Key Takeaways
- 82.4% of UK organisations experienced at least one supply chain cyber incident in the past 12 months, and 86% still rank supply chain risk among their top three concerns for 2026.
- Only 40.6% of organisations have fully automated, real-time monitoring of their critical suppliers' internal security controls; the majority still rely on quarterly or annual reviews.
- More than half of UK organisations (55.4%) do not have direct relationships with the security teams at all their critical suppliers, limiting how quickly they can respond when something goes wrong.
- Platform data across three UK Defend-as-One communities, government, local authorities and financial services, mapped supplier dependencies up to eight tiers deep and surfaced over 3,800 potential concentration risks invisible to any single organisation working alone.
- In November 2025, the EU's supervisory authorities designated 19 Critical ICT Third-Party Providers under DORA, including AWS, Microsoft Azure and Google Cloud, confirming how concentrated financial-sector supply chains have become.
- The UK's Cyber Security and Resilience Bill cleared the House of Commons on 25 June 2026, introducing fines of up to £17 million and a 24-hour incident-reporting requirement for designated critical suppliers.
- 93.2% of organisations say they would support an industry-wide model for sharing supplier risk data with peers, yet most are still assessing suppliers bilaterally rather than collectively.
Introduction
The numbers above are not new to anyone managing supply chain risk in 2026. What is less well understood is where, specifically, that gap between recognition and action sits, and what closing it actually requires.
This article sets out the main TPRM trends for 2026, drawing on new survey data from 500 UK cyber security and risk professionals and on platform data from organisations that map supplier dependencies collectively rather than in isolation. Eight shifts stand out: continuous monitoring replacing annual assessments, AI introducing new supplier-side risk, regulators converging on sector-wide visibility requirements, critical suppliers drawing sharper scrutiny over concentration risk, fourth-party and software supply chain visibility remaining partial at best, cybersecurity rather than compliance driving TPRM investment, confidence in standalone tools softening in favour of integrated platforms, and board reporting expectations outpacing what most TPRM data can currently support. Each is examined in turn below.
Continuous Monitoring Is Replacing Annual Vendor Assessments
Only 40.6% of UK organisations describe their ability to monitor the internal security controls of important suppliers as fully automated and real-time. The majority, 53.6%, still rely on partial automation with quarterly or event-triggered updates. A further 3.8% still depend on manual, spreadsheet-based annual assessments, and 1.6% describe their approach as ad hoc and reactive.
This is not a UK-specific problem. KPMG's 2026 Global Third-Party Risk Management Survey, which gathered responses from 851 organisations across 16 countries, found that only 53% of TPRM programmes are "mostly integrated" with enterprise risk management, and just 18% are "fully integrated." The same survey found that only one in five organisations report the highest level of data quality in their TPRM programme, though those that do report significantly more confidence in their risk decisions. Put alongside the UK figures, this suggests the gap is not really about whether organisations want continuous oversight. It is about whether the underlying data is structured and integrated well enough to support it.
This gap matters because "continuous monitoring" has become a loosely used term. External vulnerability scanning, which checks a supplier's public-facing perimeter, is often marketed and understood as continuous monitoring. It is not, or at least not on its own. It can flag exposed ports, misconfigurations, or expired certificates, but it says nothing about a supplier's internal access controls, staff training, patch management practices, or incident response capability. Those are the controls that actually determine whether a supplier will contain a breach or become the route through which it spreads.
Genuine continuous monitoring requires both: external signals from a supplier's digital footprint, combined with regular reassessment of internal controls and real-time notification when something changes. Right now, most organisations only have the first half of that picture, and many, per KPMG's integration figures, do not have a data foundation solid enough to support the second half even if they wanted it. Closing that gap is not about running the same annual questionnaire more often. It requires a different operating model, one built on continuous, structured data rather than periodic point-in-time reviews.
.png)
What Regulators Now Expect from TPRM Programmes
UK and EU regulation is converging on a single idea: firms must understand their supply chains well beyond the point where their direct contracts end.
