Book an Appointment

Security of the digital Supply Chain

How to systematically assess and manage the security of your IT, cloud, and AI supply chain – from supplier selection through to continuous monitoring.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

197control objectives in the CCM across 17 domains
261yes/no questions in CAIQ v4.0
247control objectives in AICM v1.1 across 18 security domains
320questions in the accompanying AI-CAIQ v1.1

Today, most security-relevant risks no longer arise solely within your own network but through third parties: cloud services, software suppliers, managed service providers, and increasingly AI services. With NIS2 and DORA, assessing direct suppliers has shifted from a recommendation to a regulatory obligation. Cloud and AI providers are special cases here: they process sensitive data outside your own control and require standardized, verifiable assessment procedures. For precisely these cases, industry bodies such as the Cloud Security Alliance have created established frameworks – the CAIQ for cloud providers and the AI Controls Matrix for AI services. Third-Party-Risk-Management (TPRM) combines these building blocks into an end-to-end process from selection through to ongoing monitoring.

The Essentials at a Glance

Six topic blocks — tap to expand.

The regulatory framework

Four sets of rules reach into the supply chain — tap a tab for the core obligations.

Richtlinie (EU) 2022/2555
  • Art. 21(2)(d) requires supply chain security measures for relationships with direct suppliers and service providers.
  • Art. 21(3) requires taking into account the vulnerabilities of each direct supplier and the quality of its cybersecurity practices — including the coordinated risk assessments under Art. 22.
Art. 21(2)(d)Art. 21(3)Art. 22direct suppliers

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Cloud Security Alliance · 2021

Consensus Assessment Initiative Questionnaire (CAIQ) & Cloud Controls Matrix (CCM)

CAIQ as a yes/no questionnaire for the CCM; CCM with 197 control objectives across 17 domains; CAIQ v4.0 with 261 questions; CCM and CAIQ merged from v4.1 onward.

Cloud Security Alliance · 2026

STAR Registry (Security, Trust, Assurance and Risk)

Public registry; Level 1 free self-assessment (updated annually), Level 2 paid third-party audit (STAR Attestation/SOC 2, STAR Certification/ISO 27001).

Cloud Security Alliance · 2026

AI Controls Matrix (AICM) v1.1

247 control objectives across 18 domains, Model Security domain with 13 AI-specific controls, accompanying AI-CAIQ with 320 questions; released June 2026, synchronized with CCM v4.1.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2)(d) supply chain security for direct suppliers, Art. 21(3) assessment of suppliers, Art. 22 EU-coordinated risk assessments of critical supply chains.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA)

Chapter V, Art. 28–31 on ICT third-party risk (strategy, register of information, due diligence, concentration risk, exit strategies); applicable since January 17, 2025.

Supplier and provider risks under control?

We assess your critical cloud and AI service providers against CAIQ and AICM and build a robust Third-Party-Risk-Management with you. Talk to us.