name them. Ask it to report its own suppliers' changes as a material change (TP-09).

Tiers, sets, intervals, overrides, severities, deadlines, decisions, the P05 scale, bands and appetite levels are on the Lists sheet. If your Supplier Criticality & Tiering Model or Supplier Security Assessment Procedure sets different ones, change them there and nowhere else. A deviation from a supplier requirement is a P02 exception, recorded in the Security Exception Register.

Register

One row per supplier (TP-01). Yellow columns are inputs; white columns calculate. Every colour sits beside a word.

ExampleSupplier refSupplierSupplier typeBusiness ownerCritical services supportedCritical services (number)DataAccessTC-1 ServiceTC-2 DataTC-3 AccessTC-4 SubstitutabilityOverrideTierTier set byQuestionnaire setReassess every (months)Last assessedPlanned assessmentNext dueAssessment statusDays past dueEvidence validated (TP-04)Open High findingsOpen Medium findingsOpen Low findingsHigh findings past deadlineResidual impact (1–4)Residual likelihood (1–4)Residual scoreResidual bandPosition against appetiteP05 risk register refDecisionContract clauses in place (TP-07)Exit plan (TP-11)Record checkNotes
EXAMPLESUP-001Managed IT service providerITHead of ITOnline ordering; Warehouse dispatch; Finance and payroll3Customer dataPrivilegedTier 1Tier 1Tier 1Tier 1GDPR processorTier 1TC-1, TC-2, TC-3, TC-4A1218 Nov 202518 Nov 2026Due soonYes0000313LowWithin appetiteR-06ApproveYesYesOKP05 risk R-06 (treatment: Transfer).
EXAMPLESUP-002Cloud hosting providerITHead of ITOnline ordering; Finance and payroll2Customer dataNetworkTier 1Tier 1Tier 1Tier 1GDPR processorTier 1TC-1, TC-2, TC-3, TC-4A1227 Jan 202627 Jan 2027In dateYes0000313LowWithin appetiteApprove with conditionsYesYesOKF-04 closed 2026-03-30.
EXAMPLESUP-003Payment service providerFinanceChief Financial OfficerPayments1Card data (held by the provider)NoneTier 1Tier 1Tier 4Tier 1NoneTier 1TC-1, TC-2, TC-4A1224 Feb 202624 Feb 2027In dateYes0000313LowWithin appetiteApproveYesYesOK
EXAMPLESUP-004ERP software provider (hosted)ITChief Financial OfficerFinance and payroll; Warehouse dispatch2Personal dataRemote supportTier 1Tier 2Tier 2Tier 1GDPR processorTier 1TC-1, TC-4A1221 Apr 202621 Apr 2027In dateYes1101326MediumWithin appetiteApprove with conditionsYesYesHigh finding past deadline: escalate to the business owner (TP-08)Conditions: F-01 and F-02 fixed by their deadlines.
EXAMPLESUP-005Email and office software providerITHead of ITCustomer contact1Personal dataNoneTier 1Tier 2Tier 4Tier 2GDPR processorTier 1TC-1A1219 May 202619 May 2027In dateYes0000212LowWithin appetiteApproveYesYesOK
EXAMPLESUP-006Security monitoring providerITHead of Information SecurityOnline ordering; Warehouse dispatch2Log dataPrivilegedTier 1Tier 3Tier 1Tier 2NoneTier 1TC-1, TC-3A1216 Jun 202616 Jun 2027In dateYes0000212LowWithin appetiteApproveYesYesOK
EXAMPLESUP-007National parcel carrierLogisticsHead of LogisticsWarehouse dispatch1Customer addressesIntegrationTier 1Tier 1Tier 2Tier 2GDPR processorTier 1TC-1, TC-2A1214 Jul 202614 Jul 2027In dateYes0000224MediumWithin appetiteApproveYesYesOK
EXAMPLESUP-008Express courierLogisticsHead of LogisticsWarehouse dispatch1Customer addressesIntegrationTier 1Tier 1Tier 2Tier 2GDPR processorTier 1TC-1, TC-2A1218 Aug 202618 Aug 2027In dateYes0000212LowWithin appetiteApproveYesYesOK
EXAMPLESUP-009Pallet networkLogisticsHead of LogisticsWarehouse dispatch1Customer addressesPortalTier 1Tier 1Tier 4Tier 2GDPR processorTier 1TC-1, TC-2A1215 Sep 202615 Sep 2027In dateYes0100224MediumWithin appetiteApprove with conditionsYesYesOKCondition: F-03 fixed by its deadline.
EXAMPLESUP-010Warehouse management system providerITHead of LogisticsWarehouse dispatch1InternalRemote supportTier 1Tier 3Tier 2Tier 1NoneTier 1TC-1, TC-4A1220 Oct 202620 Oct 2026Planned0000YesNoAgree an exit plan (TP-11)
EXAMPLESUP-011Backup service providerITHead of ITOnline ordering; Finance and payroll2Customer dataNetworkTier 1Tier 1Tier 1Tier 2GDPR processorTier 1TC-1, TC-2, TC-3A123 Nov 20263 Nov 2026Planned0000YesNoAgree an exit plan (TP-11)
EXAMPLESUP-012Payroll bureauFinanceHR DirectorFinance and payroll1Personal data (staff)PortalTier 1Tier 1Tier 4Tier 2GDPR processorTier 1TC-1, TC-2A1217 Nov 202617 Nov 2026Planned0000YesNoAgree an exit plan (TP-11)
EXAMPLESUP-013Outsourced customer contact centreServiceChief Operating OfficerCustomer contact1Customer dataRemote userTier 1Tier 1Tier 2Tier 2GDPR processorTier 1TC-1, TC-2A121 Dec 20261 Dec 2026Planned0000NoNoAdd the tier's security clauses to the contract (TP-07)Contract predates the policy; clauses added at renewal.
EXAMPLESUP-014Network connectivity providerITHead of ITOnline ordering; Warehouse dispatch2None storedNetworkTier 1Tier 4Tier 1Tier 1NoneTier 1TC-1, TC-3, TC-4A128 Dec 20268 Dec 2026Planned0000NoNoAdd the tier's security clauses to the contract (TP-07)Contract predates the policy; clauses added at renewal.

