What Makes A Supplier Critical?

What makes a supplier critical, the criteria security teams should use, common mistakes to avoid and how to prioritise supplier risk effectively.
Risk Ledger
|
Company
August 3, 2026
3
mins read
What Makes A Supplier Critical?

A supplier is critical when your business depends on them for something it cannot afford to lose, such as an essential operation or a specific service, or the wellbeing of the people you serve. Most supplier assessments only concentrate on these. Other suppliers often go unnoticed.

There is no standard definition of critical, nor necessarily should there be. What is critical to one business will not be critical to another.
Emily Hodges Emily Hodges COO, Risk Ledger

Could your business keep running without this supplier?

Operational dependency is the plainest route to criticality. A supplier is operationally critical when your business cannot keep an essential function running without them, and there's no reasonable substitute available in time to matter.

Working this out means starting from the business, not the supplier list. You name the operations that would genuinely stop the organisation functioning if they failed, then trace which suppliers sit underneath them. Whatever comes out the other end of that exercise is your critical supplier list.

The part that’s actually worth your time dwelling on is what "no substitute" actually means in practice. It isn't enough that an alternative supplier exists somewhere in theory. The alternative has to be contracted, qualified, and able to step in within a timeframe that actually protects the operation, not just available on paper.

Teams routinely assume a backup exists because someone mentioned one in a meeting once. Whether that backup has ever been tested under real conditions is a different question, and usually the one that matters more.

This is really one question with two levels of severity. Sometimes it's the whole business that stops, but more often, it's one specific thing the business delivers, to a customer, a regulator, or another team internally, that stops or degrades, while everything else keeps running. That narrower version is easy to underweight, because the wider business carries on regardless. It's still the same question, just asked about one output instead of the whole organisation, and it deserves the same test: could this stop, and is there a real, tested alternative if it did?

Three Supplier Criticality Questions

What data and access could a supplier put at risk?

Data access measures a different kind of criticality to the two dependency lenses above it. A supplier can be entirely dispensable operationally, no essential function or service depends on them, and still be critical because of what they can see, alter, or reach inside your organisation.

This maps onto confidentiality and integrity, the two thirds of the CIA triad that operational and service dependency don't cover. It's also the part that tends to get the least airtime in practice, because criticality conversations naturally gravitate toward "what stops working," and this isn't that question at all.

The access point matters more than it sounds like it should… if a supplier were taken over by someone you can't trust, the real question is what they'd have access to. If they can reach into your systems, that's a route to lateral movement into your own environment.

There's a softer version of the same risk too, if a supplier relationship is trusted enough that an unusual request, an invoice, a change of bank details, would get actioned without a second look, that trust itself is an exploitable access point, no technical foothold required.

This is where supplier risk extends far beyond an operational outage and does a completely different kind of lasting damage. The June 2024 attack on Synnovis, the pathology partnership providing blood testing and diagnostics to Guy's and St Thomas' and King's College Hospital NHS Foundation Trusts, illustrates this double-edged threat.

While the loss of pathology systems caused an immediate availability crisis—dropping testing capacity to ten per cent, cancelling thousands of appointments, and straining blood supplies—the access side of the equation yielded a severe confidentiality disaster. Because Synnovis held deep access to sensitive clinical data, threat actors exfiltrated roughly 400 gigabytes of private records. When extortion demands were refused, patient names, dates of birth, NHS numbers, and lab results were published on the dark web.

The operational paralysis proved that Synnovis was vital to daily hospital function, but the dark web leak demonstrated the confidentiality side of supplier criticality: even if operational downtime is eventually resolved, a breach of trusted data access leaves permanent damage that cannot be undone.

When a regulator decides a supplier is critical for you

Everything above is a judgement your own business makes, what you depend on, what data and access matter. Regulation doesn't ask permission to agree with that judgement.

Regulatory impact isn't a judgement your business gets to make alone. Both DORA and the UK's Cyber Security and Resilience Bill explicitly expect organisations to understand dependencies for their critical services, regardless of whether the organisation would have flagged those suppliers as critical on its own.

DORA already places direct obligations on financial services firms to manage risk from critical ICT third parties, with concentration risk and resilience testing built into the regulation itself.

A supplier can sit low on your internal scale and still trigger a formal obligation, because of what the regulation requires you to demonstrate about it, not because of anything your own assessment concluded.

