Book an Appointment

Security of the digital Supply Chain

How to systematically assess and manage the security of your IT, cloud, and AI supply chain – from supplier selection through to continuous monitoring.

Today, most security-relevant risks no longer arise solely within your own network but through third parties: cloud services, software suppliers, managed service providers, and increasingly AI services. With NIS2 and DORA, assessing direct suppliers has shifted from a recommendation to a regulatory obligation. Cloud and AI providers are special cases here: they process sensitive data outside your own control and require standardized, verifiable assessment procedures. For precisely these cases, industry bodies such as the Cloud Security Alliance have created established frameworks – the CAIQ for cloud providers and the AI Controls Matrix for AI services. Third-Party-Risk-Management (TPRM) combines these building blocks into an end-to-end process from selection through to ongoing monitoring.

The Essentials at a Glance

01

What supply chain security and TPRM cover

Third-Party-Risk-Management (TPRM) covers the identification, assessment, and ongoing management of risks arising from relationships with suppliers and service providers. This includes an inventory of all third parties, their classification by criticality, the assessment of their security practices, and contractual and organizational controls across the entire lifecycle – from procurement to exit. The goal is transparency about which providers support critical functions and how robust their security posture actually is.

02

Regulatory framework: NIS2, DORA, CRA, ISO 27001

The supply chain is now explicitly regulated. NIS2 (Richtlinie (EU) 2022/2555) requires supply chain security measures for relationships with direct suppliers and service providers in Art. 21(2)(d); Art. 21(3) requires taking into account the vulnerabilities of each direct supplier and the quality of its cybersecurity practices (including the coordinated risk assessments under Art. 22). For the financial sector, DORA (Verordnung (EU) 2022/2554, applicable since January 17, 2025) governs ICT third-party risk in Chapter V – including strategy and register of information (Art. 28), concentration risk (Art. 29), and minimum contractual provisions (Art. 30). The Cyber Resilience Act extends these obligations to products with digital elements and their components. In practice, the ISO/IEC 27001 controls A.5.19–A.5.23 operationalize these requirements for supplier relationships and cloud use.

03

Assessing cloud providers: CAIQ, CCM, and STAR

The Cloud Security Alliance has created an established procedure for assessing cloud providers. The Cloud Controls Matrix (CCM) is a control framework for cloud computing with 197 control objectives across 17 domains. The accompanying Consensus Assessment Initiative Questionnaire (CAIQ) translates these controls into yes/no questions (v4.0: 261 questions) with which a provider documents its existing security controls; from version 4.1 onward, CCM and CAIQ are merged. Through the STAR Registry (Security, Trust, Assurance and Risk), the completed CAIQ becomes publicly accessible: STAR Level 1 is a free self-assessment (updated annually), Level 2 a paid third-party audit – as STAR Attestation (SOC 2) or STAR Certification (ISO/IEC 27001). This makes it possible to judge whether a service is secure enough for your own intended use.

04

Assessing AI providers: CSA AI Controls Matrix v1.1

AI services require their own assessment logic. The CSA AI Controls Matrix (AICM) v1.1 is a vendor-neutral control framework for cloud-based AI systems with 247 control objectives across 18 security domains; it builds on the CCM and is synchronized with CCM v4.1. A dedicated “Model Security” domain addresses AI-specific topics such as Model Poisoning, Prompt Injection, unauthorized model access, and the protection of Model Weights through 13 AI-specific controls. The controls distinguish five roles (including Model Provider, Application Provider, AI Customer) and provide mappings to ISO 42001, ISO/IEC 27001, NIST AI RMF and NIST AI 600-1, BSI AIC4, and the EU AI Act. The accompanying AI-CAIQ (v1.1: 320 questions) serves – like the CAIQ in the cloud domain – as a question catalog for self- and third-party assessments.

05

From questionnaire to continuous monitoring

A questionnaire is a snapshot – security, by contrast, is a state over time. A robust assessment begins with the criticality rating of the provider, followed by the evaluation of the CAIQ or AICM responses as well as available certificates and audit reports. Because STAR Level 1 self-disclosures are updated annually, a provider's compliance posture can be tracked continuously; for critical functions, DORA requirements such as concentration analysis (Art. 29) and exit strategies (Art. 28(8)) complete the picture. Point-in-time questionnaires thus become a continuous process with defined triggers for reassessments.

06

The VamiSec approach

VamiSec supports the establishment of a TPRM program and the concrete assessment of individual providers. We structure supplier and provider assessments along established catalogs (CAIQ/CCM for cloud, AICM for AI), automate recurring security questionnaires, and map the results to the regulatory requirements from NIS2, DORA, and ISO/IEC 27001. On request, we support the preparation for STAR or ISO 27001 audits and set up continuous monitoring of critical third parties – vendor-neutral and documented in a verifiable manner.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Cloud Security Alliance · 2021

Consensus Assessment Initiative Questionnaire (CAIQ) & Cloud Controls Matrix (CCM)

CAIQ as a yes/no questionnaire for the CCM; CCM with 197 control objectives across 17 domains; CAIQ v4.0 with 261 questions; CCM and CAIQ merged from v4.1 onward.

Cloud Security Alliance · 2026

STAR Registry (Security, Trust, Assurance and Risk)

Public registry; Level 1 free self-assessment (updated annually), Level 2 paid third-party audit (STAR Attestation/SOC 2, STAR Certification/ISO 27001).

Cloud Security Alliance · 2026

AI Controls Matrix (AICM) v1.1

247 control objectives across 18 domains, Model Security domain with 13 AI-specific controls, accompanying AI-CAIQ with 320 questions; released June 2026, synchronized with CCM v4.1.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2)(d) supply chain security for direct suppliers, Art. 21(3) assessment of suppliers, Art. 22 EU-coordinated risk assessments of critical supply chains.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA)

Chapter V, Art. 28–31 on ICT third-party risk (strategy, register of information, due diligence, concentration risk, exit strategies); applicable since January 17, 2025.

Supplier and provider risks under control?

We assess your critical cloud and AI service providers against CAIQ and AICM and build a robust Third-Party-Risk-Management with you. Talk to us.