Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Supply chain security

Also known as: Cyber supply chain security, Supply chain risk management

German: Lieferkettensicherheit

In cybersecurity, supply chain security is the management of risks that arise from suppliers, service providers and third-party components, including compromised software or hardware, insecure development practices, malicious updates and insecure remote access by service partners.

  • OT security

In one sentence

Supply chain security manages cybersecurity risks from suppliers, service providers and third-party components, including compromised software or updates.

Example

Before approving a new robot supplier, the plant checks the supplier's vulnerability handling process, requests an SBOM and defines how the supplier's technicians may connect remotely.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Procurement: Asset owners set security requirements in contracts: IEC 62443 conformity of products and services, vulnerability handling, update support periods, SBOM delivery and rules for remote access.
  • Compliance: NIS 2 lists supply chain security, including security aspects of relationships with direct suppliers, among the required risk-management measures. The CRA requires manufacturers to exercise due diligence when integrating third-party components.
  • Product development: Suppliers protect their own chain: trusted sources for open-source packages, signed builds, protected signing keys and verified update distribution, so that customers receive exactly the software that was released.
  • Documentation: Documentation is part of the supply chain too. Manuals, firmware and certificates should be distributed through authenticated channels, and customers should be told how to verify that files are genuine.

Supply chain security vs. product security

Product security covers the product itself. Supply chain security covers everything the product depends on on its way to the customer: components, tools, suppliers, logistics and update channels.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on Directive (EU) 2022/2555 (NIS 2), Regulation (EU) 2024/2847 (CRA) and IEC 62443

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!