What is included?
Guided work process, 13 editable work tools, SCMS Cockpit, 9 AI assistants and documentation.
Work through supplier and third-party cybersecurity in a structured way – from scope, criticality and due diligence through contractual requirements, SBOM/VEX, vulnerabilities and incidents to monitoring, management decisions and evidence.
For procurement, supply chain, information security, product security, quality and compliance teams that need to handle supplier and third-party cybersecurity in a structured, case-based way.
Guided work process, 13 editable work tools, SCMS Cockpit, 9 AI assistants and documentation.
Criticality, due diligence, contracts, evidence, vulnerabilities, incidents, monitoring and approval.
No legal advice, supplier audit, automatic classification or approval.
Supplier information, security requirements, evidence, vulnerabilities, incidents and decisions are often spread across teams and files.
A connected working system for traceable assessment, documentation, monitoring and management decisions.
Connect scope, criticality, due diligence, evidence, measures and decisions.
Use editable templates and the SCMS Cockpit for the actual working process.
Keep changes, vulnerabilities, incidents, reviews and approval status visible.
Use the Practice Kit to structure supplier, service and component cases. It does not replace a legal, technical or case-specific assessment.
Establish the relevant dependency, service context, criticality and assessment boundary.
Document supplier information, evidence gaps, assessment and required follow-up.
Structure requirements, notification paths, evidence and review expectations.
Link external notifications, components, versions, assessment status and internal escalation.
Keep reassessment triggers, measures, reviews and management decisions traceable.
Connected work tools for supplier, service and technical dependency cases.
Orientation, sequence and working logic for the end-to-end process.
Templates and variants for scope, criticality, due diligence, requirements, evidence and lifecycle work.
Central working file for registers, status, reviews, measures and management overview.
System-neutral assistive workflows for structuring and completeness review.
Start guidance, worked example, licence, sources, manifest and change log.





Eight connected steps bring supplier cybersecurity work into a controlled state.
Begin with a working copy and apply the process to one concrete supplier, service or technical dependency.
Read START HERE and create a controlled working copy.
Save the SCMS Cockpit as the central working file.
Capture the supplier or service case with a clear reference.
Work through scope, criticality and due diligence.
Record requirements, evidence, vulnerabilities, incidents and monitoring.
Document the decision, conditions and next review.
Perpetual internal use and editing within the named legal entity. Blank templates and source files may not be passed on.
Support for download, file access, package structure and reproducible technical product errors. No individual legal or specialist advice.
The purchased version applies. Later versions and additional content are included only where expressly stated.
No. It structures work and evidence but does not replace case-specific specialist assessment.
Yes. The work tools are provided for internal editing and controlled use.
No. They support structuring and review. Decisions remain human responsibilities.
Support covers download, file access, package structure and reproducible technical product errors.
€249.00 incl. VAT. Binding purchase and delivery information is available in the CopeCart checkout.