Supply Chain Security

Know Your Things

Supply chain security is no longer a checkbox. It is a business risk, a regulatory obligation, and increasingly a competitive differentiator. The hardware, software, and services that run your industrial operations come from a global web of manufacturers, vendors, integrators, and distributors, each representing a potential point of compromise. What you buy, who you buy it from, and whether you can trust what arrives are now questions with regulatory teeth.

Ampyx Cyber approaches supply chain security from both sides of the equation. We help asset owners build programs that satisfy CIP-013, NIS2, and the EU Cyber Resilience Act while actually reducing risk, not just generating paperwork. We help vendors and manufacturers navigate the growing web of customer questionnaires, conformity requirements, and documentation demands. And through our partnership with Embedded Lab, we provide hardware-level assessment capabilities that go deeper than any software tool can reach, verifying what is actually inside the devices your operations depend on before they are trusted in your environment.

CIP-013
Supply Chain

NERC CIP-013 is the floor, not the ceiling.

For utilities and other registered entities operating under NERC CIP, supply chain risk management begins with CIP-013. But the standard was written conservatively, and the threat environment has moved considerably since it was first implemented. Executive orders, FERC directives, and high-profile supply chain compromises have raised the bar well beyond what CIP-013 alone requires. The gap between compliance and actual security in the supply chain has never been wider, and auditors are beginning to close it. With FERC Order 912 expanding CIP-013 scope to Protected Cyber Assets, the compliance perimeter is growing. Organizations that built their programs to the original scope need to revisit them now.


Asset owners: compliance is your responsibility.
Vendor cooperation is not guaranteed.

CIP-013 is one of the most structurally complex standards in the NERC CIP framework because it requires your program to reach beyond your own organization and into the practices of the vendors, manufacturers, and integrators your operations depend on. The standard sets clear expectations for how you identify, assess, and mitigate cyber security risks in your supply chain. What it cannot do is make your vendors participate. If a vendor declines to engage, provides incomplete answers, or disappears through acquisition or discontinuation, the compliance obligation still sits with you.

Ampyx Cyber has worked with CIP-013 from its earliest drafts through its current implementation. We know where programs succeed, where they stall, and where auditors focus their attention. We help registered entities build supply chain risk management programs that are defensible under scrutiny, proportionate to their actual risk profile, and sustainable through the inevitable changes in their vendor landscape. Whether you are standing up a CIP-013 program for the first time, remediating findings from a prior audit, or preparing for the expanded scope that FERC Order 912 brings to Protected Cyber Assets, we have the experience to help you do it right.

Our CIP-013 services include:

  • Supply chain risk management plan development and review

  • Vendor identification and scoping for BES Cyber Systems and PCAs

  • Vendor questionnaire development, distribution, and response analysis

  • Procurement language review and development

  • Software and firmware integrity verification program design

  • CIP-013 gap assessment and mock audit

  • RSAW review and evidence sufficiency analysis

  • Order 912 PCA scope expansion planning

  • Compliance program integration with CIP-005, CIP-010, and CIP-011


Vendors: You are not required to be compliant.
But you should make it easy for your customers to be.

Industrial hardware and software vendors face a supply chain compliance burden they did not create and are not legally required to solve. Your utility customers are the ones subject to CIP-013, not you. But that distinction only helps you if your products and documentation make their compliance program easier to manage. Vendors that create friction, by getting the terminology wrong, providing incomplete answers, or sending responses that don't map to what auditors actually look for, get flagged in their customers' risk assessments. That creates delays in procurement, additional scrutiny at renewal, and in some cases lost business.

The terminology problem alone is more significant than most vendors realize. NERC CIP has a precise vocabulary, and using the wrong terms in a questionnaire response signals unfamiliarity with the regulatory environment your customers operate in. Trust erodes quickly. Getting this right is not complicated, but it requires knowing the framework and the right language in the right place at the right time.

