If your business has suppliers, and it does, DSI just gave the market a structured way to grade how much cyber risk each one is carrying.

DSI, Dynamic Standards International, the body behind the SMB1001 cybersecurity standard, has released the Supplier Cyber Assurance Program, SCAP for short. It's a genuinely useful idea: a structured way for a business to categorise its suppliers by cyber risk and set the SMB1001 tier each one needs to hold. If you've ever sat on the other end of one of these programmes, filling out a security questionnaire for a customer twice your size, this is the tool built for the business asking the questions.

Coastal Cyber has been engaging directly with DSI on SCAP since it opened up for early feedback. Here's what it does well, and the one structural gap worth understanding before you build a supplier programme around it.

How SCAP works

SMB1001 certifies a business's own cyber posture, five tiers running Bronze to Diamond. SCAP is the buyer-side layer sitting on top of it. Instead of certifying your own business, you use it to manage the cyber risk sitting in your supply chain, using the same five tiers.

The mechanics are straightforward. You run each supplier through DSI's Supplier Categorisation Matrix, scored against three questions: how much confidential or sensitive data can this supplier access, how much influence do they have over your systems or decisions, and how much damage would an outage at their end do to you. The matrix maps the answers to a required risk tier and, from there, a required certification: SMB1001 for most of your suppliers, ISO 27001, SOC 2, or a governance questionnaire for your largest ones. You set that as a contract and onboarding condition. The model clauses scale your right to audit a supplier's attestation to the risk they carry, full audit rights for your highest-risk suppliers, lighter spot-checks further down. The supplier manages their own uplift and certification through the same CyberCert platform that already issues SMB1001 certificates, where you can track their progress.

DSI's own worked example in the playbook runs a hypothetical company with over 5,000 suppliers on the SMB1001 track: roughly 20 per cent land at Bronze, 55 per cent at Silver, 10 per cent at Gold, 10 per cent at Platinum, and 5 per cent at Diamond. Yours will differ, but most real supplier bases cluster the same way, lower-middle tiers.

What a self-attested tier proves

Here's the part worth being precise about before you lean on SCAP output in a board pack or an insurance renewal conversation.

SMB1001 certification at Bronze, Silver, and Gold is director self-attestation, no routine independent verification. Only Platinum and Diamond involve an external audit, carried out by a CyberCert-appointed auditor. That's real, and worth knowing, but it isn't a flaw peculiar to SCAP or SMB1001. Most supplier assessments work exactly this way, and so does the Essential Eight, there's no mandated independent audit to claim an Essential Eight maturity level either. Genuine, mandatory third-party assurance is a shorter list: ISO 27001, SOC 2, and SMB1001's own Platinum and Diamond tiers.

So what does a director's signature buy you? More than it sounds like, the same logic as lodging your own tax return. Your accountant, or in this case your IT provider, can assemble the paperwork, but you're the one who signs and you're the one exposed if it's later found untrue, a genuine deterrent even without a routine audit behind it. SCAP adds a further layer: its model contracts scale your right to audit a supplier's attestation to the risk they carry, a discretionary spot-check at the bottom, a right you can exercise at any time for your highest-risk suppliers.

A Gold SMB1001 badge and a Platinum SMB1001 badge answer two different questions. One tells you a director has staked their name on it, with real exposure if they're wrong. The other tells you an independent auditor checked. Know which question you need answered, and remember SCAP gives you the contractual right to ask the first one harder.

Categorising suppliers by risk and setting tiered requirements beats the annual spreadsheet questionnaire most businesses still run, and a self-attested tier is a real signal, not a hollow one. For your highest-risk suppliers, the question isn't whether self-attestation is worthless. It's whether you've written the audit right into the contract, and whether you'd use it.

Best Practice - This is the way

Don't stop at the tier badge for your highest-risk suppliers. SCAP's model contracts hand you the strongest audit rights exactly where the risk sits, full audit rights at High Risk, lighter checks below it. For anyone landing at Gold or below who genuinely handles sensitive data or critical access, use the right you've got, don't just hope the director got it right.
Reserve Platinum as a real requirement, not a wish list item. If a supplier's risk genuinely warrants independent verification, self-attested Gold isn't the same thing, however close the control set looks on paper.
Build the supplier register regardless of where you land. The categorisation exercise itself, working out what each supplier can access and what would break if they went down, is worth doing even before you touch a tier requirement. It's usually the thing missing entirely.
Treat the categorisation as a starting point, not a settled answer. DSI's matrix gives you a defensible baseline; your own risk appetite and regulatory obligations should still adjust it up or down.
Revisit tiers as relationships change. A supplier that starts small and grows into handling more of your data needs re-categorising, not a set-and-forget exercise.

Where this sits for Coastal Cyber

Coastal Cyber has been engaging directly with DSI on SCAP's early rollout, evaluating it the same way we'd want a client to. We're not, yet, a formal SCAP partner in the way we are for SMB1001 certification, that relationship is separate and established, and it's worth keeping the two distinct. What SCAP does give us is a natural extension of work we already do well: categorising risk, setting defensible requirements, and being honest about what a certificate does and doesn't prove.

The question worth asking your own supply chain

If a customer asked you tomorrow which of your suppliers hold your most sensitive data, and what proof you have that each one's security claims are real, could you answer in an afternoon? For most businesses I talk to, the honest answer is no.

SCAP won't answer that question for you. It gives you a structured way to start.

Daniel Johns is a CRISC-certified virtual CISO and GRC advisor, Founder of Coastal Cyber, and a former member of the ISACA Global Advisory Council and CompTIA Executive Council ANZ. He works with healthcare providers, education, financial services, technology businesses, and MSPs across Southeast Queensland on privacy, cyber security, and governance.

If your privacy and cyber posture needs a clear-eyed assessment, book a 20-minute conversation.