Sort your suppliers into three tiers by what they can reach, then only do real diligence on the top tier. That is the part most small businesses get backwards: they send the same forty-question spreadsheet to the payroll platform and the office plant supplier, get bored halfway through, and end up with a folder of unread answers. Twelve questions asked of the five vendors that genuinely hold your data will protect you better than forty questions asked of everyone.

Where third-party risk actually bites
Verizon’s 2026 Data Breach Investigations Report analysed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries. Third-party involvement appeared in 48% of breaches, up 60% year on year. That is the headline number, and it is worth being precise about what it means: it does not say half of breaches are your supplier’s fault. It says that in about half of breaches, a party other than the victim organisation was part of the chain, whether that was a compromised software update, a managed service provider’s credentials, or a hosting platform.
The same report found something related and more uncomfortable. For the first time in nineteen editions, exploitation of software vulnerabilities overtook stolen credentials as the leading way into a breach. Software you did not write, running on infrastructure you do not manage, is now the most common entry point. You cannot patch your supplier’s estate. You can only choose suppliers who patch it themselves and prove it.
Meanwhile almost nobody checks. The UK Cyber Security Breaches Survey 2025/2026, covering 2,112 businesses, found that 15% review the risks posed by their immediate suppliers and 6% look at the wider supply chain. Among large businesses it is 48% and 24%. Among micro businesses, 12% and lower still. Only 11% of businesses require suppliers to hold any security certification at all, rising to 41% of large businesses.
If you run a thirty-person company and you review your top five suppliers properly, you are doing more than most medium-sized businesses. The bar is genuinely low, which is good news for the effort you are about to spend.
Tier the suppliers before you question any of them
Open a spreadsheet, list every supplier that has a login to anything or holds any of your data, and put each into one of three tiers. Tier by what they can reach if they were fully compromised tomorrow, not by what you pay them.
Tier 1 — holds your data or has admin access
Payroll, accounting, CRM, email and identity platform, hosting, your MSP, anything storing customer records.
- Annual review with evidence, not just a questionnaire
- Named security contact and breach notification clause
- Exit plan and data export tested once
- Takes real time — budget half a day each
Tier 2 — limited access, no sensitive data
Design tools, project trackers, scheduling, analytics, most SaaS with non-personal content.
- Short questionnaire, every two years
- Check for single sign-on support and MFA enforcement
- Confirm where data is hosted
- Easy to let drift as the tool’s role expands
Tier 3 — no access to systems or data
Office supplies, hardware resellers, hosting-free services, anything paid by invoice with no login.
- Skip the questionnaire entirely
- Spend the time on tier 1 instead
- Re-tier if they ever ask for a login
NIST’s SP 800-161r1 makes the same structural argument at enterprise scale: supply chain risk management works when it is driven by criticality, not by procurement volume. You do not need the full framework for a thirty-person business, but you do need its ordering. Identify what matters, then apply effort proportionally.

What the paperwork proves, and what it does not
Vendors will send you a certificate or a report. Knowing what each one actually demonstrates stops you accepting a badge as an answer.
| Artefact | What it demonstrates | Main limitation | Ask for it when |
|---|---|---|---|
| SOC 2 Type II report | An independent auditor tested described controls over a period, typically 6-12 months, against the AICPA trust services criteria | Scope is chosen by the vendor. Read the system description and the exceptions list, not the opinion letter | The supplier holds customer or employee data |
| SOC 2 Type I report | The controls existed and were suitably designed on one specified date | Says nothing about whether they kept working | A young vendor is mid-way to Type II; treat as interim |
| ISO/IEC 27001:2022 certificate | A certified management system, with Annex A’s 93 controls across four themes considered and documented in a Statement of Applicability | Certifies the management system, not any particular control. Always read the scope statement and the certificate’s validity dates | You need evidence of governance rather than specific technical tests |
| Cyber Essentials | Self-assessment against five technical control areas, verified by a certifying body | Self-reported. 24% of UK businesses say they meet all five areas; only 5% hold the certificate | A small UK supplier with a modest estate |
| Cyber Essentials Plus | The same five areas, plus hands-on technical testing by a qualified assessor | Point-in-time, and narrow in scope | You want a cheap supplier assurance bar that is actually tested |
| Recent penetration test summary | Someone competent attacked a defined target and the findings were remediated | Scope is often tiny. Ask what was in scope and what the retest showed | The supplier runs the application your data lives in |
One practice worth borrowing from larger buyers: ask for the subservice organisation list. A SOC 2 report usually names the vendors your vendor depends on, and that is the quickest way to discover that three of your tier 1 suppliers all sit on the same platform. Concentration is a risk that no individual questionnaire surfaces.