The questionnaire problem is equally significant. There is no standard CIP-013 vendor questionnaire. Every registered entity develops their own, which means a vendor with many utility customers may be managing many different questionnaire formats for each product. Most vendors answer each one from scratch, which is expensive, inconsistent, and unnecessary. The industry is trying to meet a common goal, so there is some commonality. A well-structured master response library, built around what CIP-013 actually requires, can respond to nearly any utility questionnaire efficiently and consistently, while producing answers that hold up under auditor review.

Ampyx Cyber helps vendors get this right. We know what utilities are asking for, why they are asking for it, and what a credible answer looks like. We have written the questionnaires that vendors receive. We’ve helped vendors respond to entity questions. We can help you build the documentation, programs, and processes that reduce friction in your customers' CIP-013 programs and make your products easier to buy.

Our vendor services include:

  • Master questionnaire response library development

  • CIP-013 terminology and framework training for vendor teams

  • SBOM, FBOM, and HBOM program development

  • PSIRT establishment and operational design

  • Secure development lifecycle consulting

  • Procurement language negotiation support

  • Patch and vulnerability notification program design

  • Market entry consulting for vendors new to the US utility sector

NIS2 & CRA
Supply Chain

The European Union is not waiting for the market to solve this on its own.

The European Union has moved faster and more decisively on supply chain security than any other regulatory jurisdiction in the world. NIS2 places binding supply chain risk management obligations on operators of essential and important services across the bloc. The Cyber Resilience Act places mandatory cybersecurity requirements on manufacturers of products with digital elements sold in the EU. KRITIS and its successor KRITIS-DACHG impose additional obligations on German critical infrastructure operators. Taken together, these frameworks represent the most consequential shift in industrial cybersecurity regulation since NERC CIP was first implemented in North America.

The obligations are real, the timelines are tightening, and member state enforcement is accelerating. Organizations that have been waiting for regulatory clarity are running out of runway.

Ampyx Cyber GmbH is a legally independent European entity headquartered in Hamburg, purpose-built to serve EU clients under EU law. We provide EU-sovereign engagement with no US ownership, no US control, and a sole Managing Director who is a German national. That structure is not a technicality. For clients in regulated sectors handling sensitive infrastructure data, it is a prerequisite.


For Operators of Essential and Important Services

NIS2 holds management personally accountable for cybersecurity failures, and supply chain risk management sits near the top of the list of obligations. Article 21 requires operators to implement measures addressing the security of network and information systems, including the policies and procedures they use to assess and manage risks in their supplier relationships. Article 21(2)(d) names supply chain security as an explicit requirement, not an afterthought. Demonstrating compliance means being able to show regulators not just that you have a policy, but that you have applied it to your actual vendor relationships with documented results.

For German operators, KRITIS and the forthcoming KRITIS-DACHG add a layer of sector-specific requirements on top of NIS2, with stricter timelines and more prescriptive controls in some areas. The interaction between NIS2 and KRITIS is not always straightforward, and the national implementation picture across EU member states is still developing.

Ampyx Cyber GmbH helps operators of essential and important services build supply chain security programs that satisfy NIS2 and applicable national frameworks, produce the documentation regulators expect to see, and hold up under competent authority review.

Our EU operator services include:

  • NIS2 Article 21 and 26 gap assessment and program development

  • Supply chain risk management policy and procedure development

  • Vendor identification, scoping, and risk assessment

  • Supplier questionnaire development and response analysis

  • Procurement language review and development under EU law

  • KRITIS and KRITIS-DACHG compliance support for German operators

  • Incident reporting obligation mapping and preparation

  • Management accountability briefings and board-level reporting

  • Competent authority audit preparation and support


For Manufacturers and Vendors Selling into the EU

The Cyber Resilience Act changes the terms of market access for any manufacturer of a product with digital elements sold in the EU. Default products can be self-declared. Important products face stricter conformity assessment. Class II products are expected to require third-party assessment. Critical products face the highest bar, potentially including mandatory European cybersecurity certification. The practical question for most manufacturers is not whether the CRA applies to their products, but which class they fall into, what conformity evidence they need to place their products on the market, and how much time they have.

