Cyber Security
Essential Cyber Due Diligence for UK Tech Buyers: Navigating Supply Chain Security Risks
For UK businesses procuring software, automation, or design services, understanding and mitigating cybersecurity risks from third-party suppliers is critical. This guide, aligned with NCSC principles, outlines key due diligence steps from initial assessment to

The short answer
UK businesses procuring software and digital services can effectively assess and manage cybersecurity risks from third-party suppliers by adopting a structured due diligence process, heavily informed by the National Cyber Security Centre (NCSC) guidance. This involves understanding your own risk posture, developing a consistent supplier assessment approach, embedding security practices throughout the contract lifecycle, and continuously improving. Key measures include requiring suppliers to demonstrate adherence to standards like Cyber Essentials, assessing their incident response capabilities, and considering advanced certifications like ISO 27001. Company directors hold legal responsibility for cybersecurity, making robust protection essential for both compliance and resilience.
The Growing Imperative of Digital Supply Chain Cyber Security
Cyber attacks increasingly target organisations through vulnerabilities in their supply chains, rather than directly attacking their own systems. This trend highlights a critical shift in the threat landscape, where a compromise in a third-party supplier can have devastating consequences for multiple downstream organisations. Notable incidents such as NotPetya, SolarWinds, and MOVEit have underscored the far-reaching impact of breaches originating from commercial software or open-source components that form part of a broader digital supply chain.12
Despite the escalating risks, UK government data reveals a low rate of businesses actively reviewing the cyber security risks posed by their immediate suppliers, with only 13% doing so, and an even lower 7% examining risks from their wider supply chain. This oversight is particularly concerning given that company directors in the UK bear legal responsibility for ensuring robust cybersecurity. Therefore, establishing comprehensive protection is not merely a technical concern but an essential legal and operational imperative for business continuity and trust.34
The NCSC Framework: A Foundation for UK Businesses
The National Cyber Security Centre (NCSC) provides invaluable guidance tailored for UK organisations to enhance their supply chain security. Recognising supply chain security as a critical 'future threat challenge', the NCSC published extensive advisory to help organisations assess and build confidence in their supply chain's cybersecurity posture. This guidance serves as a foundational resource for developing a practitioner-led method to manage these complex risks effectively.56
Central to the NCSC's approach are 12 supply chain security principles. These principles advocate for a methodical strategy that begins with understanding inherent risks, progresses to establishing clear control mechanisms, verifying adherence to security arrangements, and culminates in a commitment to continuous improvement. By following this comprehensive framework, UK businesses can systematically build resilience against supply chain threats.78
Key Stages of Cyber Due Diligence: An NCSC-Aligned Approach
Effective cyber due diligence begins before engaging a new supplier. Businesses must first deeply understand their own cyber security risk management, identify critical assets requiring protection, and anticipate potential attack paths. Crucially, determining the key stakeholders—such as procurement, legal, and IT teams—who will be involved in supply chain cyber security decisions is an essential preliminary step. This initial introspection forms the bedrock for a robust assessment strategy.9
Developing a consistent and repeatable approach to assess supplier cyber security is vital. This involves defining ideal security controls, establishing clear procedures for handling non-compliance, and considering commercial tools that can help reconcile supplier information across various tiers and provide ongoing monitoring beyond the initial assessment. As new supplier relationships are forged, these refined security practices must be embedded throughout the entire contract lifecycle, from initial procurement through to contract closure. Suppliers should be required to demonstrate adherence to specified security standards, with contractual agreements explicitly outlining mutual responsibilities. Additionally, ensuring that personnel involved in assessing suppliers receive adequate training is paramount.1011
