How Do We Identify Critical Suppliers In Our Supply Chain?

Your supplier list only shows the first layer. Fourth parties, shared providers and concentration risk sit underneath it, and they can fail without a single supplier of yours doing anything wrong.
Risk Ledger
|
Company
July 17, 2026
8
mins read
How Do We Identify Critical Suppliers In Our Supply Chain?

Why supplier inventories become unmanageable

Every business ends up with more suppliers than anyone planned for. Nobody sits down and decides to build a list of a thousand suppliers. It happens through years of ordinary growth, procurement adding a new relationship here, a new tool there, until the register is enormous and nobody remembers agreeing to review all of it.

There are two separate problems buried in that, and they need separate fixes… 

  • The first is volume. You genuinely cannot go through a supplier list of that size one by one and make a proper judgement on each entry. At some point you have to set some rules of the game, because there isn't the time or the headcount to do it any other way.
  • The second is different: even with unlimited time, a supplier register on its own doesn't tell you anything about which of those relationships matter more than the others. It's a list, not a judgement.

That second problem is the harder one, because it isn't really a data problem. It's a business-understanding problem.

To work out which suppliers matter most, you first have to be able to answer what your business is actually there to do, what it can't afford to lose, and that requires a fairly broad view of the organisation that a security team doesn't always have sitting with them.

Some businesses have resilience or business continuity functions built for exactly this kind of question. Plenty don't, which leaves security teams trying to build that picture of the whole business themselves before they can even start on suppliers. That's a skills and capability gap as much as a workload one, and it's not always an easy one to hire for.

There's also no shortcut in the form of an industry-standard answer waiting to be applied. What's critical to one organisation genuinely isn't critical to another, and even the criteria you'd use to work that out differ across sectors.

Critical suppliers and high-risk suppliers are not the same thing

A critical supplier is one your business cannot function without. A high-risk supplier is one that could seriously damage your business if something went wrong, whether or not you'd notice it going down. The two overlap a lot, but they're not the same category, and mixing them up means missing suppliers that could still end your business.

There are two separate things going on here, and they're worth taking one at a time. The first is availability. When people talk about a critical supplier, they usually mean: if this supplier had an incident and went down, it would have a material impact on the business. That's an availability question.

You work it out by starting with your own business, deciding what your essential operations are, what you genuinely cannot afford to lose, and then mapping which suppliers support those operations. That list becomes your critical suppliers.

The second thing is confidentiality, and it's the part that gets missed. A supplier can be entirely dispensable operationally and still hold data sensitive enough that a breach there does as much damage as losing a critical service outright, through regulatory action, through the fallout with customers, through reputational cost that has nothing to do with anything going offline.

Most security people will say, if you ask them directly, that of course they look at this too. But the practical reality is that criticality conversations take up most of the airtime, so this second group of suppliers, not critical but genuinely high-risk, quietly falls out of scope.

High Risk vs Critical Suppliers

The reason people conflate the two is that criticality is the easier conversation to have. It maps neatly onto a business continuity question: what stops working if this supplier fails? 

High risk is messier, because it asks what could go wrong even if nothing stops working at all. A supplier holding sensitive personal data isn't going to show up on an availability-based list, because your business keeps running fine without them.

But if that data gets breached, the regulatory and reputational cost can be just as severe as losing a critical service outright.

Treating "critical" and "high-risk" as interchangeable means the assessment work naturally drifts toward the first group and away from the second, not because anyone decided that was the right call, but because the criticality conversation is the one that gets had.

Critical vs High Risk Suppliers Mapped to CIA Triad

What actually makes a supplier critical?

A supplier becomes critical when your business depends on them to keep an essential operation running, not because of what they cost or how big they are. The clearest way to see this is to look at what's actually essential to a specific organisation, then trace it back to the suppliers underneath it.

Take a large NHS trust. What's essential is that the hospitals keep running. That depends on things you wouldn't necessarily think of as security-relevant at first glance, like the electricity staying on. If there's a third party doing the maintenance that keeps that power supply working, that maintenance provider is now a critical supplier, not because of the contract value, but because the hospital can't run without the electricity, and the electricity can't run without them.

The same logic applies at any scale. At Risk Ledger, AWS is a critical supplier, because the product doesn't run without it. Something like Google could arguably count too, but if it went down, the business wouldn't stop, because the team would quickly find another way to work.

That's the actual test: not "is this supplier important," but "does my business stop functioning without them."

Organisations with large numbers of physical, complex operations, healthcare, energy, water, transport, tend to end up with far more critical suppliers than a remote, cloud-based business, simply because there are more moving parts that all have to keep working at once. 

