Supplier Self Assessment
Cyber Security
- Does your organisation have a relevant cyber security certification (e.g. ISO 27001)? 
- Does your organisation have a formal cyber security policy? 
- Are the organisation's security policies and procedures reviewed and updated at least annually? 
- When were they last updated? 
- Please briefly describe which areas are addressed within your cyber security policy 
- Does your organisation have established procedures and technical, operational and organisational measures to secure your organisation's cyber security by avoiding disruptions and minimising the impact of security incidents? 
- Has your organisation gone through cyber security audits, assessments and inspections? 
- Please upload the results of these cyber security audits and assessments taking account of potential "need-to-know" content and making sure business secrecy is preserved 
- Does your organisation have a responsible person or team for cyber security within your organisation? 
- Does your organisation use security softwares to protect your systems? 
- Are your systems and software updated regularly? 
- How often are your systems and software updated? 
- Does your organisation enforce access controls and permissions to ensure the protection of sensitive data? 
- Does your organisation have a backup and recovery plan in place? 
- Does your organisation perform simulations of failures? 
- Are employees regularly trained regarding cyber security? 
- How often are employees trained? 
- Does your organisation regularly conduct penetration tests to identify possible security vulnerabilities and to check security measures? 
- Does your organisation have an incident response plan in place for handling cyber security incidents? 
- Does your organisation have a plan for reporting an incident to relevant authorities and how to do so? 
- Has your organisation experienced a cybersecurity incident in the past 12 months? 
- Does your organisation have a process to learn and improve from experienced cyber security incidents? 
- Does your organisation manufacture, distribute or import products with digital elements (e.g., IoT products)? 
- Does your organisation design, develop and manufacture the products with digital elements to ensure an appropriate level of cyber security? 
- Is an adequate level of cybersecurity guaranteed in the development, testing, manufacturing and production of products with digital elements? 
- How is this level of cybersecurity defined? 
- Will your product have a declaration of conformity for the Cyber Resilience Act available? 
- Does your organisation or your suppliers offer cyber security updates for the products with digital elements? 
- For what periods? What is your update policy (e.g. only the current version receives a cybersecurity update and can be obtained free of charge for updates)? 
- Does your organization have a plan to report vulnerabilities or cybersecurity incidents related to products with digital elements? 
- Do you have a central point of contact so that possible cybersecurity-relevant errors in your products can be reported to you? 
- What is your desired response time? 