The twelve questions that do the work
Twelve questions, sent as a short email rather than a spreadsheet. Expect answers in prose. Vague answers are themselves an answer.
- What data of ours do you hold, and in which countries is it stored and backed up?
- Is multi-factor authentication enforced for every one of your staff, including contractors and administrators? Which method?
- Do you support single sign-on so our identity platform controls who gets in, and at which price tier?
- Who on your team can read our data in production, and how is that access logged?
- What is your patching commitment for internet-facing systems, in days?
- When did you last restore a customer’s data from backup as a test, and how long did it take?
- What is your breach notification timeline to customers, in hours, and who signs it off?
- Do you hold SOC 2 Type II, ISO/IEC 27001 or Cyber Essentials Plus? Please send the report or certificate with its scope statement.
- Which subprocessors can reach our data, and how are we told when that list changes?
- If we leave, how do we export everything, in what format, and when is our data deleted?
- Have you had a security incident affecting customer data in the last 24 months? What changed afterwards?
- Who is the named security contact, and what is the out-of-hours route to them?
Question six is the one that separates good suppliers from confident ones. Plenty of vendors take backups. Far fewer have restored a specific customer’s data recently and can tell you how long it took. The same question is worth asking of your own setup, which our ransomware protection guide goes into properly.
Question eleven tends to produce the most useful conversation. A vendor that describes an incident plainly, says what they changed and does not oversell is usually safer than one with a spotless story. Incidents are normal. Hiding them is the problem.
Contract clauses worth arguing about
Most small-business contracts with SaaS providers are click-through terms you cannot negotiate, and that is fine for tier 2. For tier 1, these four clauses are worth asking about even if the answer is no, because the answer tells you how the vendor thinks.
- Breach notification in hours, not ‘promptly’. Name a number. 72 hours is the common regulatory anchor; 24 is better and some vendors will agree to it.
- Subprocessor change notice. Thirty days’ notice of a new subprocessor, with a right to object, stops your data quietly moving platform.
- Audit or evidence rights. Not a right to send auditors, which no vendor grants a small customer, but a right to receive the current SOC 2 or certificate annually.
- Data return and deletion on exit. Format, timescale and written confirmation of deletion. Test the export while you are still a happy customer.
A note on tone: you are a small customer asking a larger supplier for assurances, and the answer to some of this will be a polite no. That is information rather than failure. Write down which protections you did not get, and let that shape how much of your business depends on that one vendor.

What to check after you have signed
Vetting at purchase and never again is how a tier 1 supplier quietly becomes a tier 1 risk. Four lightweight habits keep the picture current without creating a compliance function.
- Review access quarterly. Pull the user list from each tier 1 platform and remove people who left. This catches more real exposure than any questionnaire.
- Re-read the certificate date annually. ISO and SOC artefacts expire. An out-of-date certificate on a vendor’s trust page is a useful signal about their internal discipline.
- Subscribe to their status page and security advisories. You want to hear about their incident from them, not from your customers.
- Keep the exit route warm. Export your data from each tier 1 supplier once a year and check the file actually opens. The NCSC’s supply chain guidance makes the same point about maintaining the ability to change supplier.
