Vendor Register

Logistics and couriers

The movement and storage of goods, including the hardware and media that carry data.

How the register reads it

Also calledcouriers, freight, 3PL
FamilyOperations
Default criticalityStandard when the paste gives none. Deliveries delay; alternatives exist; the exposure is custody of what is shipped. Raised to critical when the vendor is the only source and touches two or more systems, or touches three or more.
DORA scopeNot an ICT service in itself: recorded in the register of information only where a service element (support, maintenance, hosting) sits in the contract.
Contract focusChain of custody, insurance in transit, service levels, sub-contractor disclosure.

What each regime attaches

9 clauses across 3 regimes

Shown on a register for the regimes you tick; with none ticked, the ISO 27001 rows are the default. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

The NIS2 Directive

Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality.

NIS2 Art. 21(2)(d) Supply chain security, covering the relationship with each direct supplier and service provider

The Directive scopes this deliberately at direct suppliers and service providers, which makes the first artefact an inventory of who those parties are and which of them touch the network and information systems behind the service. From there the entity has to manage the security-related aspects of each relationship: what the supplier may access, what securit...

Evidence an auditor accepts: Inventory of direct suppliers and service providers, flagged for access to in-scope systems; Risk assessment per supplier proportionate to the access and criticality involved; Contractual security clauses, including incident notification obligations and audit or assurance rights
Common gap: Inventory built from the procurement system, so shadow and free-tier services are missing
Source framework: NIS2 Directive

NIST SP 800-161 Rev 1

Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access.

SP 800-161 SR-6 Supplier Assessments and Reviews

Assesses and reviews suppliers, at a depth matched to what they supply and the access they hold.

Evidence an auditor accepts: assessment methodology and tiering by criticality; assessment records per supplier; review cycle evidence
Common gap: all suppliers assessed with the same questionnaire
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-8 Notification Agreements

Establishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.

Evidence an auditor accepts: notification clauses with defined triggers and timeframes; evidence of notifications received; escalation route when notification fails
Common gap: notification obligation absent or without a timeframe
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-4 Acquisition Process

Puts security and supply chain requirements into the contract, including the evidence the supplier must provide.

Evidence an auditor accepts: contract templates carrying security and C-SCRM requirements; evidence of requirements in executed contracts; acceptance criteria tied to those requirements
Common gap: requirements in the template but absent from signed contracts
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-13 Supplier Inventory

A control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.

Evidence an auditor accepts: supplier inventory with the systems and components each supports; criticality attached to each supplier; update procedure on supplier change
Common gap: supplier list held by procurement with no link to systems
Source framework: NIST SP 800-161 Rev 1
SP 800-161 PS-7 External Personnel Security

Sets and enforces the personnel security requirements applying to external providers, including notification when their staff leave.

Evidence an auditor accepts: requirements imposed on providers; notification obligations for personnel change and their evidence; records of access removed on notification
Common gap: provider does not notify departures so access lingers
Source framework: NIST SP 800-161 Rev 1

ISO/IEC 27001:2022

Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default.

ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: supplier_risk_assessment; contractual_security_requirements; supplier_security_monitoring
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: contract_security_clauses; supplier_risk_assessment; security_incident_reporting
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an auditor accepts: supplier_security_monitoring_reports; supplier_service_review_meetings; supplier_change_management_records
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022

Findings this category can raise

Do this for every vendor on your list

Paste the list and get this classification for every vendor at once, with the share of spend and systems, the country it lands in, the criticality, the findings and the obligation rows per regime. Eight vendors free, no account.

Build my vendor register

Facilities and premises · Printing and document services