● Included in Standard

Know who has access to your data. And when you last checked.

The Supplier Register helps you track every third party that holds or accesses your organisation's data — their criticality, data protection agreements, access levels and review history — in one structured place.

Supplier Register — 8 suppliers
Supplier
Criticality
DPA
Last Review
Microsoft 365
Critical
Signed
2 months ago
Stripe
Critical
Signed
4 months ago
IT Support Ltd
High
Pending
⚠ Overdue
Mailchimp
Medium
Signed
1 month ago
Website Agency
High
Missing
⚠ Never

Your supply chain is part of your attack surface.

Most cyber breaches don't happen by attacking an organisation directly — they happen through a supplier. The GDPR also places obligations on you as data controller to know who processes personal data on your behalf, and to have appropriate agreements in place. The Supplier Register gives you that visibility and the audit trail to prove it.

📋

GDPR compliance

The UK GDPR requires data controllers to have Data Processing Agreements (DPAs) with suppliers who process personal data. The Supplier Register tracks DPA status across your supply chain.

🕵

Supply chain attacks

Attackers increasingly target smaller suppliers to reach larger organisations. Knowing which suppliers have access to which systems and data helps you assess and manage that risk.

🏆

Cyber Essentials alignment

Cyber Essentials includes expectations around access control and third-party access. The Supplier Register directly supports your CE evidence gathering.

Everything you need to know about each supplier.

Each supplier record captures the full picture — not just a name and contract date, but the details that matter for data protection compliance and security risk management.

📋

Criticality and data access

Tag each supplier as Critical, High, Medium or Low risk, and record what data they hold, where they store it, and what access they have to your systems.

🔑

DPA and certification status

Track whether a Data Processing Agreement is in place, and log any certifications (ISO 27001, Cyber Essentials, SOC 2) held by the supplier.

📅

Review history

Log supplier reviews with a dated record of who reviewed, what risk rating was assigned, and any notes from the review. Know at a glance which suppliers are overdue.

📦

Archive, don't delete

When a supplier relationship ends, archive the record rather than delete it. The full history remains for audit purposes without cluttering your active register.

Stat cards at a glance

Total suppliers
14
Reviews overdue
3
Missing DPA
2
Critical suppliers
4
Stats update automatically as you add and review suppliers.

Stay on top of third-party risk.

Supplier Register is included in all Cyber Assure plans. Get in touch to find out more.

Get StartedView Pricing