Supply Chain Security

cyber resilience act uk companies a three ascending rounded pillars

Cyber Resilience Act UK: Does It Apply? Essential Risk Guide

Does the EU Cyber Resilience Act apply to UK companies after Brexit? Yes — whenever software or hardware with digital elements is placed on the EU market, the duties follow the product regardless of where the manufacturer sits. This guide maps which UK businesses are caught and which escape, what placing on the market really means, the September 2026 reporting clocks and December 2027 full-application deadline, the manufacturer, importer and distributor duties, fines of up to 15 million euros or 2.5 percent of worldwide turnover, how the EU regime compares with the UK’s narrower PSTI rules and the services-focused Cyber Security and Resilience Bill, the unresolved Northern Ireland position under the Windsor Framework, and a four-step preparation plan for UK exporters.

Read more
cyber resilience act vulnerability handling requirements a upright funnel

Vulnerability Handling Requirements: Proven Safe CRA Guide

A plain-language walkthrough of the vulnerability handling requirements in Annex I, Part II of the EU Cyber Resilience Act for software teams: the eight duties from SBOM documentation to free security updates, how the five-year support period stretches them across a product’s life, what a coordinated vulnerability disclosure policy must contain, how the handling process feeds the 24-hour and 72-hour Article 14 reporting clocks from September 2026, the fine bands up to 15 million euros, the mistakes that fail assessments, and a 90-day plan to stand the whole process up before the December 2027 deadline.

Read more
sbom requirements eu cyber resilience act a tall stack blank paper sheets

SBOM Requirements: Essential EU CRA Guide to Avoid Risk

A deep-dive on SBOM requirements under the EU Cyber Resilience Act for software teams: what Annex I, Part II actually obliges you to document, the seven minimum data fields every component entry needs, how to choose between SPDX and CycloneDX, how to generate and store SBOMs in your delivery pipeline, keeping them current across versions and patches, the VEX workflow that makes vulnerability matching usable, what market surveillance authorities can demand, the fine bands up to €15 million, and a 90-day plan to get compliant before the December 2027 deadline.

Read more
supplier cyber-risk assessment - supplier cyber risk assessment checklist a concentric cube rings plinth

Supplier Cyber-Risk Assessment: Essential Safe Checklist

Most supplier assurance programmes send a spreadsheet, receive a spreadsheet and file it — producing documentation rather than assessment. This guide sets out a working supplier cyber-risk assessment checklist as a seven-step programme: building an honest supplier inventory from four independent sources, scoring inherent risk before you contact anyone, tiering the base so effort follows exposure, the ten control domains the checklist must cover, choosing an assessment method that matches the tier, demanding the evidence artefact behind every claim, converting answers into residual risk and a dated decision, handling concentration and fourth-party risk, turning findings into remediation with deadlines and consequences, monitoring continuously between reviews, and closing the loop properly at offboarding.

Read more
third-party cybersecurity questionnaire - third party cybersecurity questionnaire template a central hub six satellite nodes plinth

Third-Party Cybersecurity Questionnaire: Proven Risk Guide

Most supplier security questionnaires are inherited spreadsheets that produce documented false assurance rather than real risk reduction. This guide provides a working third-party cybersecurity questionnaire template: the eight domains it must cover, the full 47-question Tier 1 set written as closed questions, a three-tier model so you stop sending 180 rows to low-risk suppliers, a four-outcome scoring rubric that produces decisions instead of percentages, the evidence artefact to demand behind every claim, the red flags that separate a filed document from a real finding, a mapping to Cyber Essentials, ISO 27001 and NIS2 Article 21, and the contract clauses that turn questionnaire answers into enforceable obligations.

Read more
nis2 compliance uk businesses eu customers a shield padlock hexring plinth

NIS2 Compliance for UK Suppliers: Essential Risk Guide

NIS2 compliance reaches UK businesses along two routes, and the second catches far more of them than the first. This guide explains which UK companies fall directly under Directive (EU) 2022/2555 and must appoint an EU representative, how the Article 21 supply chain clause pulls every other UK supplier in through customer contracts, what the ten security measures actually require, how the 24-hour, 72-hour and one-month reporting clocks work when you are the supplier rather than the reporting entity, how the regime compares with the UK NIS Regulations 2018 and the Cyber Security and Resilience Bill, what fines and management liability look like, and a 90-day programme that gets a UK supplier to a defensible position.

Read more
cyber essentials for suppliers contract clauses a shield with keyhole plinth

Cyber Essentials for Suppliers: Proven Safe Contract Terms

Most organisations ask for Cyber Essentials during the tender and never mention it again, which leaves the requirement sitting in a questionnaire with no expiry date, no evidence obligation and no consequence attached. This guide shows how to write it into the contract instead: which suppliers belong in scope and at what level, model clause wording for the certification obligation, how to define scope so a certificate for somewhere else cannot satisfy it, what evidence to demand and how to verify it against the register, how the obligation flows down to subcontractors, what happens when certification lapses mid-term, and a proportionate remedy ladder that runs from a rectification plan to termination without ending a workable relationship.

Read more
CHAT