Why this is required, not optional
Every framework asks the supplier question somewhere.
Different regulators, the same underlying ask: know which suppliers touch what, and be able to show it.
21434 · Clause 7
Distributed activities: when cybersecurity work is split between customer and supplier, responsibilities live in a Cybersecurity Interface Agreement, evaluated at supplier selection.
21434 · Clause 15
TARA covers every component in scope, and supplier-sourced components feed the same analysis with a recorded treatment decision.
UNECE R155
The certified CSMS must manage risk across the supply chain: requirements cascaded to suppliers, and cybersecurity evidence flowing back per component.
EU CRA · Art. 13
Due diligence on third-party and open-source components, and a duty to report a vulnerability found in one back to its maker or maintainer.
NIS2 · Art. 21(2)(d)
Supply-chain security covering the relationship with each direct supplier, weighed against that supplier's own vulnerabilities and practices.
DORA · Art. 28
Financial entities, including OEM captive finance and leasing arms that are licensed institutions, keep a current register of every ICT third-party arrangement, tagged by criticality and reported to regulators.
TISAX / VDA ISA
OEMs require suppliers handling shared data or prototypes to hold a TISAX label at an assessment level matched to data sensitivity.
SBOM practice
Born from US EO 14028 and NTIA minimum elements; the federal mandate was rescinded by an OMB policy change in February 2026, but R156 and the CRA still expect component-level bills of materials per release.