In the EU, the Digital Operational Resilience Act became fully applicable in January 2025. Article 29 requires financial entities to assess whether an ICT arrangement creates substitutability risk or excessive dependence on a single provider, and to account for the downstream consequences of subcontracting. This is no longer an abstract requirement. In November 2025, the European Supervisory Authorities published their first list of designated Critical ICT Third-Party Providers under DORA, naming 19 organisations, including AWS, Microsoft Azure, Google Cloud, IBM, Bloomberg and LSEG, that now face direct EU-level oversight rather than oversight solely through their financial-sector clients. The list is a concrete illustration of exactly the concentration risk Article 29 was written to address: a handful of technology providers sitting underneath a large share of the financial sector's critical functions. The proposed Cybersecurity Act 2, introduced in January 2026, goes further still, expecting organisations to map their digital dependencies deeply enough to identify and phase out high-risk suppliers or jurisdictions.
The UK has followed a similar path through a different route. Operational resilience rules from the Bank of England, FCA and PRA, in force since March 2025, require firms to identify their most important business services and demonstrate they can stay within impact tolerances during severe disruption, including disruption that originates with a supplier. Newly finalised reporting rules, published in March 2026, will require firms to submit standardised registers of all material third-party arrangements by March 2027.
The Cyber Security and Resilience Bill has moved quickly since it was introduced to Parliament in November 2025. It completed all its stages in the House of Commons and entered the House of Lords on 25 June 2026, carrying fines of up to £17 million or 4% of global turnover, and a requirement that regulated entities begin incident reporting within 24 hours. The Bill introduces a Designated Critical Suppliers regime that places direct statutory duties on suppliers whose failure could cause widespread harm. The government has used the Synnovis attack on NHS services as its own reference point for what this regime is meant to prevent: one supplier breach, cascading across multiple critical services at once.
The common thread across all of these frameworks is that regulators are not simply asking firms to demonstrate due diligence on paper. They are collecting structured data on suppliers, subcontractors and deeper-tier dependencies in order to build a sector-wide map of who depends on whom. That is a different exercise to firm-level compliance, and it is one that most TPRM programmes are not yet resourced to support.

Why Critical Suppliers Are Getting More Attention Than Ever
Criticality is determined in two distinct ways. An organisation designates its own suppliers as critical based on factors it controls: whether a supplier underpins one of its critical or important business functions, whether it holds system access or sensitive data, or whether it would be difficult to replace. Regulators are now designating a separate, narrower set of suppliers as critical at a sector level, bringing them under direct statutory supervision in addition to oversight by their individual clients. The 19 providers named as DORA's first Critical ICT Third-Party Providers in November 2025, including AWS, Microsoft Azure and Google Cloud, fall into this second category. The data below concerns the first: how well organisations manage the suppliers they themselves have identified as critical.
.png)
More than half of UK organisations, 55.4%, do not have direct relationships with the security teams at all their critical suppliers. Of these, 53% have access to only some, and 2.4% have none at all. This is a significant gap, because it means that when something goes wrong at a critical supplier, many organisations have no established route to the people who can explain what happened, what controls failed, and what needs to happen next.
The data from Risk Ledger's own community platform shows why this gap matters at scale. Among 26 UK government bodies collectively assessing 3,240 direct suppliers, the platform identified 820 potential concentration risks at the third-party level alone, of which 224 were rated critical by their clients. The pattern repeats elsewhere. Among 30 financial institutions, 288 of 727 third-party concentration risks were rated critical. Among 25 local authorities, 99 of 364 were.
There is a live policy response to ensure critical suppliers and sub-contractors contributing to critical or important business functions don’t become a systemic risk. At CYBERUK 2026, the Security Minister announced a voluntary Cyber Resilience Pledge, under which signatories commit to auditing Cyber Essentials coverage across their supply chains using a new Cyber Essentials Supplier Check Tool within two months. That is a direct match for the weakness this data reveals: organisations cannot manage what they cannot see, and most cannot currently see whether their own critical suppliers meet even baseline certification standards. The challenge is that most organisations cannot identify which of their suppliers carry this kind of concentration risk in the first place, because that picture only becomes visible once dependencies are mapped across peer organisations rather than within a single firm's own supplier list.
Fourth-Party and Software Supply Chain Visibility
Visibility beyond the first tier of suppliers has improved, but it remains far from complete. In the 2026 survey, 30% of organisations report full visibility into the entire chain of subcontractors supporting their important business functions. A further 50.2% have high visibility into direct fourth parties only, 16% have partial visibility into some fourth parties, and 3% have no visibility beyond their direct critical third parties at all.
