Supply chain visibility
Supplier Criticality Matrix
Score suppliers by impact and likelihood side by side, then see them plotted and sorted automatically. Add your own supplier list below and try it now.
RISK, NOT JUST CRITICALITY
What Is a Supplier Criticality Matrix?
A supplier criticality matrix plots suppliers against two things at once: impact (what happens if this supplier fails) and likelihood (how probable a security problem actually is).
Most templates only ever measure one of these and call the result "criticality." That's the gap this tool is built to close.
Most templates only ever measure one of these and call the result "criticality." That's the gap this tool is built to close.
Suppliers that look important but have never actually been assessed for security
The moderate-impact suppliers most teams never get around to
Suppliers holding sensitive data with no operational role at all
Existing suppliers on your books versus new suppliers coming in
Where regulation designates a supplier as critical regardless of your own score
A single score is not the same as two dimensions. Plotting impact and likelihood separately surfaces suppliers that don't look dangerous on impact alone, moderate in importance, but genuinely uncertain on security, which is often the group carrying the most realistic risk.
CRITICAL VS HIGH-RISK
Why This Tool Tags Critical and High-Risk Separately
A critical supplier is one your business depends on operationally, if they went down, something stops. A high-risk supplier could seriously damage the business even if you'd barely notice them failing, most often through the data or access they hold, not through anything going offline.
Critical suppliers sit inside the wider set of high-risk suppliers, not alongside it.
Critical suppliers sit inside the wider set of high-risk suppliers, not alongside it.
Operational dependency, would the business actually stop
Data sensitivity, independent of whether anything stops working
System access, what a compromised supplier could reach
Suppliers that fail one test and pass the other entirely
Regulatory designation as a separate override, not a third category
Critical is not the same as high-risk. Score only for criticality and the confidentiality-driven risks quietly fall out of scope. This tool tags both categories separately, so a supplier holding sensitive data but with no real operational weight doesn't get missed just because it isn't "critical" in the traditional sense.
THREE COMMON MISTAKES
Where Most Criticality Matrices Go Wrong
None of these are careless. Each one is a shortcut that feels reasonable under real time pressure, and each one quietly narrows what actually gets looked at.
Asking the supplier how critical they are
Scoring impact and stopping there
Treating full supply chain visibility as impossible
Missing the moderate-impact, high-likelihood group entirely
Treating the exercise as a one-off rather than an ongoing judgement
Impact alone is not the same as risk. The suppliers with moderate impact but real security uncertainty are often more realistic risks than the biggest names on the list, and they're the group most impact-only processes miss completely.
CRITICAL VS HIGH-RISK
Why This Tool Tags Critical and High-Risk Separately
A critical supplier is one your business depends on operationally, if they went down, something stops. A high-risk supplier could seriously damage the business even if you'd barely notice them failing, most often through the data or access they hold, not through anything going offline.
Critical suppliers sit inside the wider set of high-risk suppliers, not alongside it.
Critical suppliers sit inside the wider set of high-risk suppliers, not alongside it.
Operational dependency, would the business actually stop
Data sensitivity, independent of whether anything stops working
System access, what a compromised supplier could reach
Suppliers that fail one test and pass the other entirely
Regulatory designation as a separate override, not a third category
Critical is not the same as high-risk. Score only for criticality and the confidentiality-driven risks quietly fall out of scope. This tool tags both categories separately, so a supplier holding sensitive data but with no real operational weight doesn't get missed just because it isn't "critical" in the traditional sense.
FOUR QUESTIONS to ask youself
How to Assess Supplier Criticality
The Suppler Criticality Matrix scores against four questions.
The first three combine into an impact score. Likelihood stays on its own axis, deliberately simple enough to run against a real supplier list rather than a hypothetical one.
The first three combine into an impact score. Likelihood stays on its own axis, deliberately simple enough to run against a real supplier list rather than a hypothetical one.
What does this supplier do for us?
What data do they hold?
What access do they have into our systems?
How confident are you in their security?
Why the supplier is never the right person to ask?
Asking the supplier is not the same as assessing them. It sounds efficient, but a supplier isn't the right party to answer a question about your business, and their incentives aren't always aligned with an honest answer.
FOUR FACTORS, ONE OVERRIDE
What Actually Goes Into a Supplier Criticality Score?
Impact and likelihood aren't single numbers, they're built from four separate questions, plus one override that sits outside the model entirely and can outrank all four.
01
Operational Dependency
Would an essential function stop without this supplier?
02
Data Sensitivity
What sensitive data do they hold, regardless of their operational role?
03
System Access
What could they reach inside your systems if compromised?
04
Security Confidence
How confident are you in their own security posture?
05
Regulatory Override
Could a regulator designate them critical regardless of your own score?
FAQ
Supplier Criticality Matrix FAQ
What's the difference between a criticality matrix and a risk matrix?
How many suppliers should I score in this tool?
Does this replace a formal risk assessment?
FROM SNAPSHOT TO CONTINUOUS
See This Running Across Your Real Supply Chain
This tool scores what you tell it, once. It doesn't notice a contract changing, a supplier's access expanding, or a regulator designating them critical while nobody's looking, that's exactly the gap a spreadsheet always leaves.
Book a consultation to see what continuous, evidence-backed criticality scoring actually looks like across your real supplier network.
Ready to map your exposure?
Speak with a Risk Ledger expert about where hidden dependencies and concentration risks may exist across your supplier ecosystem.