Findings

One row per finding from a Supplier Security Review Report Template (TP-08). The deadline is set by severity, in calendar days from the date raised.

ExampleFinding IDSupplier refSupplierSeverityFindingOwnerRaisedDeadlineStatusClosed onDays past deadlineDeadline flagEscalated to business owner onNotes
EXAMPLEF-01SUP-004ERP software provider (hosted)HighSupport staff reach our ERP without multi-factor authenticationChief Financial Officer21 Apr 202620 Jul 2026Open72Past deadline21 Jul 2026Escalated to the business owner the day after the deadline (TP-08).
EXAMPLEF-02SUP-004ERP software provider (hosted)MediumNo evidence that our data is deleted at contract endChief Financial Officer21 Apr 202618 Oct 2026Open
EXAMPLEF-03SUP-009Pallet networkMediumShared portal accounts used by depot staffHead of Logistics15 Sep 202614 Mar 2027Open
EXAMPLEF-04SUP-002Cloud hosting providerHighPenetration test older than 12 monthsHead of IT27 Jan 202627 Apr 2026Closed30 Mar 2026New penetration test summary received and checked.

Critical Services

Your critical services and their owners. The Register sheet counts how many of these each supplier supports.

ExampleCritical serviceService ownerSuppliers supporting itOf those, without an exit planOf those, not assessed or overdue
EXAMPLEOnline orderingChief Operating Officer522
EXAMPLEWarehouse dispatchHead of Logistics822
EXAMPLEPaymentsChief Financial Officer100
EXAMPLEFinance and payrollChief Financial Officer522
EXAMPLECustomer contactChief Operating Officer211

Summary

Register summary

Every figure is calculated from the Register and Findings sheets as at the date shown. Use them for the quarterly report to executive management (TP-12); the Third-Party Risk Dashboard adds the trend.

As-at date30 Sep 2026EXAMPLE date (the example quarter end). Replace it with today's date, or type =TODAY().
Appetite level: third-party dependencyCautiousEXAMPLE: the level in the P05 Cyber Risk Appetite Statement Template for RC-05 third-party dependency. Use your own.
Due soon: calendar days before the next due date90One quarter, the reporting interval. Change it if you report more often.
Target date: all Tier 1 suppliers assessed (TPM-01)31 Dec 2026EXAMPLE: the year end, from the target "All Tier 1 by [[year end]]". Use your own.

