Ask only questions that feed product decisions. Link supplier answers to the component and product that depend on them, validate high-risk claims with evidence, and flag missing security contacts, unsupported components, weak vulnerability processes or unclear update commitments. Supplier assurance is an input to the manufacturer's cybersecurity risk assessment and vulnerability handling, not a substitute for them.
Identify the Supplier, Component and Product Relationship
Start with the legal supplier or maintainer, component name, version, licensing model and the manufacturer products that integrate it. A questionnaire that is not tied to a specific component is difficult to use in product risk and vulnerability work.
Ask About Secure Development Practices
Collect information about security design, code review, testing, dependency management, release controls and change management that is relevant to the supplied component. The manufacturer should use the answers to inform product risk rather than scoring the supplier in isolation.
Ask for a Monitored Vulnerability Contact
The manufacturer may need to communicate quickly when a vulnerability is identified in an integrated component. Record the supplier's monitored security contact, escalation path and expected response process.
Ask How Vulnerabilities Are Received and Remediated
Ask how the supplier validates reports, prioritises remediation, coordinates disclosure, tests fixes and communicates security updates. Request evidence or policy references for critical components instead of relying only on yes-or-no answers.
Ask for Component and Dependency Information
Where useful, ask whether the supplier can provide SBOM or dependency information, component identifiers and release-linked versions. This can improve the manufacturer's own SBOM quality and speed up vulnerability matching.
Ask About Security Update Delivery
Record how updates are authenticated, distributed and communicated, how quickly critical fixes can be released and whether the supplier supports older versions. These facts can affect the manufacturer's own vulnerability-handling and support commitments.
Ask About Support Commitments and End-of-Support
The supplier's support period is not automatically the finished product's CRA support period. Still, unsupported dependencies can create manufacturer risk. Record support timelines, end-of-support notice periods and options for extended support or replacement.
Ask About Known Security Limitations and Open Vulnerabilities
Request information about known unresolved vulnerabilities, compensating controls, security advisories and relevant product limitations. High-risk or unsupported issues should feed the manufacturer's Article 13 cybersecurity risk assessment.
Ask About Incident and Exploitation Notification
Define how the supplier will notify the manufacturer of active exploitation, severe security events or urgent vulnerability information affecting the component. Fast upstream communication can be essential because Article 14 deadlines run from the manufacturer's awareness.
Validate Critical Responses With Evidence
For higher-risk components, request policy documents, test reports, certification evidence, SBOM extracts, support statements or other records that support the supplier's answers. Supplier declarations should be treated as evidence inputs, not unquestioned proof.
Feed Supplier Answers Into Product Risk and Documentation
Store the questionnaire with the component record and link important answers to the product cybersecurity risk assessment, SBOM, vulnerability process and technical documentation. This prevents procurement evidence from becoming disconnected from the product it is meant to support.
Reassess Suppliers When Components or Support Change
Trigger review when the component changes materially, the supplier changes ownership or support terms, serious vulnerabilities emerge, security contacts fail or a previously supported version approaches end of support. Due diligence should remain current enough to support ongoing product decisions.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.