Skip to main content
M516 Cyber Solutions

Digital Supply Chain Cyber Risk

Cyber Governance, Procurement & Controls Mapping

Build security controls into contracts before they're signed.

What this is

Build security controls into contracts before they're signed.

We embed cyber risk into procurement and supplier management so requirements, controls and evidence expectations are agreed at onboarding rather than negotiated after an incident.

What you get

  • Supplier classification model and risk-tiering criteria
  • Security requirements and control clauses for procurement
  • Controls mapped to your frameworks and control owners
  • Onboarding and offboarding governance steps

Best for

Teams where procurement and security currently operate independently.

See how an engagement runs →

Benchmarked Against

  • NIST Cybersecurity Framework (CSF) 2.0
  • NIST SP 800-161
  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • ISO/IEC 27036
  • ISO/IEC 27701
  • ISO/IEC 42001 (AI management systems)
  • ISO 22301 (business continuity)
  • NIS2 Directive
  • DORA (where applicable)
  • UK GDPR & Data Protection Act 2018
  • NCSC Cyber Assessment Framework (CAF)
  • Cyber Essentials / Cyber Essentials Plus
  • CIS Controls
  • SOC 2 (Trust Services Criteria)

Talk to us about scoping this service.

A short, no-obligation discovery call to understand your risk profile and where to start.