
OT Supply Chain Security & GRC.
Your plant runs on other people's engineering. OEMs, integrators, maintenance contractors, firmware, spares and remote support all reach inside the operational estate. We bring vendor management, supply chain risk and compliance evidence into one place — scaled across the estate, run to a plan, not a spreadsheet.
You can outsource the work. You cannot outsource the consequence.
Vendors
One tiered register of everyone who touches OT — including the ones procurement never saw
Risk
Assessed by what a supplier can reach and stop, not by how much you spend with them
Evidence
Assessments, attestations and remediation held once and reused across every regime
Powered by our supply chain module, delivered in partnership with Ciphrix.
01 · The problem
The riskiest supplier is rarely the biggest one.
Third-party risk programmes rank suppliers by contract value and by the personal data they hold. Neither measure describes an OT estate. The integrator with a £40k support contract holds engineering credentials on a line that makes half your product. The instrument vendor's remote dial-in has been open since commissioning. The firmware in a hundred field devices came from a component maker three tiers down that nobody has a contract with at all.
Meanwhile the questionnaires keep arriving — from regulators, insurers, and your own customers asking you the same questions you are failing to ask your suppliers.
Third-party risk programmes
Tiered by spend, not by reach
A supplier with a small contract and engineering-level access to a production line outranks a large one that only sends invoices. Conventional tiering cannot see that.
We tier by what a supplier can reach and stop.
Procurement & contracts
Clauses written for IT services
Standard security schedules assume cloud software and personal data. They rarely mention firmware provenance, patch commitments, remote access conditions or handover of engineering credentials.
We write OT terms with teeth into the contract.
Site & maintenance teams
Access granted at the point of need
A vendor arrives to fix a line at 2am. Someone gives them what they need and the account, the dial-in or the laptop stays behind long after the job is closed.
We broker access instead of blocking it.
Assurance & audit
Evidence reassembled every time
Attestations expire quietly, questionnaires are answered from memory, and the pack put together for the last audit no longer reflects the estate.
We hold evidence once and keep it live.

