Home/Documentation/Programme-level documentation
Supply Chain Risk Management Plan
A C-SCRM strategy and implementation plan built on NIST SP 800-161 R1, with supplier tiering, due-diligence questionnaires and contract clauses.
What this set does
NIS2, DORA, 800-171 R3 and ISO 27001:2022 all now require a documented approach to supplier and ICT third-party risk. This plan gives you the strategy, the tiering model, the assessment questionnaire and the contractual controls, so a single process answers all four.
What's inside
- C-SCRM strategy and implementation plan (800-161 structure)
- Supplier tiering and criticality model
- Supplier security questionnaire (short and full forms)
- Contract security clauses and exit-plan requirements
- Supplier register and assessment tracker
- Concentration risk and ICT third-party register (DORA-ready)
Who it is for
Organisations with a growing supplier estate and a regulator or customer asking how it is governed.
How the documents are structured
Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.
Tailoring effort
Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.
Included in these bundles
- NIST CSF 2.0 Governance Bundle — £1,495
- EU Resilience Bundle (NIS2, DORA, GDPR) — £1,595
Licence
One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.
Related products
Policies & Standards — ISO/IEC 27001:2022
A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.
£495 · 41 documentsPolicies & Standards — NIST CSF 2.0
Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.
£445 · 36 documentsPolicies & Standards — NIST SP 800-53 R5 (Moderate)
Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.
£695 · 48 documents