A maintained reading library for the rules, supervisory expectations, and technical standards that change how organizations inventory, assess, monitor, govern, and exit third-party relationships.
Foundational NIST guidance for integrating cybersecurity supply-chain risk management into enterprise risk management. It covers strategy, policy, risk assessment, acquisition, supplier oversight, controls, and risk response across organizational levels and the system life cycle.
National Institute of Standards and Technology · United States; broadly adopted as voluntary guidance outside federal use
An implementation-oriented guide for conducting due-diligence research on ICT suppliers and products before acquisition or during an existing relationship. Its assessment components are foreign ownership, control, or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers.
National Institute of Standards and Technology · United States; usable as voluntary guidance by public- and private-sector acquirers
Joint supervisory guidance covering the full third-party relationship life cycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. It emphasizes proportionality, governance, inventory, critical-activity identification, documentation, independent review, and oversight of subcontractors where appropriate.
Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency · United States banking organizations supervised by the issuing agencies
A harmonized digital-operational-resilience regime for EU financial entities. Chapter V requires ICT third-party risk to be managed within the ICT risk framework and includes strategy, contractual, concentration, register-of-information, criticality, exit, and oversight provisions.
European Parliament and Council of the European Union · European Union financial sector and in-scope ICT third-party arrangements
2019 final report remains listed as applicable; replacement third-party-risk guidelines for non-ICT services were under review after a consultation that closed October 8, 2025 February 24, 2019
Applicable EBA guidance defining outsourcing, identifying critical or important functions, and setting expectations for governance, records, pre-outsourcing analysis, due diligence, contracting, access and audit rights, security, subcontracting, monitoring, concentration, exit strategies, and supervisory cooperation. The EBA has been updating the framework to align non-ICT third-party risk with DORA.
European Banking Authority · EU credit institutions, investment firms, payment institutions, and electronic-money institutions within the stated scope
Current rule in effect; HHS separately proposed strengthened cybersecurity requirements on January 6, 2025 February 19, 2003
The Security Rule requires covered entities and business associates to protect electronic protected health information with administrative, physical, and technical safeguards. Organizational requirements include written business-associate arrangements, satisfactory assurances, flow-down obligations to subcontractors, incident reporting, and required documentation.
U.S. Department of Health and Human Services, Office for Civil Rights · United States covered entities and business associates subject to HIPAA
In force; supplemented by October 21, 2025 DFS guidance on managing third-party service-provider risk October 31, 2023
Part 500 requires a risk-based cybersecurity program for covered entities. Section 500.11 requires written policies and procedures for third-party service providers with access to information systems or nonpublic information, including identification, risk assessment, minimum practices, due diligence, periodic assessment, and relevant contractual protections.
New York State Department of Financial Services · New York DFS-regulated covered entities
Current active version as of July 18, 2026 June 10, 2024
The current PCI DSS baseline for protecting account data. Requirement 12.8 addresses management of third-party service-provider relationships, including due diligence, agreements, clear responsibility allocation, a maintained provider list, and at least annual monitoring of provider compliance status.
PCI Security Standards Council · Organizations whose payment-card obligations require PCI DSS compliance and their relevant third-party service providers
CPS 230 requires APRA-regulated entities to manage operational risk, maintain critical operations through disruption, and manage risks arising from service providers through policy, formal agreements, monitoring, and accountable governance.
Australian Prudential Regulation Authority · APRA-regulated banks, insurers, private health insurers, and registrable superannuation entity licensees
Current statement effective December 31, 2024; March 2026 update takes effect March 18, 2027 March 30, 2021
SS2/21 sets expectations for governance, materiality, pre-contract assessment, due diligence, contracts, data security, access and audit rights, subcontracting, monitoring, business continuity, concentration, and exit across outsourcing and third-party arrangements.
Bank of England Prudential Regulation Authority · PRA-regulated firms in the United Kingdom
In force; application depends on national transposition and entity scope December 26, 2022
NIS2 establishes cybersecurity risk-management and incident-reporting obligations for covered entities. Article 21 expressly includes supply-chain security and security-related aspects of relationships with direct suppliers and service providers.
European Parliament and Council of the European Union · EU Member States and essential or important entities within the directive's scope as implemented in national law
Published standard under systematic review as of July 15, 2026 July 31, 2021
Part 1 establishes the concepts and framing for information and communication technology supplier relationships, including risks that arise when organizations acquire products and services or participate in supply chains.
International Organization for Standardization and International Electrotechnical Commission · Voluntary international standard unless adopted through contract, policy, certification scope, or regulatory expectation