02 · Where the risk lives
Eight ways a supplier becomes your incident.
We assess suppliers the way we assess plant: by what they can reach, what they can change, and what stops if they fail. Each of these has caused real industrial downtime — for someone.
Remote access
Standing vendor connections
Cellular routers, jump boxes and support VPNs installed at commissioning, often outside the asset register and always outside the joiners-movers-leavers process.
Brokered, time-boxed, recorded access
Integrators
One engineer, many clients
System integrators carry project files, credentials and laptops between sites. A compromise at the integrator becomes a compromise across their whole customer base.
Assessment, segregation, device conditions
Firmware & components
Provenance you cannot see
Controllers, drives and instruments contain third and fourth tier software. Without an SBOM you learn about a vulnerable component when a researcher publishes it.
SBOM demand & component monitoring
Updates
Trusted delivery channels
Signed updates, engineering software downloads and vendor patch portals are a legitimate route into the OT zone. That is exactly why they are attacked.
Staged validation before plant
Managed services
Concentration in one provider
When monitoring, maintenance and IT are consolidated into a single provider, their bad week becomes your outage across every site simultaneously.
Concentration analysis & exit plans
Spares & logistics
Counterfeit and grey-market parts
Obsolete controllers sourced from resellers arrive with unknown firmware, unknown history and no support path — installed because the line had to run.
Sourcing rules & receipt inspection
Cloud & SaaS
Operational data in someone else’s estate
Historian mirrors, OEM analytics portals and asset performance platforms hold your process data, under terms rarely reviewed by anyone who understands the process.
Data terms, residency, egress limits
People
Contractors treated as staff
Long-term contractors accumulate access across systems and sites, and their offboarding depends on a manager remembering. It is the quietest access-creep of all.
Identity lifecycle for third parties
03 · The module
Vendor management, risk and compliance in one place.
Most organisations run supply chain security across three disconnected systems: a procurement list, a risk register in a spreadsheet, and an audit folder assembled the week before an assessment. Nothing reconciles, and every regulator asks for the same evidence in a different shape.
Our supply chain module — delivered in partnership with Ciphrix — puts the register, the assessments, the continuous monitoring and the compliance mapping on one platform. We bring the OT engineering judgement; the platform carries the scale, the automation and the audit trail. Onboarding a supplier takes hours instead of weeks, and the evidence is current on the day someone asks for it.
One register · one risk view · one evidence set
From ten suppliers to a thousand
Templated assessments by tier, reusable evidence and automated re-review dates mean the model holds as you extend it from one site to the whole estate.
Assessment in hours, not procurement cycles
Structured questionnaires, external monitoring signals and pre-mapped controls remove most of the manual chase. Engineers spend their time on the findings that matter.
A roadmap, not a rolling backlog
Tiering first, critical suppliers next, contract and monitoring last — with each phase scoped, dated and owned so the programme survives contact with day-to-day operations.
04 · What we do
Eight workstreams, from supplier discovery to contract teeth.
Delivered as a whole or picked individually. Each one produces something operable — a register, a control, a tested finding — not a policy document.
05 · How we run it
Tiered first, so effort lands where it matters.
- Weeks 1–2
Discover and tier
Interviews, procurement extracts, network evidence and site walkdowns to build the real supplier picture. Output is a tiered register and the top exposures.
- Weeks 3–6
Assess the critical few
Deep assessment of the suppliers that can reach or stop the process, with technical review of their access rather than reliance on their answers.
- Weeks 7–12
Fix and formalise
Revoke what should not exist, broker what should, uplift contracts at the next renewal point, and stand up the module as the single register.
- Ongoing
Run it, or hand it over
We can operate the review cycle as a managed service, or train and hand it to your team — engineered by us, owned by you.
Scalable · fast · planned
06 · Compliance lens
Every regime now asks about your suppliers.
Supply chain security stopped being a procurement preference and became a statutory duty. Assembled once, in the right structure, the same evidence answers most of them — and answers your customers' questionnaires too.
NIS2
Supply chain security is an explicit duty for essential and important entities, with management accountable personally for the measures taken.
Supplier register, assessments, board reporting
NCSC CAF
Supply chain outcomes require you to understand and manage the risk from third parties with access to your essential function.
Access map, tiering rationale, control evidence
IEC 62443-2-4 & -4-1
Defines what you should require of service providers and product suppliers — the most useful yardstick when assessing an integrator or an OEM.
Capability assessments, gap findings
EU Cyber Resilience Act
Product makers face vulnerability handling and SBOM duties. As a buyer it gives you something concrete to ask for, and a date to ask by.
SBOM register, vendor commitments
ISO 27001 & 28000
Supplier relationship controls and supply chain security management — useful when a customer or insurer wants certifiable process rather than assurance by assertion.
Policy set, control mapping, audit trail
Customers & insurers
Your own customers now audit your supply chain, and cover renewals ask how third-party access to operations is controlled.
Answer pack, attestation library
The same register also works in the other direction. When your customers audit you, the answers to their supply chain questions are already assembled, evidenced and in date.

07 · Deliverables
What you are left holding.

08 · Why Nuvantiq
Assessing an OT supplier needs someone who knows what they actually do on site.
01
We know what the supplier does on site
Our engineers have been the integrator and the vendor. We can tell whether a claimed control is real practice or a paragraph written by their marketing team.
02
Platform and judgement together
The module carries the scale, automation and evidence; our people carry the OT engineering call. Neither works properly without the other.
03
We keep the plant running
Cutting vendor access is easy until a line stops. We design brokered access that still lets support happen at 2am on a Sunday.
04
Engineered by us, owned by you
The register, the process and the platform are yours. We build them to be run by your team, and hand over properly when they are ready.
For the CISO & risk lead
You need to name every third party with a route into OT, know what each can reach, and show a regulator that the register is live rather than reconstructed. That is what this pillar produces, and it stays current between audits.
For procurement & commercial
Security clauses only work if someone can tell you which suppliers matter and what to demand of each. We tier the base, write the OT-specific requirements into the contract, and make renewal the moment evidence is refreshed.
For operations & engineering
You need the contractor on site on Monday. We are not here to stop that — we are here to make access brokered, logged and time-boxed so that support still works and nobody has a standing key to the plant.

Start with one site
Know who can reach your plant — before someone else finds out.
Start with a supplier discovery and tiering across one site. Within a fortnight you will have the register, the top ten exposures and a costed plan for the rest.
Or email Info@nuvantiq.com.