Headline measures

MeasureResultTargetStatusWhat it means
TPM-01 Tier 1 suppliers assessed9 of 14All Tier 1 by [[year end]]On targetTier 1 suppliers with an assessment within the last 12 months, out of all Tier 1 suppliers. On target while the rest are planned before the target date (C8). The board measure BM-05 in the P03 pack.
TPM-02 Reassessments overdue0Zero Tier 1; none more than 90 days overdueOn targetSuppliers past their tier's reassessment interval. A supplier never assessed whose planned date has passed counts as overdue.
TPM-03 High findings past deadline1ZeroAction neededOpen High findings past their remediation deadline. Each is escalated to the supplier's business owner (TP-08); see the Findings sheet.
TPM-04 Concentration6Each one known, with an exit plan (TP-11)Action neededProviders that two or more critical services depend on. Counted from the critical services each supplier supports.
of those, without an exit plan20Every Tier 1 and Tier 2 contract needs an exit plan (TP-11); a concentration provider without one is the first to fix.

Portfolio by tier

TierQuestionnaire setReassess every (months)Suppliers in the portfolioRows in the registerNot yet in the registerIn dateDue soonOverduePlanned
Tier 1 CriticalA12141408105
Tier 2 ImportantB24220220000
Tier 3 StandardC36310310000
Tier 4 MinimalDOn change450450000
All tiers11214988105

EXAMPLE: the suppliers in each tier are typed in (yellow). Only the 14 Tier 1 suppliers have rows in this example; in your register every supplier has a row and "Not yet in the register" is 0.

Decisions and residual risk

Decision (TP-05)SuppliersResidual bandSuppliersPosition against appetiteSuppliers
Approve6Low (1–3)6Within appetite9
Approve with conditions3Medium (4–6)3Outside appetite, within tolerance0
Escalate0High (8–9)0Outside tolerance0
Reject0Critical (12–16)0Not yet scored5

Findings

SeverityDeadline (calendar days from the report)OpenPast deadlineClosed
High90111
Medium180200
LowNext assessment000

Record checks to resolve

CheckSuppliers
Complete the supplier and business owner0
Rate the four tiering criteria (TP-01, TP-02)0
Not yet assessed: set a planned date (TP-09)0
Overdue: reassess now (TP-09)0
Validate the evidence: scope, dates and legal entity (TP-04)0
Record the decision, signed by the business owner (TP-05)0
Score the residual risk on the P05 scale (TP-06)0
Outside appetite: enter it in the P05 risk register (TP-06)0
High finding past deadline: escalate to the business owner (TP-08)1
Add the tier's security clauses to the contract (TP-07)2
Agree an exit plan (TP-11)3
All rows with a check to resolve6

Each row shows only its first unresolved check; clear it and the next one, if any, appears.

Quarterly review record

ItemEntry
Reviewed by (name, role) and date[[Name, role, YYYY-MM-DD]]
Suppliers assessed this quarter, and their decisions[[e.g. SUP-007, SUP-008, SUP-009: two Approve, one Approve with conditions]]
Findings escalated, and to whom[[e.g. F-01 to the Chief Financial Officer, 2026-07-21]]
Decisions needed from executive management[[e.g. exit plans for the two concentration providers without one]]

Lists

TierNameTierLabelTierSetTierMonthsOverrideNameOverrideMinTierStatusYesNoDecisionSeveritySeverityDaysFindingStatusLevelBandBandMinScoreAppetiteLevelLevelAppetiteLevelTolerancePosition
Tier 1Tier 1 CriticalA12NoneIn dateYesApproveHigh90Open1Low1AverseLowMediumWithin appetite
Tier 2Tier 2 ImportantB24DORA critical or important functionTier 1Due soonNoApprove with conditionsMedium180Closed2Medium4CautiousMediumHighOutside appetite, within tolerance
Tier 3Tier 3 StandardC36GDPR processorTier 2OverdueEscalateLowNext assessment3High8OpenHighHighOutside tolerance
Tier 4Tier 4 MinimalDOn changePlannedReject4Critical12