Financial services is the other place this shows up heavily, for a related but different reason: decades of interconnected global payment systems mean a failure in one place can cascade to others fast, so resilience has been built into how that sector thinks about suppliers for a long time.

Why budget-based tiering breaks down

When teams don't have a proper way to work out criticality, the most common fallback is spend. A supplier costing more than some threshold, ten grand a year, twenty grand, gets pulled in for review. Anything under that gets waved through on the assumption that small spend means small supplier, and small supplier means not critical.

The flaws in that are fairly obvious once you say them out loud, but it persists because the alternative is genuinely hard, and you have to draw the line somewhere, especially once you're trying to do this at scale rather than judging every supplier one by one. Budget as one input among several is reasonable. Budget as the only filter is where it breaks.

At Risk Ledger, we’ve seen organisations where procurement owns that spend threshold entirely, and it sits at around twenty grand. Below that line, the security and resilience teams don't just deprioritise those suppliers… they don't know they exist. There's no visibility into what those suppliers do or hold, because the filter that decides who gets looked at sits with a team that isn't asking the criticality question at all.

This matters because cost has nothing to do with the two things that actually determine criticality: how much your business depends on a supplier operationally, and how sensitive the data or access they hold is.

A tiny specialist supplier with a niche, low-cost service can sit underneath multiple much larger organisations, invisible to any of them, precisely because none of them would ever flag it as worth twenty grand of attention.

Budget-Based Supplier Tiering

A working framework: impact and likelihood together

You get to your critical suppliers by starting with risk, not by starting with criticality directly. If you start by trying to define what's critical, you end up missing the wider group of high-risk suppliers, because high-risk is the bigger set and critical suppliers sit inside it.

Risk is made up of two things: impact and likelihood, and most teams only ever properly assess one of them.

Likelihood Chart

The impact side comes down to three questions, and you ask them of your own business, not the supplier.

  • What does this supplier do for us?
  • What data do they hold?
  • What access do they have into our systems?

The access question matters more than it sounds like it should, because it's really asking what a hostile actor could do if they took over that supplier. If they have access into your systems, that's a route to lateral movement into your own environment. If you trust them enough that an email asking you to pay an overdue invoice would get paid without question, that's a different kind of exposure entirely.

The likelihood side is simpler to state and harder to get right: how good is that supplier's security. Most teams don't try to assess this for every supplier, because it feels like an impossible amount of work to do properly at scale, which is a reasonable assumption to make on your own.

Once you have both dimensions, you can plot every supplier on an impact and likelihood grid and draw your own line for where attention starts. That's your risk appetite, and it's a legitimate business decision, not a shortcut.

The mistake most teams make isn't ignoring likelihood, it's cutting the line on impact alone and only thinking about likelihood second, if at all. That misses a specific and important group: suppliers with moderate impact but genuinely high likelihood of a problem.

Those are often the more realistic targets, because a supplier your business would barely notice losing usually hasn't had serious security investment put into it either, whereas the biggest, highest-impact suppliers tend to already have tighter security simply because of their own scale.

The suppliers sitting in the middle, not big enough to have hardened their own security, not small enough to be dismissed as immaterial, are where risk quietly concentrates.

Try it on a real supplier

Where does this supplier sit on the grid?

Answer for one supplier at a time. Impact comes from your own business, likelihood is your honest read on their security, there's no scoring trick behind either.

Impact
Likelihood

Low impactHigh impact

This reflects your own answers, it isn't checked against external data. Use it to structure the conversation, not to replace judgement.

Put this into practice

Use our free Supplier Criticality Matrix to help you score suppliers consistently using the impact and likelihood framework described above.

Why this is a whole-business exercise, not a security team task

To assess impact properly, you have to understand the business well enough to know what it can't afford to lose, and that's rarely something one security person can do alone, however good they are.

There are two separate difficulties here. The first is structural. Responsibility for this usually sits across several teams that have grown up for slightly different, often historical reasons: security, resilience, business continuity, sometimes all three with overlapping but not identical remits.

That creates real lines of accountability, but it also means the person actually doing the assessment doesn't always have the authority or the reach to get a full picture of the business on their own.

The second difficulty is the scale of what understanding "the business" actually requires. Properly working out what's essential means engaging with the whole organisation, not just security's corner of it. In practice, that often looks like going department by department, understanding what each one does, and slowly building up a picture of how it all connects, before you can even start asking which suppliers sit underneath those essential functions.

If that responsibility gets pushed down to a single security person in a large organisation, that's a genuinely large undertaking for one role to carry, and it's not a reasonable expectation.

Where organisations have dedicated business continuity or operational resilience teams, this is usually their job, and they own the "what is essential here" question directly. Where those functions don't exist, security ends up doing it by default, either building that picture themselves or relying on whatever's already been documented elsewhere in the business, which isn't always complete or current.