The UK's Cyber Security and Resilience Bill takes this further, and it's newer ground. Still progressing through Parliament, expected to reach Royal Assent later in 2026, it introduces a "designated critical supplier" concept, letting regulators designate specific third parties as critical where their disruption could cause significant knock-on effects. 

Either way, this is the one lens where the answer isn't yours to make. A regulator can define a supplier as critical to you, on their own terms, independent of your internal risk register.

Treat this as a check you run after your own assessment, not a third question to weigh alongside the other two. A supplier can score low on both operational dependency and data access by your own measure and still be critical the moment a regulator says so.

Examples of critical suppliers, by type

Operational dependency and data access aren't two separate checklists, most real suppliers touch both, which is why treating "critical" as a single yes-or-no question misses so much. A supplier can fail one test and pass the other entirely, and either one is enough to matter. Likelihood is a different kind of question again, covered separately below, since it's about the supplier's own security, not about how much you depend on them.

Quick reference

Criterion, question, and a real example

Two questions decide criticality. Likelihood is a separate, third question that turns this into an actual risk picture, not a criterion to score alongside the other two.

Criterion The question to ask Example
Operational dependency Does an essential function, or one specific output of the business, stop without them, with no tested substitute available in time? A specialist maintenance contractor with no accredited alternative for a physical operation.
Data and access What could they see, change, or reach inside your systems, and how much damage would that do even if nothing stopped working? Synnovis, June 2024: NHS trusts kept operating, but pathology capacity in south-east London dropped to roughly 10% of normal, and patients felt the consequences directly.
Likelihood Separately from impact, how confident are you in this supplier's security? This is the other half of the risk picture, not a property of how important the supplier is. Covered in the assessor on the identification page.

Where regulation fits

Regulatory designation sits outside this table on purpose. A regulator can designate a supplier as critical under DORA or the UK's Cyber Security and Resilience Bill regardless of what these two questions conclude. Check it separately, don't fold it into the score.

Criticality changes, even when nobody updates the file

Everything above treats criticality as something you work out once, for one supplier, at a single point in time. In practice, none of these five answers stay fixed. 

Most organisations run this as a periodic exercise, a review once a year, or whenever someone remembers to ask. The issue isn't the five criteria themselves, it's that nothing is watching for when the answer to any of them changes in between reviews.

That's a harder problem to solve in prose than it is to just try against a real supplier

Put this into practice

Identifying critical suppliers is much easier with a consistent framework.

Use our free Supplier Criticality Matrix to help you assess suppliers using the same impact and likelihood approach described in this guide.

What security teams ask next

Key takeaways

What actually makes a supplier critical, in short

Criticality isn't one test, and it isn't the whole picture either. Most real suppliers only fail some of these, and none of it means anything until you also ask how likely a problem actually is.

  • Critical ≠ high-risk

    Critical suppliers sit inside the wider set of high-risk suppliers. A supplier can be non-critical and still hold enough sensitive data to seriously damage the business.

  • Operational dependency, at any scale

    Sometimes the whole business stops. More often it's one specific service or output that stops, while everything else carries on. Same test either way: is there a real, tested alternative.

  • Data and access carry their own criticality

    Entirely dispensable operationally, still critical because of what they can see, alter, or reach inside your systems, or what happens if that data is exposed.

  • Regulation can override your own view

    A regulator can designate this supplier as critical on their terms, under DORA or the UK's Cyber Security and Resilience Bill, regardless of what your own assessment concluded.

  • Impact is only half the picture

    Everything above answers what happens if this supplier fails. It says nothing about how likely that is. Likelihood, how good is this supplier's security, is what turns this into an actual priority list, and it's covered on the identification page, not repeated here.

  • Most suppliers touch more than one

    A supplier can fail one test and pass another entirely, which is why both are worth checking, not just the first one you think of.

Where to start

Run a supplier against operational dependency and data access, check regulatory designation separately, and don't stop there. Likelihood is what actually turns this into a risk-based priority list, and it's covered on the identification page, not repeated here.

Pattern Trapezoid Mesh

Get the security manager's briefing

Monthly research, case studies and practical guides you won't find anywhere else.

Join thousands of security managers turning their TPRM programmes into success stories.