Regulation can make suppliers part of your compliance system
Once a regulation reaches your supply chain, your suppliers' controls become part of what you are assessed on.
That changes procurement, contracts and ongoing oversight into compliance activities rather than commercial ones. It also means a supplier's inability to evidence something becomes your finding, which is a conversation better had before signing than during an audit.
More on Regulation and law
- Regulatory scope is a security architecture questionThe rope follows the wire
- Incident reporting deadlines change response prioritiesThe clock starts with the incident
- DORA makes ICT third-party resilience a contractual and oversight responsibility for regulated financial entitiesThe work moves, the answering stays
- Under NIS2, an organisation's sector, size and role can determine whether cybersecurity risk-management and reporting duties applyThree flaps, one outcome
- Breach notification and incident notification are different testsTwo holes, two different shapes
- Legal privilege does not make incident facts disappearIt seals the advice, not the facts