Getting the classification wrong is costly. Underestimating the conformity requirements is worse. And the documentation demands, vulnerability handling obligations, and software update requirements under the CRA are not compatible with a last-minute compliance push.

US vendors selling into the EU face an additional layer of complexity. The CRA's requirements do not map neatly onto any existing US framework, and the terminology and evidence standards are different from what US utility customers require under CIP-013. Ampyx Cyber bridges both worlds. We help manufacturers understand where their products sit in the CRA classification structure, what conformity assessment path applies, and how to build the documentation and processes that support it.

Our EU vendor and manufacturer services include:

  • CRA product classification analysis and conformity pathway assessment

  • Technical documentation development for CRA conformity

  • Vulnerability handling and coordinated disclosure program design

  • Software update and security support lifecycle planning

  • SBOM and HBOM development for EU market requirements

  • NIS2 supply chain obligation support for vendors serving essential service operators

  • CE marking and conformity declaration support

  • Cross-market program alignment for US vendors entering the EU

Hardware Validation

Most security programs trust the hardware.
We verify it.

Software security assumes the hardware beneath it is sound. Firmware, encryption, and network defenses all stand on that assumption. When the assumption is wrong, every layer above it inherits the flaw. And unlike a software vulnerability, a hardware flaw cannot be patched once the device is in the field. It is there for the life of that device.

This is the gap that most security programs do not close. Hardware is accepted on the strength of vendor documentation, brand reputation, or procurement process rather than independent verification. The result is an attack surface that extends below the reach of every tool in your security stack. Counterfeit components, undisclosed interfaces, extractable cryptographic keys, and design flaws exploitable through fault injection or side-channel analysis are all invisible to software-based assessment. Finding them requires a different set of skills, tools, and methods.

In one recent assessment, a district heating operator's newly procured OT sensors were found to contain an undisclosed 4G SIM card. No documentation disclosed it. No software scan would have found it. The only way to know it was there was to look.

Ampyx Cyber provides hardware validation and component assurance services through our partnership with Embedded Lab, a specialist hardware security laboratory with deep expertise in embedded device assessment, silicon-level testing, and FPGA security. We frame the device threat surface using MITRE EMB3D, MITRE's threat model for embedded devices, so findings map to a recognized industry framework rather than a proprietary checklist. Together we bring a capability to asset owners, manufacturers, and vendors that very few assessment providers can credibly offer.

For asset owners and operators: Independent verification of the devices entering your environment before they are trusted in your operations. Particularly valuable for OT sensors, controllers, and communication devices procured from vendors where supply chain visibility is limited, and for organizations with NIS2 or KRITIS obligations that require demonstrable supply chain assurance.

For manufacturers and vendors: Third-party assessment that verifies the security and resilience of your products, produces documentation suitable for CRA conformity, and gives your customers the independent evidence they need to trust what they are buying. In a market where procurement decisions increasingly depend on demonstrated security, independent validation is a competitive differentiator.

Our hardware validation services include:

  • Component identification and architecture assessment

  • PCB analysis for undisclosed or unexpected functionality

  • Firmware and embedded code security review

  • Secure boot and update process verification

  • Interface and protocol enumeration and testing

  • Side-channel analysis and power analysis testing

  • Fault injection testing including voltage, EMP, and frequency glitching

  • Cryptographic key storage and extraction resilience testing

  • FPGA bitstream protection, IP exposure, and key material assessment

  • Supply chain provenance verification and counterfeit detection

  • Hardware penetration testing and red teaming

  • Remediation support and verification-ready documentation for CRA conformity

Ask An Expert

GOT A TOUGH QUESTION?

Sometimes you just need to phone a friend. Ask us anything, any time. You don’t need to be an existing or prospective client. No cost, no hassle and no commitment. We will not put you on a contact list and our sales team won’t harass you. We will always respect your privacy. We promise. Just real answers from real experts for real problems.