Not required

Definitions

Definitions

TermMeaning in this workbook
SupplierAny third party that provides goods or services and could affect the security of our information or services, including cloud and software providers, outsourcers and their own suppliers where we rely on them.
Supplier refYour unique reference for the supplier, such as SUP-004. It stays the same while the supplier is in the register.
Business owner[[the manager who buys and relies on the service]]. Signs the decision after each assessment (TP-05) and receives escalated findings (TP-08).
Critical serviceA service whose loss would seriously harm the organisation or its customers, listed on the Critical Services sheet.
Tiering criteriaTC-1 Service — Tier 1: runs or supports a critical service, or a critical or important function; Tier 2: supports an important internal service; Tier 3: supports a minor service; Tier 4: no service dependency. TC-2 Data — Tier 1: sensitive or personal data at scale, or customer data; Tier 2: personal data; Tier 3: internal non-personal data; Tier 4: no data, or public data only. TC-3 Access — Tier 1: privileged or network-level access to critical systems; Tier 2: remote user access to our systems; Tier 3: limited or supervised on-site access; Tier 4: no access. TC-4 Substitutability — Tier 1: could not be replaced within [[3 months]] without harm to a critical service; Tier 2: could be replaced within [[3 months]] with effort; Tier 3: replaceable within [[3 months]] with little effort; Tier 4: replaceable at once: many suppliers offer the same.
OverrideAn ICT service supporting a critical or important function of a DORA financial entity: at least Tier 1. A processor of personal data under GDPR Article 28: at least Tier 2.
TierThe tier must be the highest any criterion reaches, and never below an override's minimum. Tier 1 Critical, Tier 2 Important, Tier 3 Standard, Tier 4 Minimal.
Tier set byThe criteria that reached the supplier's tier, or Override where an override raised it above every criterion.
Questionnaire setA: Tier 1, about 60 questions; B: Tier 2, about 35 questions; C: Tier 3, about 15 questions; D: Tier 4, about 5 (intake screening only) questions. The sets are in the Tiered Supplier Security Questionnaire.
Reassess everyTier 1: 12 months; Tier 2: 24 months; Tier 3: 36 months; Tier 4: only when the service changes. The most time allowed between assessments; a material change, incident or breach brings it forward (TP-09).
Next dueLast assessed plus the tier's interval. For a supplier not yet assessed, its planned assessment date.
Assessment statusIn date: next due more than the due-soon window away. Due soon: next due within the window (90 calendar days by default). Overdue: next due date passed, or no assessment and no planned date. Planned: not yet assessed, planned date still ahead. Not required: a tier reassessed only when the service changes.
Evidence validatedEvidence must be validated, not just received: its scope, dates and legal entity must match the service we buy.
Finding severityHigh: a gap that could directly cause a significant incident or data loss at this supplier; deadline 90 calendar days after the review report. Medium: a gap that weakens a control but has other protection around it; deadline 180 calendar days after the review report. Low: an improvement; tracked to the next assessment; deadline the next assessment.
Residual riskThe risk the supplier still poses with the controls it and we have in place, scored on the P05 scale: impact × likelihood, each 1 to 4 (TP-06). Bands: Low 1–3, Medium 4–6, High 8–9, Critical 12–16.
Position against appetiteWithin appetite: the band is at or below the appetite for third-party dependency. Outside appetite, within tolerance: above appetite, at or below tolerance. Outside tolerance: above tolerance. Outside appetite, the supplier risk goes to the P05 Information Security Risk Register.
DecisionApprove: residual risk within appetite; no High finding open. Approve with conditions: proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. Escalate: residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06). Reject: do not contract, or plan exit (TP-11).
Concentration providerProviders that two or more critical services depend on. Each one known, with an exit plan (TP-11).
Exit planEvery Tier 1 and Tier 2 contract must have an exit plan: data return or deletion, access removal, and a transition period.
Record checkA calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding.
As-at dateThe date status, days past due and deadline flags are measured against. Set on the Summary sheet.
EXAMPLE rowA worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. Delete before approval.
TP-nn, TPM-nnRule and measure numbers in the Third-Party Security Policy.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.19 — Information security in supplier relationshipsThe register as a whole: each supplier identified, tiered by the risk it brings, and managed to its tier's requirements
ISO/IEC 27001:2022Annex A 5.22 — Monitoring, review and change management of supplier servicesLast assessed, next due, status, findings and deadlines: supplier security monitored, reviewed and reassessed on change
NIST CSF 2.0GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship”Residual score, band, position, decision and findings: supplier risk assessed, recorded, prioritised, responded to and monitored
NIST CSF 2.0GV.SC-04 — “Suppliers are known and prioritized by criticality”Tiering criteria, override and tier: suppliers known and prioritised by criticality
DORA — Regulation (EU) 2022/2554Article 28(3) — a register of information on all contractual arrangements for ICT services, distinguishing those supporting critical or important functionsOne row per ICT arrangement with the critical services it supports; add the function and contract columns for the register of information
DORA — Regulation (EU) 2022/2554Article 29(1) — assessing concentration risk: providers not easily substitutable, or several arrangements with the same providerCritical services (number) and TPM-04: providers several critical services depend on, with substitutability (TC-4) and exit plan

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)