Skip to main content

      A significant proportion of cybersecurity risks can be attributed to third parties within your supply chain. Furthermore, geopolitical developments and threats from cybercriminals are making your supply chain more vulnerable to disruptions than ever before. Consequently, an increasing number of regulations, such as NIS-2 or DORA, are calling for an efficient C-SCRM framework. Targeted management of risks across your entire supply chain is key to staying ahead of the competition. We support you in making the risks along your supply chain transparent and in meeting regulatory requirements.

      KPMG approach

      To provide a comprehensive overview of our C-SCRM approach, the key work packages have been summarised in a structured format. Each package helps to improve your company’s security posture and demonstrates how our holistic approach aims to overcome the challenges encountered throughout your supply chain.



      KPMG Overview of C-SCRM Services

      C-SCRM-Framework Maturity Assessment

      KPMG offers a comprehensive maturity assessment that evaluates the maturity level of your organisation’s cyber supply chain risk management framework (including procurement and risk management departments). Risks are identified within existing processes, roles and technologies to ensure that your service providers are managed effectively. Working with you, we draw up a roadmap aimed at optimising your C-SCRM, bringing it up to industry standards and ensuring compliance with regulatory requirements.

      Implementation of your C-SCRM framework

      Based on the roadmap developed in the previous step, it is crucial to implement the identified measures in order to minimise risks and meet industry standards, as well as ensure compliance with NIS 2, DORA and ISO 27001. This involves implementing specific processes and technical measures relating to C-SCRM.

      C-SCRM-Framework Maturity Assessment

      KPMG bietet ein umfassendes Maturity Assessment, das den Reifegrad des Cyber Supply Chain Risk Management Frameworks Ihres Unternehmens (u.a. Procurement-, Risikomanagementabteilungen) erhebt. Risiken werden in den bestehenden Prozessen, Rollen und Technologien identifiziert, um sicherzustellen, dass Ihre Dienstleister effektiv gemanagt werden. Gemeinsam mit Ihnen wird eine Roadmap erstellt, die darauf abzielt, Ihr C-SCRM zu optimieren, auf Branchenstandards zu heben und Compliance-Anforderungen zu erfüllen.


      Your company will be supported in creating a structured record of all your service providers involved in critical business processes, in order to ensure transparency regarding external partners. On this basis, a risk score is calculated using key factors relating to your service providers, such as financial stability, compliance history and operational risks. Furthermore, the methodology is tailored to your company’s specific needs, and you are guided through the entire risk scoring process. This ensures a bespoke scoring system and prioritisation of your most important service providers (key suppliers).

      Our experts will carry out an initial review of your contracts to ensure that all your contractual agreements with your service providers comply with both your company’s specific requirements and industry-wide and compliance standards. In doing so, business continuity requirements and Key Performance Indicators (KPIs) are incorporated into contracts and Service Level Agreements (SLAs) to enable clear and measurable reporting. You can also benefit from control mechanisms that ensure continuous monitoring and adaptation of contracts to new challenges and regulatory changes.

      KPMG supports your organisation in creating questionnaires specifically designed for third-party security assessments. These questionnaires are designed to help you comply with standards such as ISO 27001, NIST, SOC 2, IT-Grundschutz or PCI-DSS.

      We offer comprehensive support in coordinating and conducting cybersecurity assessments with your service providers, ensuring that you meet your organisation’s requirements. Our process includes the planning and implementation of cybersecurity assessments, the analysis of the current status of cybersecurity measures, the detailed review and validation of the documentation provided, and the preparation of a comprehensive final report listing identified risks and, where appropriate, recommending risk mitigation measures. Through regular and systematic reviews, we help to identify potential risks at an early stage and implement targeted risk mitigation measures.

      Effective incident management and business continuity management (BCM) within the framework of C-SCRMs are crucial for preparing organisations for security incidents affecting their service providers. Our approach involves establishing a structured process for reporting (communication channels) and handling (potential) security incidents via defined communication channels. In addition, contingency plans are developed and implemented jointly to help maintain critical business processes even in crisis situations.

      As part of the C-SCRM, we offer one-off or regular training sessions aimed at both internal staff (your employees and managers) and external parties (your external service providers). These training sessions are supplemented by jointly developed materials designed to effectively impart knowledge and skills and to support participants at every stage of the C-SCRM.

      KPMG offers you the unique advantage of supporting you in establishing or optimising your processes directly as you implement the GRC tool that best suits your needs. Thanks to our strong partnerships with leading providers (e.g. ServiceNow), we can help you realise the full potential of these tools in terms of efficiency, automation and innovation.

      KPMG’s C-SCRM Managed Services are designed to monitor your day-to-day operational and risk management tasks. This enables your organisation to reduce the additional workload involved in monitoring your supply chain and to focus on what matters most: optimising your supply chain and selecting the best suppliers. Our modular, subscription-based offering utilises cutting-edge technologies and the in-depth expertise of our experienced specialists to refine your C-SCRM processes using a unique, proprietary methodology. This enables you to minimise risks and ensure that your C-SCRM challenges are resolved in a consistent, efficient and cost-effective manner.

      The benefits for you

      • Insights into the current maturity level of cyber supply chain risk management and recommended actions.
      • Establishing sustainable governance structures for the implementation and management of compliance requirements.
      • Improving transparency through clear communication and disclosure of third-party security practices.
      • Identifying and mitigating potential risks posed by third parties to avoid financial losses and reputational damage.
      • Strengthening resilience to unexpected incidents involving third-party providers.

      More interesting content for you

      Your contacts