Vendor Register

Network equipment

Switches, routers, firewalls and wireless equipment: the boxes traffic passes through, with the firmware the vendor writes.

How the register reads it

Also calledswitches, routers, firewall appliances, access points
FamilyHardware and devices
Default criticalityCritical when the paste gives none. Traffic stops at a failed core switch; the firmware supply chain and the country of manufacture are the questions the regimes now ask.
DORA scopeNot an ICT service in itself: recorded in the register of information only where a service element (support, maintenance, hosting) sits in the contract.
OriginA category where the country of origin is a supply chain question: a blank vendor country raises the origin finding, which names the lists to check (the EAR Entity List, the OFAC SDN list, the EU sanctions map) and rules on nothing.
Contract focusFirmware and vulnerability notification, country of manufacture and assembly, support term, end-of-life notice, secure disposal.

What each regime attaches

19 clauses across 3 regimes

Shown on a register for the regimes you tick; with none ticked, the ISO 27001 rows are the default. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

The NIS2 Directive

Attaches to every direct supplier and service provider of the entity, whatever it supplies; the depth of the assessment follows the access and the criticality.

NIS2 Art. 21(2)(d) Supply chain security, covering the relationship with each direct supplier and service provider

The Directive scopes this deliberately at direct suppliers and service providers, which makes the first artefact an inventory of who those parties are and which of them touch the network and information systems behind the service. From there the entity has to manage the security-related aspects of each relationship: what the supplier may access, what securit...

Evidence an auditor accepts: Inventory of direct suppliers and service providers, flagged for access to in-scope systems; Risk assessment per supplier proportionate to the access and criticality involved; Contractual security clauses, including incident notification obligations and audit or assurance rights
Common gap: Inventory built from the procurement system, so shadow and free-tier services are missing
Source framework: NIS2 Directive
NIS2 Art. 21(3) Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

Deciding what supply chain measures are appropriate is not left to general judgement. The entity has to take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of those parties' products and cybersecurity practices including their secure development procedures. Separately, it must take into account...

Evidence an auditor accepts: Per-supplier assessment records that address that supplier's own vulnerabilities and secure development practice; A watch process for Union coordinated supply chain risk assessments and the outputs it has captured; Decision records showing how each relevant coordinated assessment was reflected in supplier measures
Common gap: Supplier assessment reduced to a questionnaire score with no view of that supplier's actual weaknesses
Source framework: NIS2 Directive
NIS2 Art. 24 Use certified ICT products, services and processes where the Member State requires it

A Member State may require essential and important entities to use particular ICT products, ICT services and ICT processes that are certified under a European cybersecurity certification scheme adopted under Article 49 of Regulation (EU) 2019/881, as a way of demonstrating compliance with particular Article 21 requirements. That requirement can arrive either...

Evidence an auditor accepts: A determination of whether any certification requirement applies, per Member State of jurisdiction; Certificates held for ICT products, services or processes where certification is required; The watch process for delegated acts and national requirements, with dated review
Common gap: Assuming no requirement applies without checking each national transposition
Source framework: NIS2 Directive

NIST SP 800-161 Rev 1

Attaches to every supplier, developer, integrator and service provider of a federal system, with the hardest controls on components and on privileged access.

SP 800-161 SR-6 Supplier Assessments and Reviews

Assesses and reviews suppliers, at a depth matched to what they supply and the access they hold.

Evidence an auditor accepts: assessment methodology and tiering by criticality; assessment records per supplier; review cycle evidence
Common gap: all suppliers assessed with the same questionnaire
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-8 Notification Agreements

Establishes agreements requiring suppliers to notify the organization of compromise, vulnerability and relevant change.

Evidence an auditor accepts: notification clauses with defined triggers and timeframes; evidence of notifications received; escalation route when notification fails
Common gap: notification obligation absent or without a timeframe
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SA-4 Acquisition Process

Puts security and supply chain requirements into the contract, including the evidence the supplier must provide.

Evidence an auditor accepts: contract templates carrying security and C-SCRM requirements; evidence of requirements in executed contracts; acceptance criteria tied to those requirements
Common gap: requirements in the template but absent from signed contracts
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-13 Supplier Inventory

A control new in this publication: maintains an inventory of suppliers so that exposure to any one of them can actually be answered.

Evidence an auditor accepts: supplier inventory with the systems and components each supports; criticality attached to each supplier; update procedure on supplier change
Common gap: supplier list held by procurement with no link to systems
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-4 Provenance

Establishes and maintains provenance for systems, components and associated data so origin and change history are known.

Evidence an auditor accepts: provenance records for critical components; evidence of origin and chain of custody; update of provenance as components change
Common gap: provenance known only as far as the reseller
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-9 Tamper Resistance and Detection

Applies tamper resistance and detection to components across development, transport and operation.

Evidence an auditor accepts: tamper resistance and detection measures in use; inspection procedures and records; handling of components found tampered with
Common gap: tamper evidence applied but never inspected on receipt
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-10 Inspection of Systems or Components

Inspects systems and components at defined points to detect tampering, substitution or counterfeit.

Evidence an auditor accepts: inspection procedure and the points at which it applies; inspection records with results; criteria for what constitutes a failed inspection
Common gap: inspection performed only when something looks wrong
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-11 Component Authenticity

Establishes an anti-counterfeit policy and the means to detect and report counterfeit components.

Evidence an auditor accepts: anti-counterfeit policy and procedures; authenticity verification methods used; records of suspected counterfeits and their reporting
Common gap: authenticity assumed because the reseller is authorized
Source framework: NIST SP 800-161 Rev 1
SP 800-161 MA-6 Timely Maintenance

Secures the spares and supplier support needed to restore critical components within the time the organization can tolerate.

Evidence an auditor accepts: spares holdings or supply agreements for critical components; support response commitments and their evidence; criticality analysis driving the requirement
Common gap: support commitments assumed rather than contracted
Source framework: NIST SP 800-161 Rev 1
SP 800-161 SR-12 Component Disposal

Disposes of components so that organizational information and the components themselves cannot re-enter the supply chain uncontrolled.

Evidence an auditor accepts: disposal procedure covering data and physical component; disposal records with serial numbers; controls preventing resale of components carrying organizational identity
Common gap: components sold on with organizational markings intact
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-2 Contingency Plan

Plans for continued operation when a critical supplier, integrator or component source becomes unavailable.

Evidence an auditor accepts: contingency plan with supplier failure scenarios; identification of critical suppliers and single points of failure; alternate sourcing arrangements
Common gap: plan lists systems but not the suppliers that keep them running
Source framework: NIST SP 800-161 Rev 1
SP 800-161 CP-4 Contingency Plan Testing

Tests the supply chain elements of the contingency plan, including whether alternate sources can actually deliver.

Evidence an auditor accepts: test plan including supplier failure scenarios; test results and lessons; evidence alternate sources were contacted or validated
Common gap: alternate supplier named but never approached
Source framework: NIST SP 800-161 Rev 1

ISO/IEC 27001:2022

Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default.

ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: supplier_risk_assessment; contractual_security_requirements; supplier_security_monitoring
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: contract_security_clauses; supplier_risk_assessment; security_incident_reporting
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an auditor accepts: supplier_security_monitoring_reports; supplier_service_review_meetings; supplier_change_management_records
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: supplier_security_requirements; contractual_security_clauses; supply_chain_risk_assessments
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022

Findings this category can raise

Do this for every vendor on your list

Paste the list and get this classification for every vendor at once, with the share of spend and systems, the country it lands in, the criticality, the findings and the obligation rows per regime. Eight vendors free, no account.

Build my vendor register

End-user devices · Power and cooling modules