Supplier Standards
A supplier is evaluated on fit, control and evidence—not a logo or certification badge alone.
This is a public review draft. It is not an offer or an operative agreement; signed service terms and approved schedules prevail.
Due diligence
Assess ownership, security architecture, operational resilience, support, data locations, subcontracting, vulnerability handling and exit options in proportion to the customer's risk. Verify claims against the named legal entity, product and certification scope.
Contract and data
Define security and incident duties, audit evidence, access, change notification and exit in the contract. Where a supplier processes personal data, apply Article 28 GDPR and relevant transfer safeguards. NIS2 supply-chain measures and DORA contractual provisions are assessed when the customer and service are in scope.
Ongoing review
Revisit material supplier changes, incidents and dependency concentration. Significant findings should lead to a documented risk decision, remediation or alternative supplier. No supplier is represented as pre-approved merely by appearing on this site.