The community-bank guide says unavailable due-diligence evidence should lead to alternative information, controls, or monitoring—not an unexplained pass or a silent stop in the review.
Article 29 puts substitutability, repeated reliance on the same or connected providers, alternative solutions, and subcontracting risk into the assessment before critical ICT services are contracted.
For material outsourcing, the current supervisory statement treats exit as a planned, owned, costed, and risk-based test—not a clause that can wait for supplier failure.
Article 21 puts supply-chain security inside the risk measures for essential and important entities. A supplier score cannot replace the entity's own relationship-specific controls.
Federal banking agencies apply third-party risk principles across relationship types and structures. The operating record must explain how each arrangement works.
NIST's cyber supply-chain guidance does not reduce third-party risk to an onboarding questionnaire. It connects products, services, suppliers, system context, and risk response across the life of the relationship.
ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.
The finalized C-SCRM quick-start guide gives organizations a clearer floor for evaluating technology suppliers before risk teams build a larger program around it.
APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.
SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.
The April package adds limited contractual exemptions, clarifies their management, and updates the material service-provider register ahead of the July commencement date.
The UK policy expands reporting beyond outsourcing, separates notification from register templates, and gives firms a year to govern the data behind material third-party arrangements.
Regulation & Standards 7 min read
Market context
Coverage is attached to the companies, capabilities, and standards it affects so that market records change with evidence rather than headlines alone.