Skip to main content
[EN] Cyber Security - Supplier Self Assessment
Lakshmi avatar
Written by Lakshmi
Updated this week

Supplier Self Assessment

Cyber Security

  1. Does your organisation have a relevant cyber security certification (e.g. ISO 27001)?

  2. Does your organisation have a formal cyber security policy?

  3. Are the organisation's security policies and procedures reviewed and updated at least annually?

  4. When were they last updated?

  5. Please briefly describe which areas are addressed within your cyber security policy

  6. Does your organisation have established procedures and technical, operational and organisational measures to secure your organisation's cyber security by avoiding disruptions and minimising the impact of security incidents?

  7. Has your organisation gone through cyber security audits, assessments and inspections?

  8. Please upload the results of these cyber security audits and assessments taking account of potential "need-to-know" content and making sure business secrecy is preserved

  9. Does your organisation have a responsible person or team for cyber security within your organisation?

  10. Does your organisation use security softwares to protect your systems?

  11. Are your systems and software updated regularly?

  12. How often are your systems and software updated?

  13. Does your organisation enforce access controls and permissions to ensure the protection of sensitive data?

  14. Does your organisation have a backup and recovery plan in place?

  15. Does your organisation perform simulations of failures?

  16. Are employees regularly trained regarding cyber security?

  17. How often are employees trained?

  18. Does your organisation regularly conduct penetration tests to identify possible security vulnerabilities and to check security measures?

  19. Does your organisation have an incident response plan in place for handling cyber security incidents?

  20. Does your organisation have a plan for reporting an incident to relevant authorities and how to do so?

  21. Has your organisation experienced a cybersecurity incident in the past 12 months?

  22. Does your organisation have a process to learn and improve from experienced cyber security incidents?

  23. Does your organisation manufacture, distribute or import products with digital elements (e.g., IoT products)?

  24. Does your organisation design, develop and manufacture the products with digital elements to ensure an appropriate level of cyber security?

  25. Is an adequate level of cybersecurity guaranteed in the development, testing, manufacturing and production of products with digital elements?

  26. How is this level of cybersecurity defined?

  27. Will your product have a declaration of conformity for the Cyber Resilience Act available?

  28. Does your organisation or your suppliers offer cyber security updates for the products with digital elements?

  29. For what periods? What is your update policy (e.g. only the current version receives a cybersecurity update and can be obtained free of charge for updates)?

  30. Does your organization have a plan to report vulnerabilities or cybersecurity incidents related to products with digital elements?

  31. Do you have a central point of contact so that possible cybersecurity-relevant errors in your products can be reported to you?

  32. What is your desired response time?

Did this answer your question?