Supply Chain Security

Suppliers

Demonstrate your supply chain security.

Enterprise customers, insurers, and procurement teams are asking harder questions about suppliers and their supply chain security.

Cyber security due diligence has moved from a checkbox exercise into a genuine barrier to winning and keeping contracts.

Australian Cyber Essentials (ACE) gives suppliers an evidence-based, independently certified cyber security pathway they can use to respond with confidence.

Cyber incidents at supplier level have caused some of the most significant data breaches in recent years, and customers at enterprise scale are no longer willing to take a supplier’s word for it.

  • They want documentation.
  • They want evidence.
  • Increasingly, they want third-party certification

For many suppliers, this creates a practical problem. Cyber security frameworks can be complex, expensive to navigate, and disconnected from the day-to-day reality of running a small or medium-sized business. ACE was built to close that gap.

What ACE Gives Suppliers

  • independent certification issued by Bureau Veritas demonstrating your supply chain security
  • a practical pathway, supported by the ACE programme team
  • a stronger response to customer assurance requests
  • a tiered maturity model
  • an ISMS component that supports stronger governance
  • a reusable credential that can be used across multiple customer relationships

Common Questions

We already have controls in place.

That existing work should help. ACE is intended to recognise and build on what organisations are already doing, not force them to start from zero.

We are too small for a major certification programme.

ACE is designed to be practical for organisations without large internal security teams.

We already completed a customer questionnaire.

A customer questionnaire usually addresses one customer at one point in time. ACE is intended to provide a more credible and reusable assurance outcome that you can provide to any other enterprise to demonstrate your supply chain security.

We already hold ISO/IEC 27001 certification.

That should provide a strong foundation. Existing evidence and governance maturity may assist with the ACE journey.

Combined diagonal image to represent the types of businesses in a supply chain Australian Cyber Essentials (ACE) can help protect. Customer service / call centres, warehouse & logistics and technical and IT third parties