Gartner's own guidance to legal and compliance leaders frames this as a structural feature of third-party risk today, not a UK-specific gap. Gartner reports that 40% of compliance leaders say between 11% and 40% of their third parties are high-risk, and notes that as networks expand to include more third, fourth and fifth parties, effective governance has never been more critical. Gartner also finds that 42% of organisations now consider third parties more critical to their profitability than they were just three years ago, which helps explain why the depth of these networks keeps growing faster than most TPRM programmes can track them.
Read on its own, the UK visibility data looks like progress: only 3% are working entirely blind. But high visibility into direct fourth parties is not the same as understanding the fifth, sixth, seventh and eighth tiers that sit beneath them, and this is where the picture changes. Platform data from the three Defend-as-One communities examined in this report shows dependency chains running deep. Among UK government bodies, 3,240 direct suppliers led to a further 5,886 identified dependencies, reaching as far as the eighth tier. Among local authorities, 25 organisations with 1,004 direct suppliers uncovered 7,659 additional dependencies, again running to eight tiers. Financial institutions saw a similar pattern: 2,780 direct suppliers, 6,529 further dependencies.
.png)
None of this depth is visible to an organisation looking only at its own supplier relationships. A firm can have excellent oversight of its direct suppliers and still have no idea that six of its peers depend on the same fourth-party cloud provider, or that a single fifth-party software component sits beneath a dozen otherwise unconnected supply chains. That is precisely the kind of concentration risk that shows up in the aggregate numbers: 1,264 potential concentration risks identified across the government community, 1,240 across local authorities, 1,322 across financial services, each only visible once organisations pooled their supplier data on a shared network.
This is the practical argument for network-level visibility over bilateral assessment. It is not that individual TPRM processes are being done badly. It is that some risks, by their nature, cannot be seen from inside a single organisation, no matter how thorough that organisation's own supplier reviews are, and no matter how well governed its relationship with each direct supplier is individually.
Cybersecurity Is Still the Top Driver of TPRM Investment
The scale of the problem is set out earlier in this report: most UK organisations experienced a supply chain incident in the past year, and most still rank it a top-three concern. What is worth examining here is why cybersecurity, specifically, remains the dominant driver of TPRM investment, rather than compliance or cost.
KPMG's 2026 Global TPRM Survey offers a useful comparison point. Across 851 organisations surveyed globally, cyber risk and regulatory compliance were named the two leading drivers of TPRM strategy, cited by 48% and 37% of respondents respectively. That roughly matches the UK picture in this report, where supply chain incidents are named a top-three concern by the overwhelming majority of organisations, well ahead of cost or reputational factors.
Yet the UK government's own Cyber Security Breaches Survey 2025/2026, published in April 2026, shows that investment intent and actual practice remain far apart. Just 15% of businesses and 9% of charities formally review the cyber risk posed by their immediate suppliers, and only 6% of businesses and 4% of charities review their wider supply chain. These figures conceal a sharp divide by size: around 30% of medium businesses and 48% of large businesses reviewed their immediate suppliers, meaning the overall 15% figure is pulled down largely by smaller organisations that lack the resources to review suppliers at all.
The seriousness of the underlying threat has become harder to dismiss as a compliance abstraction. Speaking at the RUSI Annual Security Lecture in June 2026, NCSC CEO Richard Horne disclosed that the agency handled more than 200 cyber incidents affecting the UK's critical national infrastructure and its supporting ecosystem in the year to May 2026, with around 75% believed to be linked to state actors. That reframes what is driving TPRM investment in 2026. This is no longer primarily a compliance exercise or a reputational concern. It is a response to a threat landscape where supply chains are a deliberate, primary route into critical infrastructure and services, and where the attackers exploiting that route are increasingly well resourced and patient.
The gap between stated priority and formal review rates, and the divide between large and small organisations within that review rate, is the clearest evidence that awareness has outpaced action. Organisations know supply chain risk is serious, and rank cybersecurity as their top TPRM driver for good reason. What most have not yet done, particularly outside the largest firms, is build a process capable of reviewing it at the scale the threat now requires.
Why Standalone Tools Are Being Replaced by Integrated Platforms
Confidence in traditional TPRM is softening. In 2026, 27.8% of respondents still consider it very effective at reducing supply chain cyber risk, down from 37.2% the year before. The largest group, 60.4%, describe it as somewhat effective, the same dominant response as in 2025. Only 5.2% consider it not very effective, and 0.2% regard it as entirely ineffective. Read alongside the 82.4% incident rate, this points to a process most organisations find useful but not sufficient.
