Hardware and devices
Physical equipment: servers, switches, laptops, accelerators, power modules. The relationship ends at delivery unless support is bundled, but the country of origin and the spares supply outlive the invoice.
Categories in this family
6- AI accelerators and GPUs important
Specialised compute for training and running models, bought as cards and servers or rented as capacity, from a supply chain with few sources. - End-user devices standard
The laptops, phones and peripherals staff work on, bought or leased, imaged and disposed of. - Network equipment critical
Switches, routers, firewalls and wireless equipment: the boxes traffic passes through, with the firmware the vendor writes. - Power and cooling modules critical
The power and cooling equipment in the data halls and comms rooms, whose control firmware and spares come from the maker. - Semiconductors and components important
Chips, boards, drives, security modules and terminals that go into the products and systems the business runs or sells. - Servers and storage hardware important
The physical machines and storage the business owns, and the maintenance and spares contract that keeps them running.
What reaches this family
| NIS2 | Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality. On every vendor here: NIS2 Art. 21(2)(d), NIS2 Art. 21(3), NIS2 Art. 24. |
|---|---|
| SP 800-161 | Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access. On every vendor here: SP 800-161 SR-6, SP 800-161 SR-8, SP 800-161 SA-4, SP 800-161 SR-13, SP 800-161 SR-4, SP 800-161 SR-9, SP 800-161 SR-10, SP 800-161 SR-11, SP 800-161 MA-6, SP 800-161 SR-12. |
| ISO 27001 | Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default. On every vendor here: ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22, ISO 27001 5.21. |
| DORA | Not an ICT service in itself; recorded in the register of information only where a service element sits in the contract. |
Register the vendors in this family
Paste the list; every vendor in this family is placed in its category, given its share of spend and systems and the country it lands in, and carries the obligation rows above. Eight vendors free, no account.
Build my vendor register