Third-party and supply-chain security
Security requirements for suppliers, ICT third-party risk under DORA, and product security under the Cyber Resilience Act.
Supply-chain security runs in two directions. As a buyer, an organisation must know which suppliers can reach its systems and data, and NIS2 and DORA both require that this risk is managed. We build supplier classification, contract clauses, assessment processes and the register of information that DORA requires for ICT third-party arrangements.
As a manufacturer, an organisation may itself be the supplier. The EU Cyber Resilience Act sets security requirements for products with digital elements. Its reporting obligations for actively exploited vulnerabilities have applied since 11 September 2026, and its main requirements apply from 11 December 2027. We help product teams set up vulnerability handling, software bills of materials and the technical documentation needed for conformity.
Typical deliverables
- Supplier risk classification and assessment process
- Security clauses for ICT contracts and the DORA register of information
- Cyber Resilience Act applicability and gap assessment for product lines
- Vulnerability handling and SBOM process for product security teams

Talk to us about your security priorities
Tell us about your organisation, the regulations that apply to you and what you need to achieve, and we will come back to you to arrange a confidential first call. Email contact@alpwacht.com. If you are dealing with an active incident, say so in the subject line.
contact@alpwacht.com