For existing supplier relationships, particularly those deemed critical, a review of current contracts is necessary to integrate enhanced security controls. Information gathered should be retrofitted into a centralised repository, and standard contract clauses updated to reflect current best practices. Finally, cyber due diligence is not a one-off task; it demands continuous improvement. Organisations must regularly refine their approach in response to emerging threats, track external vulnerabilities, and collaborate with suppliers to evaluate the ongoing effectiveness of their security posture. This iterative process ensures long-term resilience.1012
Leveraging Cyber Essentials for Baseline Assurance
Cyber Essentials (CE), a UK government-backed scheme developed by the NCSC, represents a fundamental baseline of technical cyber security controls for organisations of all sizes. By focusing on five core technical areas—secure configuration, boundary firewalls and internet gateways, access control, patch management, and malware protection—CE helps businesses defend against approximately 80% of common cyber-attacks. This makes it an invaluable first step for any organisation seeking to bolster its digital defences and demonstrate a commitment to security.1314
For suppliers bidding for certain public sector contracts in the UK, Cyber Essentials certification is mandatory, particularly for those handling personal information or providing higher-risk IT services, as stipulated by the UK government’s Procurement Policy Note (PPN) 01/24 (updated February 2025). Beyond public procurement, the NCSC actively encourages all organisations to mandate CE certification from their suppliers. This requirement significantly enhances overall supply chain security by ensuring a consistent, recognised minimum standard across partners. Furthermore, businesses with an annual turnover under £20 million that achieve CE certification may also qualify for free cyber-liability insurance, including critical incident response support.151617
Beyond the Basics: Advanced Cyber Due Diligence Considerations
While Cyber Essentials provides a strong foundation, additional certifications such as ISO 27001 can offer further assurance during due diligence. ISO 27001 demonstrates a supplier's commitment to a comprehensive Information Security Management System (ISMS), establishing clear agreements on information security responsibilities. Beyond certifications, due diligence must extend to assessing a supplier's incident response capabilities, with contractual terms explicitly outlining how cyber events will be reported and managed between all parties involved. This proactive planning is crucial for minimising damage and maintaining trust during a breach.1819
UK directors have clear legal responsibilities for cyber security. Ensuring robust cyber protection is essential not only for handling sensitive personal and commercial information but also for adhering to evolving legislative landscapes. The forthcoming Cyber Security and Resilience Bill, expected to receive Royal Assent between 2026-2027, is anticipated to extend obligations down the supply chain, indirectly impacting many SMEs through their customer contracts. For organisations seeking comprehensive third-party risk management, specialised software solutions like OneTrust, Venminder, and AuditBoard offer advanced features for centralised inventory, automated risk mitigation, and continuous compliance tracking, moving beyond manual processes to ensure ongoing vigilance.420
Sources
- Supply Chain Security: The NCSC’s 12 Principles and Why They Matter RiskIQ
- NCSC Releases Supply Chain Cybersecurity Guidance Infosecurity Magazine
- Cyber security breaches survey 2023 - Department for Science, Innovation and Technology GOV.UK
- UK company directors face legal responsibility for cyber security and resilience The Cyber Resilience Centre for London
- NCSC Annual Review 2022 - NCSC.GOV.UK NCSC
- How to assess and gain confidence in your supply chain cyber security - NCSC.GOV.UK NCSC
- NCSC 12 Supply Chain Security Principles BlockAPT
- Understanding the NCSC's 12 Supply Chain Security Principles IASME
- How to Assess and Gain Confidence in Your Supply Chain Cyber Security NCSC
- NCSC Supply Chain Guidance Summary - Assured Business Assured Business
- How to secure your supply chain – NCSC blog NCSC
- Supply Chain Cyber Security: How to Protect Your Business From Supply Chain Attacks Kroll
- About Cyber Essentials - NCSC.GOV.UK NCSC
- The five technical controls - NCSC.GOV.UK NCSC
- Procurement Policy Note 01/24 - GOV.UK GOV.UK
- Is Cyber Essentials mandatory for government suppliers? - Cyber Smart Cyber Smart
- Cyber Essentials Benefits - QMS International QMS International
- ISO 27001 and Cyber Essentials - NCSC.GOV.UK NCSC
- The importance of incident response plans and why you need one Secureworks
- What is Third-Party Risk Management (TPRM)? - OneTrust OneTrust
Sources last checked 20 September 2026.
