Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Security procurement can reward visible assurance—completed questionnaires, certificates, and passed gates—because those artifacts are easy to request and audit. They become theater when buyers treat them as the outcome rather than as evidence to evaluate against the supplier’s actual risk. Official guidance and a public-sector audit illustrate this process problem; they do not prove that buyers broadly or deliberately prefer symbolic compliance.

How visible assurance can crowd out real assessment

A procurement team can readily document that it requested a questionnaire or checked for a named certificate. Assessing whether a supplier’s controls fit the intended use takes more judgment: the buyer must consider what information or access is involved, whether the evidence is reliable, whether the remaining risk is acceptable, and whether a gap should change the decision or contract.

That difference can make visible artifacts attractive in processes that prioritize completion and auditability. This is an explanation of how a process may reward appearances, not a measured or universal account of buyer behavior. Certificates and questionnaires can be useful inputs; they are weak substitutes when possession or completion is treated as proof that risk has been managed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an audit found—and what it does not prove

A Queensland Audit Office review of three selected public-sector entities found that all three used supplier risk questionnaires, but only one assessed the information to understand supplier risk. In the contracts reviewed, only 2 of 36 required suppliers to report cybersecurity incidents and vulnerabilities. Those counts describe the audited entities and contract sample, not the broader public or private sector. Queensland Audit Office report

The findings show how information collection can occur without consistent assessment, and how assurance may fail to carry through into contract obligations. They do not establish that staff consciously chose theater, measure how often this happens elsewhere, or identify buyer motives.

The Queensland Audit Office also reports that the Australian Signals Directorate handled 107 supply-chain-related cyber incidents in 2023–24, almost 10 per cent of all cyber incidents it responded to in that financial year. This is the Audit Office’s account of ASD data, not an all-sector breach rate. Queensland Audit Office account

What substantive supplier due diligence includes

NIST’s final SP 1326, published in July 2026, defines due diligence as research into pertinent supplier or product information to inform acquisition or system decisions. Its ICT supplier due-diligence components include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Foreign ownership, control, or influence.
  • Provenance of the supplier or product.
  • Resilience.
  • Foundational cybersecurity practices.
  • Supply-chain tiers.

These dimensions show why a single certificate or supplier self-description cannot, by itself, answer every risk question. The relevant evidence depends on the product, service, supplier, and use. NIST SP 1326

How to judge whether an assurance process is meaningful

When comparing a supplier’s certificate, questionnaire, or other assurance with the buyer’s actual needs, ask whether the process connects evidence to decisions across these five areas:

Risk relevance

Does the review reflect the information, access, service, and potential consequences involved in this purchase? UK government guidance says security questions and the share of evaluation allocated to cybersecurity can vary with the procurement, including the risk associated with personal information. UK procurement guidance

Evidence quality

Does someone investigate pertinent information about the supplier, product, and practices, or is a self-attested answer accepted as a conclusion? NIST describes due diligence as research undertaken to inform a decision—not merely the collection of a response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Decision consequence

Can a finding change the shortlist, approval, mitigation plan, or contract? If answers are collected but not assessed, the questionnaire has not demonstrated that the risk is understood.

Contract accountability

Are supplier expectations documented in suitable clauses? Depending on the purchase, this can include incident and vulnerability reporting, audit rights, and other supplier obligations. The Queensland Audit Office recommends clear expectations and suitable contract clauses.

Lifecycle follow-through

Is the supplier monitored after purchase, and are risks and mitigations revisited when circumstances change? The Queensland Audit Office recommends ongoing monitoring to check that risk and mitigation remain appropriate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical sequence for buyers

  1. Identify the supplier and exposure. Establish what the supplier provides, what information or access is involved, and relevant supply-chain exposure, including tiers where pertinent.
  2. Assess proportionately. Tailor questions and the depth of evidence review to the purchase’s context and risk. Evaluate responses rather than treating a completed form as a decision.
  3. Use findings in the decision. Decide whether evidence supports approval, calls for mitigation, changes the shortlist, or means the remaining risk is not acceptable.
  4. Put expectations in the contract. Document suitable obligations, including reporting and audit mechanisms relevant to the service and risk.
  5. Monitor over time. Check that controls and mitigations remain appropriate after purchase and respond to material changes or reported issues.

Why organizations may underinvest—and the limits of the evidence

A UK government response to a call for views identified lack of incentive to invest in supply-chain cybersecurity as a barrier and assigned senior management and boards responsibility for prioritizing investment. It supports treating accountability and organizational incentives as part of the problem, but it does not identify one dominant incentive or prove that buyers choose symbolic compliance over risk reduction. UK government response on supply-chain cybersecurity

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The evidence here consists of official guidance, an audit of three public-sector entities, a government response summarizing consultation input, and one anecdotal public discussion. It does not establish how often security buyers reward theater, whether the behavior is deliberate, or whether it is more prevalent in public or private organizations. A question raised in that discussion—“are we all just checking boxes after we’ve already decided?”—expresses the concern, but is not representative evidence. Public discussion

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.