/ THE SHORT ANSWER
- 01Prioritise suppliers by access and operational consequence.
- 02Ask for demonstrations and scoped evidence.
- 03Include service termination and emergency support in review.
- 04Reassess access when the support arrangement changes.
/ dotSuper point of view
Supplier assurance is useful when it determines what a supplier may connect to, change and retain.
Start with the supplier who can change something
Financial spend is useful for commercial management, but it does not describe cyber access.
The smaller contractor may hold credentials capable of changing production equipment.
ACSC's joint Secure by Demand publication encourages OT buyers to consider security characteristics when procuring products.[
1] Our recommendation is to extend that question to the full support arrangement.
Identify the vendor, subcontractors, connection methods and people who can change settings after delivery.
Build the first assurance list from consequences: can the supplier stop production, alter a configuration, access customer information or prevent recovery?
A supplier with no technical access may need a simpler review.
Proportionate assurance preserves attention for relationships where evidence changes the decision.
Replace general promises with observable questions
Request a demonstration in an appropriate non-production environment or a documented explanation matched to your architecture.
A broad claim that remote access is secure leaves those questions unresolved.
For updates, ask how the manufacturer communicates vulnerabilities, supplies supported fixes and handles products approaching end of support.
Record which parts of that process belong to the equipment vendor and which belong to your service contractor.
Unclear responsibility becomes expensive when a change is urgent.
The joint OT connectivity guidance addresses controlled connectivity and least privilege.[
2] Applied to procurement, ask whether the proposed support method can operate within your approved access design.
A vendor request to bypass that design should create an explicit decision, rather than becoming a convenience exception.
Make evidence reusable without making it universal
Link a contract clause to the particular service it governs.
A supplier may provide several products with different hosting and support arrangements, so a single corporate assurance pack is rarely the whole answer.
Separate information you can share with operational managers from sensitive technical details.
Decision makers need to know the accepted exposure and conditions of access.
They do not necessarily need unrestricted copies of credentials, network diagrams or the supplier's confidential security documentation.
Reuse evidence only after confirming that its scope covers the new purchase.
Adding a second site, changing a subcontractor or enabling a new remote feature may invalidate the earlier conclusion.
Record the delta so the next review focuses on what actually changed.
An original evidence matrix for industrial purchasing
It is not an official certification scheme.
Complete the decision column with an acceptance condition or an escalation owner, rather than recording every answer as merely present or absent.
Where a supplier cannot provide a requested document, consider whether another form of evidence addresses the risk.
A targeted demonstration may be more useful than a generic policy.
If uncertainty remains consequential, describe the operational limit you will apply.
| Area | Evidence request | Decision supported |
|---|---|---|
| Remote support | Session authorisation and termination flow | Which connections may operate |
| Privileges | Account scope and revocation method | What the supplier may change |
| Updates | Support commitments and notification route | Whether lifecycle support is adequate |
| Incident response | Contact and evidence responsibilities | Who acts during disruption |
| Exit | Data export and access removal process | Whether replacement is practical |
Hypothetical scenario: a low-cost support contract
The cheaper offer includes continuous remote access through a shared vendor account.
The alternative supports named, time-limited sessions through the workshop's approved route.
The workshop asks the first supplier whether it can use the approved arrangement.
If it can, the buyer obtains the revised scope and demonstrates the session lifecycle.
If it cannot, the operations and security owners decide whether the remaining exposure is acceptable before awarding the work.
This is not evidence that the more expensive supplier is inherently better.
It shows how a purchasing question can reveal a design constraint.
The final decision includes service quality, support availability and price, with the access implications made visible rather than hidden in onboarding.
Keep assurance connected to service management
Give the service owner responsibility for confirming closure, including subcontractor access.
A renewal should reference the existing record and identify changed products, people or connection methods.
Another failure is demanding so much evidence that good small suppliers cannot participate.
Focus requirements on the actual exposure and explain the decision each request supports.
Proportionate alternatives can improve competition while preserving the controls the buyer genuinely needs.
Begin with one supplier whose access or recovery role matters to production.
Walk through a normal support call and a termination scenario.
Use the gaps to update the procurement brief and service record, then apply the same decision discipline to other important relationships as they change.
What this page cannot conclude
- 01The cited OT publications are technical guidance, not a complete procurement or legal standard.
- 02No supplier was assessed or endorsed.
- 03Detailed equipment and safety requirements require the appropriate engineering owner.
- 04This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01Secure by DemandAustralian Signals Directorate, Australian Cyber Security Centre and international partners · accessed Sep 15, 2026
- 02Secure connectivity principles for Operational TechnologyAustralian Signals Directorate, Australian Cyber Security Centre and international partners · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Ask Industrial Suppliers for Evidence You Can Use. dotSuper. https://dotsuper.net/feeds/applied-systems/australia-industrial-supplier-assurance-evidence