Regulated Incident Management Ecosystem Versão portuguesa

Service sheet CSO-06

Product and Digital Supply Chain Security

Analysis of the duties applicable to products with digital elements and of the security requirements to impose on, and meet within, the supply chain.

The problem it solves

Security no longer stops at the boundary of the organisation. Those who make software or devices have their own reporting duties; those who buy must require them by contract.

Who it is for

  • Manufacturers and distributors of products with digital elements;
  • Covered entities that depend on critical suppliers;
  • Procurement and legal departments.

Deliverables

  • Map of products and applicable duties;
  • Vulnerability handling and reporting procedure;
  • Contractual security and alerting clauses;
  • Supplier assessment criteria.

Method

  1. 01

    Inventory

    Products and suppliers.

  2. 02

    Frame

    Applicable duties.

  3. 03

    Contract

    Clauses and alerts.

  4. 04

    Verify

    Periodic assessment.

Regulatory basis

  • Regulation (EU) 2024/2847, whose Article 14 requires reporting of actively exploited vulnerabilities and severe incidents, applicable since 11 September 2026;
  • Article 27 of Decree-Law 125/2025, on supply chain security.

Expected results

  • Product duties identified and met;
  • Suppliers assessed and contractually bound;
  • Fewer surprises coming from the supply chain.

An appointed role is not yet a role performed

Start by checking your organisation scope or ask for a proposal to structure the role.