You cannot identify critical suppliers without first understanding what is essential to the business. That requires knowledge and engagement across the whole organisation.
Emily Hodges Emily Hodges COO, Risk Ledger

Where most supplier prioritisation goes wrong

Most of the mistakes in this space aren't careless, they're reasonable shortcuts under real resource pressure that quietly narrow what actually gets looked at.

The most common is asking the supplier directly how critical they are to you. It sounds efficient, but the supplier isn't the right person to answer that question, and the incentives aren't always aligned. A supplier might want to seem critical to protect the relationship, or want to avoid a long list of questions entirely. Either way, they don't actually know the answer, because criticality is about your business, not theirs. What does tend to happen instead, more often than an outright question, is asking suppliers what functions they support or what data they hold, which is useful, but only as an input into your own judgement, not a substitute for it.

The second is assessing impact and stopping there, cutting the line at "how bad would this be" without asking "how likely is it." That misses the suppliers sitting in the middle, moderate impact, genuinely high likelihood, which are often more realistic targets than the biggest names on the list.

The third is treating full supply chain visibility as impossible and not attempting it. That assumption is understandable given the scale of the problem, but it's also one worth challenging directly, because collaboration and shared data across organisations can get you a usable picture of likelihood without having to build it supplier by supplier from nothing.

Common mistakes

Three mistakes that feel like rigour, but aren't

Each of these looks like a defensible process choice under resource pressure. None of them are careless. All three quietly narrow what actually gets looked at.

  • Asking the supplier how critical they are
    Feels like

    A quick, direct way to get an answer without building your own assessment from scratch.

    Actually misses

    The supplier doesn't know your business, and the incentives aren't aligned. Criticality is a judgement about you, not them.

  • Cutting the line on impact alone
    Feels like

    Focusing effort on the suppliers that would hurt the most if something went wrong.

    Actually misses

    Suppliers with moderate impact but genuinely high likelihood, often more realistic targets than the biggest names on the list.

  • Treating full visibility as impossible
    Feels like

    A realistic call given the scale of most supplier lists and the resource available to review them.

    Actually misses

    That shared data across organisations can get you a usable picture of likelihood without building it supplier by supplier from nothing.

What to check instead

Ask your own business what a supplier does, what data they hold and what access they have, plot impact against likelihood together, and treat "we can't see the whole supply chain" as an assumption worth testing rather than a fixed limit.

From a one-off exercise to a continuing judgement

Everything above describes how to work out which suppliers are critical today. The harder question most teams don't ask is what happens to that answer next year, or after the next reorganisation, or once a supplier changes what they do for you without telling anyone.

Most organisations treat criticality as something you establish once and file away. A supplier gets tiered, the tier gets recorded, and the assumption is that the work is done.

But the two inputs that actually determine criticality, what a supplier does for you and how much you depend on it, change constantly. Businesses restructure, suppliers get acquired, expand their service, change what data they touch… and none of that shows up automatically in a spreadsheet someone filled in eighteen months ago.

The teams that handle this well don't treat it as a bigger version of the same annual exercise. They treat the judgement itself as something to revisit when the underlying facts change, not on a fixed calendar. That's a different kind of process to design for, one built around noticing change rather than scheduling reviews.

What security teams ask next

Key takeaways

How to identify critical suppliers, in short

Criticality is a judgement about your business, not a property of the supplier. Here's the shape of the approach, and where most teams go wrong.

  • Critical ≠ high-risk

    Critical suppliers sit inside the wider set of high-risk suppliers. A supplier can be non-critical and still hold enough sensitive data to seriously damage the business.

  • Start with risk, not criticality

    Starting from "what's critical" misses the broader high-risk group. Starting from impact and likelihood together gets you to your critical suppliers as a subset.

  • Budget is not a criticality filter

    Tiering by spend alone hides small, low-cost suppliers that can carry outsized operational or data risk.

  • Ask three questions, of yourselves

    What does this supplier do for us? What data do they hold? What access do they have? Answered internally, not by the supplier.

  • Likelihood is the harder half

    Impact is answerable by looking at your own business. Likelihood means assessing someone else's security, which is where most teams run out of time.

  • It's a whole-business exercise

    Assessing impact properly requires understanding what the business can't afford to lose, not just a security team's view of its own remit.

Where to start

Plot suppliers on impact and likelihood together, draw your own risk-appetite line, and treat mid-impact, high-likelihood suppliers as seriously as your biggest names, they're often the more realistic target.

Pattern Trapezoid Mesh

Get the security manager's briefing

Monthly research, case studies and practical guides you won't find anywhere else.

Join thousands of security managers turning their TPRM programmes into success stories.