Home/Documentation/Programme-level documentation

Supply Chain Risk Management Plan

A C-SCRM strategy and implementation plan built on NIST SP 800-161 R1, with supplier tiering, due-diligence questionnaires and contract clauses.

What this set does

NIS2, DORA, 800-171 R3 and ISO 27001:2022 all now require a documented approach to supplier and ICT third-party risk. This plan gives you the strategy, the tiering model, the assessment questionnaire and the contractual controls, so a single process answers all four.

What's inside

  • C-SCRM strategy and implementation plan (800-161 structure)
  • Supplier tiering and criticality model
  • Supplier security questionnaire (short and full forms)
  • Contract security clauses and exit-plan requirements
  • Supplier register and assessment tracker
  • Concentration risk and ICT third-party register (DORA-ready)

Who it is for

Organisations with a growing supplier estate and a regulator or customer asking how it is governed.

How the documents are structured

Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.

Tailoring effort

Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.

Included in these bundles

Licence

One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.

Related products

Policies & Standards — ISO/IEC 27001:2022

A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.

£495 · 41 documents

Policies & Standards — NIST CSF 2.0

Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.

£445 · 36 documents

Policies & Standards — NIST SP 800-53 R5 (Moderate)

Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.

£695 · 48 documents