Getting Started: Supplier Risk

Supplier Risk

The Supplier Risk page gives you a supplier-centric view of your third-party software, so you can answer questions like "What do we have from this supplier?" or "How risky is this vendor?" without filtering through your full asset list. It rolls up risk, vulnerabilities, and asset counts by supplier and lets you drill into any one of them for detail.

Prerequisites

  • At least one software bill of materials (SBOM) uploaded and classified as third-party, with a supplier associated with it. This is what populates the Suppliers page.

Navigating to Suppliers

  1. In the left navigation, select Suppliers to open the Suppliers dashboard.
  2. Select Supplier Inventory, located just below Suppliers in the navigation, to view all third-party products across every supplier in a single table.

Suppliers dashboard

The Suppliers dashboard is your starting point for reviewing vendor risk across the organization. It includes four summary cards:

  • Total Suppliers
  • High Risk Suppliers
  • Total Assets
  • Total Vulnerabilities

Below the summary cards, the supplier table lists every supplier with the following sortable columns:

  • Supplier
  • Risk Score
  • Assets
  • Vulnerabilities
  • Last Updated

Use the search bar above the table to filter suppliers by name. Select any row to open that supplier's detail view.

The Supplier Risk Score reflects the highest-priority vulnerability recommendation across all of that supplier's assets. If any asset has a Mitigate-tier vulnerability, the supplier inherits that risk level, the same rollup logic used for product risk elsewhere in the platform.

Supplier detail

Selecting a supplier opens its detail view, which includes:

  • A header showing the supplier name, a "Third Party Supplier" label, and an overall risk indicator
  • Upload file and Import Binary buttons for adding a new SBOM or binary directly to this supplier
  • Summary cards for Overall Risk, Items, Total Vulnerabilities, and Last Scan date
  • An Inventory tab listing each asset tied to the supplier, with columns for Risk, Asset Name & Version, Components, Vulnerabilities, and Date Added
  • A Vulnerabilities tab listing findings across the supplier's assets, with columns for CVE ID, Recommendation, Severity, EPSS: Exploitability, Items Affected, and Affected Components

Uploading an SBOM to a supplier

You can associate a new SBOM with a supplier in two ways.

From the Suppliers dashboard

  1. Start a new upload from the Suppliers dashboard.
  2. Select an existing supplier, or enter a name to create a new supplier record.
  3. Once processed, the assets from the SBOM appear on that supplier's detail page, and the supplier's risk score recalculates to reflect the new data.

From an existing supplier's detail page

  1. Open the supplier you want to add to.
  2. Select Upload file to add an SBOM, or Import Binary to run binary analysis.
  3. The resulting asset appears in the supplier's Inventory tab, and the supplier's summary cards update accordingly.

Binary analysis uploads are treated as third-party assets and are represented on the Suppliers page the same way as uploaded SBOMs.

What to expect

Once your third-party SBOMs are tagged with a supplier, they appear as line items on the Suppliers dashboard, rolled up into that supplier's risk score, asset count, and vulnerability count. Selecting a supplier surfaces every associated asset and its vulnerabilities in one place, so you can assess a vendor's footprint without cross-referencing the general asset list.

Related docs



Did this page help you?