Asked to identify the single biggest shortcoming in prevailing TPRM approaches, 24.8% of respondents pointed to lack of visibility into supply chain dependencies beyond direct third parties. A further 19.8% cited the inability to continuously monitor suppliers' internal security controls, 15.4% cited insufficient resourcing, and 13% cited a lack of collaboration and information sharing with industry peers.
KPMG's 2026 Global TPRM Survey points to the same conclusion from a much larger, global sample. It recommends that organisations expand visibility into Nth-party relationships to manage concentration risk and make greater use of managed services to scale their programmes, while noting that only around 5% of organisations currently operate anything close to a comprehensive, end-to-end managed model. That figure, drawn from 851 organisations across 16 countries, is a useful check on any assumption that the UK's gaps are somehow unusual. Most organisations everywhere are still assembling TPRM piece by piece rather than operating it as a single, integrated capability.
When asked about support for an industry-wide collaborative model, in which supplier intelligence and assurance data are shared with peers, 42% of UK respondents said their organisation would be very supportive and 50.2% said somewhat supportive. Combined, that is 93.2% of organisations open to a more collective approach, against just 0.6% somewhat unsupportive.
The three community examples in this report show what that support looks like in practice. Twenty-six UK government bodies, twenty-five local authorities, and thirty financial institutions have each formed their own Defend-as-One networks, pooling supplier data to surface concentration risks that none of them could have identified working alone. None of these organisations abandoned their existing TPRM processes to do this. They built on them, adding a shared, standardised layer that let their individual assessments work harder collectively than they ever could in isolation. That is the practical shape of the shift away from standalone tools: not a replacement of supplier assurance, but an integration of it across organisational boundaries.
What Boards Actually Want to See in Third-Party Risk Reporting
When a major supplier is compromised, the first question a board will ask is how exposed the organisation is. In 2026, only 6% of organisations can answer that question in under four hours. 45% need between four and 24 hours, 26% need one to three business days, and 23% need more than a week and manual outreach to suppliers to build a picture of their exposure.
.png)
That is not a reporting problem. It is a data problem that only becomes visible in a reporting context. A board asking for exposure figures within hours of an incident is asking for something that most TPRM programmes were never built to produce, because the underlying supplier data is not structured, not centralised, and not current enough to query quickly. The same pattern shows up further upstream, in how long it takes to bring a new supplier on board in the first place. Only 38% of organisations can complete security due diligence on a new supplier within two weeks. 34.6% need three weeks or more, and 12% need over a month. Slow onboarding is often treated as a procurement inconvenience, but it is the same underlying weakness as slow incident response: assurance data that has to be gathered fresh each time, rather than data that already exists in a usable, shared form.
This is also where the regulatory timeline in Section 3 becomes a practical reporting requirement rather than a distant compliance deadline. UK financial firms must submit standardised registers of material third-party arrangements by March 2027. Boards that want to be ready for that deadline, rather than scrambling to meet it, need reporting built around the same standardised, continuously updated supplier data that would also let them answer an exposure question in hours rather than days.
The organisations already operating this way are the ones in the Defend-as-One examples in this report. Their boards are not asking a security team to manually compile a picture of exposure after the fact. They are looking at a supply chain map that already exists, built collectively with peers, and updated on an ongoing basis rather than reconstructed each time something goes wrong.
Conclusion
None of the findings in this report suggest that UK organisations have failed to notice the risk in their supply chains. The opposite is true. Concern is high, incidents are frequent, and regulators are moving in the same direction across both the UK and EU. What the data shows instead is a gap between recognising the problem and having a process capable of matching its scale.
That gap has a shape. It runs through assessments that are periodic rather than continuous, visibility that stops at the first or second tier of suppliers, and incident response that depends on manual outreach rather than data that is already there. Closing it does not require organisations to discard their existing TPRM programmes. The government, local authority and financial services communities in this report built on what they already had, adding a shared, standardised layer that let their individual assessments surface risks none of them could see alone.
That combination, standardised data, continuous rather than annual assurance, and visibility built collectively with peers, is what Risk Ledger describes as Active Supply Chain Security. The regulatory direction, the incident data, and the appetite for collaboration in this report all point the same way. The organisations already working this way are not waiting for the next incident to find out what they don't know.
What security teams are reading next
The gap in this data isn't awareness. It's operational capacity. Teams that are closing it are typically doing three things: getting a working definition of criticality that goes beyond spend, building visibility past the first tier of suppliers, and testing whether collaboration can do what bilateral assessment can't.
