Supply Chain & Third-Party Risk Management Challenges in 2026
Originally reported viaCISA Secure Software Development Framework v1.2 · ENISA Threat Landscape 2025 · Sonatype State of the Software Supply Chain 2025ENISA's 2025 Threat Landscape report ranks supply chain attacks as the second most prevalent threat to enterprises, behind only phishing — and the fastest-growing by incident volume. Sonatype's State of the Software Supply Chain 2025 documented 245,000 malicious open-source packages uploaded to public registries in 2025, a 156% year-over-year increase. The challenge for enterprise security teams is that the tooling exists; the process maturity to operationalise it consistently does not.
The four failure modes CISA is citing
CISA's SSDF v1.2 guidance identifies four recurring gaps in third-party risk programmes: absence of vendor security questionnaire refresh cycles (vendor assessments are completed at onboarding and never revisited); no contractual incident notification requirements beyond vague 'timely notification' language; SBOM requirements in contracts that are not validated at delivery; and privileged access granted to MSPs and integrators without session monitoring or time-bound access controls.
SBOM maturity: from checkbox to operational tool
Software Bill of Materials (SBOM) requirements are appearing in procurement contracts across financial services, critical infrastructure, and government. The problem is that most SBOMs are generated at release and not updated as dependencies change. A living SBOM — continuously regenerated in CI/CD pipelines and ingested into vulnerability management workflows — is what the regulation intends and what most organisations are not yet delivering.
- Refresh third-party security assessments annually at minimum — onboarding-only assessments are no longer sufficient for Tier 1 vendors.
- Require contractual incident notification within 24 hours for any vendor with privileged access or access to sensitive data.
- Validate SBOM delivery at each software release, not only at contract signature.
- Implement just-in-time access with session recording for all MSP and integrator privileged access.
- Deploy an SCA (Software Composition Analysis) tool in your CI/CD pipeline to catch malicious or vulnerable dependencies before build.
- Run monthly open-source dependency confusion and typosquatting checks against your internal package registries.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.