A supplier is critical when your business depends on them for something it cannot afford to lose, such as an essential operation or a specific service, or the wellbeing of the people you serve. Most supplier assessments only concentrate on these. Other suppliers often go unnoticed.
Could your business keep running without this supplier?
Operational dependency is the plainest route to criticality. A supplier is operationally critical when your business cannot keep an essential function running without them, and there's no reasonable substitute available in time to matter.
Working this out means starting from the business, not the supplier list. You name the operations that would genuinely stop the organisation functioning if they failed, then trace which suppliers sit underneath them. Whatever comes out the other end of that exercise is your critical supplier list.
The part that’s actually worth your time dwelling on is what "no substitute" actually means in practice. It isn't enough that an alternative supplier exists somewhere in theory. The alternative has to be contracted, qualified, and able to step in within a timeframe that actually protects the operation, not just available on paper.
Teams routinely assume a backup exists because someone mentioned one in a meeting once. Whether that backup has ever been tested under real conditions is a different question, and usually the one that matters more.
This is really one question with two levels of severity. Sometimes it's the whole business that stops, but more often, it's one specific thing the business delivers, to a customer, a regulator, or another team internally, that stops or degrades, while everything else keeps running. That narrower version is easy to underweight, because the wider business carries on regardless. It's still the same question, just asked about one output instead of the whole organisation, and it deserves the same test: could this stop, and is there a real, tested alternative if it did?

What data and access could a supplier put at risk?
Data access measures a different kind of criticality to the two dependency lenses above it. A supplier can be entirely dispensable operationally, no essential function or service depends on them, and still be critical because of what they can see, alter, or reach inside your organisation.
This maps onto confidentiality and integrity, the two thirds of the CIA triad that operational and service dependency don't cover. It's also the part that tends to get the least airtime in practice, because criticality conversations naturally gravitate toward "what stops working," and this isn't that question at all.
The access point matters more than it sounds like it should… if a supplier were taken over by someone you can't trust, the real question is what they'd have access to. If they can reach into your systems, that's a route to lateral movement into your own environment.
There's a softer version of the same risk too, if a supplier relationship is trusted enough that an unusual request, an invoice, a change of bank details, would get actioned without a second look, that trust itself is an exploitable access point, no technical foothold required.
This is where supplier risk extends far beyond an operational outage and does a completely different kind of lasting damage. The June 2024 attack on Synnovis, the pathology partnership providing blood testing and diagnostics to Guy's and St Thomas' and King's College Hospital NHS Foundation Trusts, illustrates this double-edged threat.
While the loss of pathology systems caused an immediate availability crisis—dropping testing capacity to ten per cent, cancelling thousands of appointments, and straining blood supplies—the access side of the equation yielded a severe confidentiality disaster. Because Synnovis held deep access to sensitive clinical data, threat actors exfiltrated roughly 400 gigabytes of private records. When extortion demands were refused, patient names, dates of birth, NHS numbers, and lab results were published on the dark web.
The operational paralysis proved that Synnovis was vital to daily hospital function, but the dark web leak demonstrated the confidentiality side of supplier criticality: even if operational downtime is eventually resolved, a breach of trusted data access leaves permanent damage that cannot be undone.
When a regulator decides a supplier is critical for you
Everything above is a judgement your own business makes, what you depend on, what data and access matter. Regulation doesn't ask permission to agree with that judgement.
Regulatory impact isn't a judgement your business gets to make alone. Both DORA and the UK's Cyber Security and Resilience Bill explicitly expect organisations to understand dependencies for their critical services, regardless of whether the organisation would have flagged those suppliers as critical on its own.
DORA already places direct obligations on financial services firms to manage risk from critical ICT third parties, with concentration risk and resilience testing built into the regulation itself.
A supplier can sit low on your internal scale and still trigger a formal obligation, because of what the regulation requires you to demonstrate about it, not because of anything your own assessment concluded.
The UK's Cyber Security and Resilience Bill takes this further, and it's newer ground. Still progressing through Parliament, expected to reach Royal Assent later in 2026, it introduces a "designated critical supplier" concept, letting regulators designate specific third parties as critical where their disruption could cause significant knock-on effects.
Either way, this is the one lens where the answer isn't yours to make. A regulator can define a supplier as critical to you, on their own terms, independent of your internal risk register.
Treat this as a check you run after your own assessment, not a third question to weigh alongside the other two. A supplier can score low on both operational dependency and data access by your own measure and still be critical the moment a regulator says so.
Examples of critical suppliers, by type
Operational dependency and data access aren't two separate checklists, most real suppliers touch both, which is why treating "critical" as a single yes-or-no question misses so much. A supplier can fail one test and pass the other entirely, and either one is enough to matter. Likelihood is a different kind of question again, covered separately below, since it's about the supplier's own security, not about how much you depend on them.
Criticality changes, even when nobody updates the file
Everything above treats criticality as something you work out once, for one supplier, at a single point in time. In practice, none of these five answers stay fixed.
Most organisations run this as a periodic exercise, a review once a year, or whenever someone remembers to ask. The issue isn't the five criteria themselves, it's that nothing is watching for when the answer to any of them changes in between reviews.
That's a harder problem to solve in prose than it is to just try against a real supplier
Put this into practice
Identifying critical suppliers is much easier with a consistent framework.
Use our free Supplier Criticality Matrix to help you assess suppliers using the same impact and likelihood approach described in this guide.
What security teams ask next
- How Should We Prioritise Supplier Assessments?
- Are We Focusing Supplier Assurance on the Right Suppliers?
- What Hidden Supplier Dependencies Could Increase Our Risk?
- Use the Supplier Criticality Matrix