Get the criticality call right first. Concentration risk and slow incident response both trace back to the same root cause: most programmes still sort suppliers by spend rather than by what the business actually depends on. Risk Ledger's guide to supplier criticality sets out the three questions that determine it, and the Supplier Criticality Matrix is a free tool for scoring suppliers against them consistently.
Map what sits beyond direct suppliers. With 50.2% of UK organisations able to see only their direct fourth parties, this is where most of the report's concentration risk was found. Beyond Third Parties: Tackling Nth-Party Risk in Modern Supply Chains explains why this blind spot forms, and the concentration risk data snapshot shows what turned up when three UK sectors mapped their dependencies together.
Move assessment from periodic to continuous. Only 40.6% of respondents have real-time monitoring of their suppliers' internal controls. Continuous Monitoring in Cyber Security and TPRM sets out what genuine continuous assurance requires, beyond external vulnerability scanning alone.
See what collaboration looks like at sector scale. The government, local authority and financial services examples in this report aren't hypothetical. Financial Services & Insurance, Public Sector and Critical National Infrastructure set out how these communities work in practice.
For the full survey data and methodology behind the figures in this article, the source report is available here: Every Link Matters: The State of Supply Chain Security 2026 — UK Edition.
FAQs: TPRM trends 2026
What is the biggest change in third-party risk management in 2026?
The shift is from periodic, bilateral assessment towards continuous, collaborative models. UK organisations still experience supply chain incidents at a high rate (82.4% in the past 12 months), but the 2026 data shows growing recognition that fixing this requires standardised, shared supplier data rather than more frequent versions of the same annual questionnaire.
Is traditional TPRM still effective in 2026?
Most organisations regard it as somewhat effective rather than highly effective. 60.4% of respondents in the 2026 survey call it somewhat effective at reducing supply chain cyber risk, down from a higher confidence level the year before, while incident rates have stayed largely unchanged. TPRM still provides useful evidence; the gap is in speed, visibility beyond direct suppliers, and continuous assurance.
What counts as continuous monitoring in third-party risk management?
Genuine continuous monitoring combines two things: external signals from a supplier's digital footprint (exposed ports, certificate issues, misconfigurations) and regular reassessment of internal controls such as access management, staff training and incident response capability. External vulnerability scanning alone, though often marketed as continuous monitoring, only covers the first half of that picture.
What do UK and EU regulators now expect from TPRM programmes?
Both are converging on the same requirement: firms must understand risk beyond their direct contracts, into subcontractors and deeper-tier dependencies. In the EU, DORA's Article 29 requires assessment of concentration and substitutability risk. In the UK, new FCA and PRA reporting rules will require standardised registers of material third-party arrangements by March 2027, and the Cyber Security and Resilience Bill introduces a Designated Critical Suppliers regime.
What is the difference between a critical supplier and a concentration risk?
A critical supplier is one an organisation has identified as essential to its own operations. A concentration risk is a dependency that only becomes visible once multiple organisations' supply chains are mapped together, for example when several peers unknowingly rely on the same fourth-party cloud provider. An organisation can have excellent oversight of its own critical suppliers and still miss concentration risk entirely, because it sits between organisations rather than within one.
Why do most organisations lose visibility beyond the fourth party?
Visibility typically depends on what a direct supplier discloses about its own suppliers, and that chain of disclosure weakens at each additional tier. In the 2026 survey, 50.2% of UK organisations have high visibility into direct fourth parties but only 30% have full visibility into the entire subcontractor chain supporting their important business functions. Dependencies mapped through shared platforms have been found to run as deep as the eighth tier.
How quickly can organisations assess their exposure after a supplier incident?
Slowly, for most. Only 6% of UK organisations can map their exposure across their supplier ecosystem within four hours of a major incident. 45% need between four and 24 hours, and 23% need more than a week and manual supplier outreach. This is generally a data structuring problem rather than a reporting problem: exposure mapping is only fast when supplier data is already standardised and centralised.
Does moving towards continuous or network-based supply chain security mean replacing existing TPRM processes?
No. The organisations covered in the underlying data, across UK government, local authorities and financial services, built a shared, standardised layer on top of their existing TPRM programmes rather than discarding them. The assessments and due diligence already in place remain the foundation; what changes is how current, comparable and collectively visible that data is.

