Supplier Security Services
Supply Chain Cyber Risk Management and SBOM Analysis
We identify, assess and manage the cyber security risks in your supply chain. Our services cover Third-Party Risk Management (TPRM), Software Bill of Materials (SBOM), VEX (Vulnerability Exploitability eXchange) and supplier security auditing.
Service Details
As of 2025, 62% of cyber attacks occur directly or indirectly through the supply chain. High-profile incidents such as SolarWinds Orion (2020), Log4Shell (2021), the 3CX supply chain compromise (2023), the XZ Utils backdoor (2024) and the polyfill.io domain hijack (2024) have shown just how destructive and widespread these attacks can be. CoreDefence Supplier Security Services manage the cyber risk in your supply chain proactively.
Our Third-Party Risk Management (TPRM) programme classifies suppliers as Tier 1/2/3 by criticality and applies the appropriate assessment method to each tier. Automated security questionnaires (SIG Lite, CAIQ), external attack surface scanning, security rating platforms and SOC report analysis continuously monitor your suppliers' security posture. We establish a governance framework that tracks security requirements across the full contract lifecycle.
Our Software Bill of Materials (SBOM) management service inventories every component used in your software projects in CycloneDX and SPDX formats, in line with NTIA minimum SBOM requirements and the EU Cyber Resilience Act (CRA). It continuously scans each component for known vulnerabilities (CVE) against the NVD and OSV databases, evaluates exploit likelihood with EPSS (Exploit Prediction Scoring System) and prioritises actively exploited flaws using the KEV (Known Exploited Vulnerabilities) catalogue.
By producing VEX (Vulnerability Exploitability eXchange) documents we assess whether the vulnerabilities found are genuinely exploitable in your environment, reducing false alarm load. This makes vulnerability management practical and actionable, particularly in large software projects with thousands of dependencies.
Our supplier security audit service reviews the security controls of your critical suppliers on site or remotely against ISO 27001, SOC 2 Type II and sector standards. For cloud SaaS suppliers we perform CSA STAR assessment, API security auditing and data processing agreement (DPA) review. Supplier-originated incident response plans and escalation procedures are also within scope.
Our continuous supplier monitoring programme tracks your suppliers' external attack surface, data leaks, dark web exposures and changes in security scores in real time, presenting them on a risk dashboard. Automated alerts and periodic risk reports make your supply chain risk management proactive.
Our Methodology
What We Offer
Learn More About This Service
Our experts will assess your organisation individually and recommend the solution that fits best.
Contact Us