Supplier review should be risk based. A low-impact utility package does not need the same depth of assessment as a security-critical cryptographic module, identity component or remote-management subsystem, but every dependency should have enough evidence for its risk profile.
Start With Component Criticality
Assess the security importance of the component before deciding how deeply to review its supplier. Consider privileges, network exposure, data handled, update path, replaceability and the consequences of supplier failure.
Verify Component Identity and Provenance
Confirm what product or package the supplier is providing, how releases are identified and how the manufacturer can verify that the component received is the expected one. Ambiguous provenance weakens both SBOM accuracy and vulnerability response.
Review Vulnerability Disclosure and Response
Check whether the supplier has a monitored security contact, a vulnerability disclosure process, a history of advisories and a defined route for notifying customers of affected versions and fixes.
Assess Security-Update Capability
Review how security patches are created, tested, distributed and supported. Critical suppliers should be able to provide timely information that lets the manufacturer assess and remediate finished-product impact.
Check Support and End-of-Life Commitments
Understand how long the supplier plans to support the component and what happens when support ends. This is particularly important where replacement would require major redesign or conformity work.
Request Evidence Proportionate to Risk
Useful evidence can include security development practices, testing summaries, conformity information where applicable, component inventories, advisories, support policies and architecture documentation. Avoid collecting large questionnaires that are never evaluated.
Assess Change-Control Communication
Suppliers should provide enough notice of security-relevant component, dependency, firmware or manufacturing changes for the product manufacturer to reassess risk and update its evidence.
Make Supplier Assessment Ongoing
Reassess critical suppliers when major vulnerabilities, ownership changes, support changes, quality failures or material product changes occur. CRA supply-chain due diligence should remain active during the product lifecycle.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.