When a supplier is the one that gets breached
When the breach is at your supplier, your job is narrower than it feels. You cannot investigate their estate. You can work out what of yours was exposed and close the doors that are yours to close.
- Rotate every credential and API key that touches that vendor, including integration tokens nobody remembers creating.
- Revoke active sessions in your own systems for any account that authenticates through them.
- Pull your own access logs for the window the vendor describes, and look for logins from unfamiliar locations.
- Work out which of your customers’ data was in scope, and check your own notification duties before anyone asks.
- Write down what you learn and which tier you will put that vendor in next year.
Credential rotation is where most small businesses lose time, because nobody has a list of integration tokens. Building that list before an incident takes an afternoon. Building it during one takes a week. If MFA is enforced on your own side, the rotation is also far less urgent, which is the practical case made in our multi-factor authentication guide.
A worked example: one marketing agency, three findings
A client of ours ran their email marketing through a small agency. The agency was tier 2 on the first pass, because the assumption was that they only had a login to the campaign tool. Three findings came out of one thirty-minute call.
First, the agency had an API key with full read access to the customer list, not just campaign send rights. That moved them to tier 1 immediately. Second, two staff who had left the agency eighteen months earlier still appeared in the campaign platform’s user list, because nobody on either side owned that review. Third, the agency’s own email accounts had MFA available but not enforced, which is the gap that turns a phished agency password into a sender-reputation problem for your domain.
None of that needed a forty-question spreadsheet. It needed one call, the user list and the question about API scope. The fix took a morning: a scoped key, a quarterly access review on both sides, and enforced MFA written into the renewal. That is roughly the shape every one of these reviews takes. The findings are mundane, and that is why they keep happening. Our cybersecurity services include running this exercise with you across your tier 1 list, remotely, with the evidence written up so you can hand it to an insurer or a customer who asks.
One last point on the human side. A supplier review tends to surface the fact that one person in your business holds all the logins for the vendors nobody else deals with. That is not a security finding so much as a continuity one, and it is worth fixing in the same pass. The same goes for the inbound side: our guide to stopping phishing attacks covers the supplier-impersonation emails that almost always follow a publicised vendor breach.
Frequently asked questions
How many suppliers should actually be in tier 1?
For a business under a hundred people, usually between three and eight. Payroll, accounting, your identity and email platform, your CRM, your hosting, and your managed service provider if you use one. If your tier 1 list has twenty entries, the tiering is too generous and the programme will not survive its second year.
A vendor refuses to send their SOC 2 report. Is that a red flag?
Not on its own. Many vendors will only share the full report under a non-disclosure agreement, which is reasonable, and some will only offer a summary or a bridge letter. Signing an NDA to read it is normal. A flat refusal to share anything, including scope and audit period, is the actual red flag.
Do we need to do this if all our suppliers are large platforms?
Yes, but it is quick. Large platforms publish their certifications, subprocessor lists and status pages, so most of the twelve questions are answered by reading rather than asking. The parts you still have to do yourself are access reviews, export tests and working out your concentration risk when several suppliers share one cloud region.
Where does the Cyber Essentials requirement fit for small UK suppliers?
It is a cheap, proportionate bar. In the 2025/2026 UK survey only 3% of businesses required suppliers to hold Cyber Essentials, rising to 26% of large businesses, so asking for it still puts you ahead. Cyber Essentials Plus adds hands-on testing by an assessor, which is why larger buyers increasingly specify the Plus variant.
How long should the whole exercise take the first time?
Budget one day to build the supplier list and tier it, then half a day per tier 1 supplier. For a typical thirty-person business that is about four days of work spread over a month, and roughly a day a year afterwards. The list is the asset; after the first pass you are only maintaining it.
If you would rather not spend a month building a supplier register from scratch, we can tier your vendors, run the tier 1 reviews and leave you the register and the annual checklist. Get in touch with Eudora Technology to talk about your project.



