NIST C-SCRM Key Practice 3: Know and Manage Critical Suppliers

April 6th, 2021 Jackie Risley Reading Time: 3 minutes
Know & Manage Critical Suppliers (NIST C-SCRM)

The global pandemic has underscored the need to understand risk associated with critical third parties in your cyber supply chain as they can bring your business to a halt or at least have a major negative impact. So it’s no wonder that the National Institute of Standards and Technology (NIST) listed “Know and Manage Critical Suppliers” as one of its “Key Practices in Cyber Supply Chain Risk Management: Observations from Industry.” Unfortunately, this advice can be hard to put into practice, especially for organizations trying to manage cyber supply chain risk using manual or disparate systems.

Aravo’s 2020 benchmarking research found that 25% of survey respondents didn’t know what percentage of their third parties would be categorized as critical. And fewer than one-third felt they could report on critical third parties quickly and completely. Not having access to data related to critical vendors exposes organizations to serious risk and limits the ability to create effective business continuity and organizational resilience plans.

This is the third in a series of Aravo blogs exploring NIST’s Key Practices. Previous installments focused on integrating C-SCRM across the organization and establishing a formal C-SCRM program.

Defining Supplier Criticality

A critical supplier is a third party whose failure or disruption would significantly impair your operations, revenue, or compliance.

Before you can leverage technology to identify critical suppliers, the first step is to identify what criteria is used to define a critical supplier. Beyond a complete inability to function if they were disrupted, critical supplier designation can be based on multiple factors, such as amount of spend, volume or sensitivity of data processed, or ability to act as a threat vector. The NIST guidance includes links to additional resources that can help you determine the criteria that is most appropriate for your organization.

In Aravo industry research, organizations that are able to track supplier criticality typically report that about 10% of their third of their suppliers are categorized as critical. However, there is no universal heuristic for how many suppliers should be considered critical. That decision will be driven by the nature of your business and your supplier ecosystem.

How Technology Supports Critical Supplier Management

Even with perfectly defined criteria, trying to identify and tier suppliers using spreadsheets can be complicated and prone to error. To streamline this process and reduce exposure, you’ll want to choose technology that can:

  • Systematically identify critical suppliers during the onboarding and assessment processes by applying your criteria. The system should be able to apply business rules and logic easily configured to reflect your organization’s priorities.
  • Automatically conduct a level of due diligence aligned to the criticality and risk profile of the supplier. The system should be able to require suppliers with the highest combination of criticality and risk to undergo more detailed assessment processes and, when needed, meet risk mitigation requirements.
  • Proactively alert you to events that could threaten the continuity of supply (e.g. weather, geo-political events, biohazards) and generate business impact assessments for critical suppliers. The system should include a complete workflow for evaluating the hazard and conducting any additional activities required to mitigate the risk.
  • Identify alternate sources of supply within your cyber supplier base and/or facilitate RFP/RFI solicitation. In a crisis, your competitors will likely also be looking to backfill suppliers, so it’s crucial to act quickly to avoid delays.
  • Monitor contractual terms throughout the life cycle of the relationship. Typically based on master specifications that take supplier criticality into account, these contractual terms should be subject to performance management that accounts for qualitative and quantitative evaluation.
  • Trigger escalation processes appropriate to the situation as needed, ranging from logging a case and resolving the issue via intelligent automation to termination and off-boarding. Data that signals non-compliance can include performance management feedback, changes in risk scores related to security (such as those from BitSight or Security Scorecard), adverse media (e.g. reports of a breach), or an issue that is self-reported logged by a user.
  • Provide feedback to the contracting team responsible for negotiating contracts to refine terms and conditions. A C-SCRM team should be able to identify additional risk dimensions for that particular kind of supplier, as well as monitor the performance of and compliance to the established contract terms.

Check out the other installments of this blog series to explore the rest of NIST’s Key Practices. The complete list includes:

1. Integrate C-SCRM Across the Organization
2. Establish a Formal C-SCRM Program
3. Know and Manage Critical Suppliers
4. Understand the Organization’s Supply Chain
5. Closely Collaborate with Key Suppliers
6. Include Key Suppliers in Resilience and Improvement Activities
7. Assess and Monitor Throughout the Supplier Relationship
8. Plan for the Full Life Cycle

Frequently Asked Questions

Why is it important for businesses to identify their critical suppliers?

Identifying critical suppliers is crucial for preventing business disruption and mitigating major negative impacts from third-party risks. It enables organizations to develop effective business continuity and resilience plans, safeguarding against potential cyber supply chain failures and ensuring operational stability.

How do organizations typically define a critical supplier?

Organizations define critical suppliers based on various factors, including the potential for business disruption if the supplier fails, the amount of spend, the volume or sensitivity of data processed, and their ability to act as a threat vector within the cyber supply chain.

What criteria should I use to classify a supplier as critical?

To classify critical suppliers, consider if their disruption would halt your business operations, the volume and sensitivity of data they handle, and their potential as a cybersecurity threat vector. Align your criteria with your organization’s specific business model and risk appetite.

What percentage of a company's total suppliers are usually considered critical?

While there’s no universal rule, organizations often categorize approximately 10% of their third-party suppliers as critical. This percentage varies significantly based on the specific nature of the business, its operational dependencies, and its unique supplier ecosystem.

How can technology help streamline critical supplier identification and management?

Technology can systematically identify critical suppliers by applying defined criteria, automate due diligence based on risk, and proactively alert to continuity threats. It also helps monitor contractual terms and triggers escalation processes for non-compliance or adverse events.

What are the biggest risks of not knowing your critical suppliers?

Not knowing critical suppliers exposes an organization to serious risks, including widespread business disruption, significant financial losses, and regulatory non-compliance. It also severely limits the ability to create and execute effective business continuity and organizational resilience plans during a crisis.

How often should a company re-evaluate its critical supplier designations?

Supplier criticality should be re-evaluated periodically, such as annually or biennially, and whenever there are significant changes to the supplier’s services, the contractual terms, or the organization’s business needs. This ensures designations remain accurate and relevant.

Jackie Risley

Head of Product Marketing at Varis

Jackie serves as the Head of Product Marketing at Varis.  Previously she spent 3 years serving as Senior Director of Product Marketing for Aravo partnering with customers and prospects to architect their TPRM solution to build value and mature their program. Jackie has held marketing leadership position at Nomis Solutions, Upland Software, ABBYY USA and Hyland Software.

Head of Product Marketing at Varis

Jackie serves as the Head of Product Marketing at Varis.  Previously she spent 3 years serving as Senior Director of Product Marketing for Aravo partnering with customers and prospects to architect their TPRM solution to build value and mature their program. Jackie has held marketing leadership position at Nomis Solutions, Upland Software, ABBYY USA and Hyland Software.

Share with Your Friends:

Subscribe to Blog Updates

Tags