← Knowledge areas
Knowledge area 07 · External dependencies

Third-Party
Dependencies

Outsourcing technology does not outsource cryptographic risk.

Third-party resilience depends on knowing which cryptographic capabilities sit outside direct control, how critical they are, who owns the relationship and whether suppliers can support change when standards evolve.

Last reviewed: August 2026

Your migration path may be controlled by someone else.

Cryptography is embedded in SaaS, cloud, managed PKI, identity platforms, libraries, hardware and other supplied technology.

The organisation may not control the algorithm, certificate hierarchy, key-management mechanism, component or migration schedule. Supplier capability and transparency therefore become part of organisational resilience.

Follow dependency beyond the contract boundary.

CLOUD

Cloud & managed services

KMS, HSM, TLS, identity and certificate capabilities may be provider-controlled.

SAAS

SaaS

Customers may have limited visibility into algorithms, keys and migration roadmaps.

SOFTWARE

Libraries & components

Applications inherit capabilities and constraints from software dependencies.

PRODUCTS

Commercial technology

Products constrain supported protocols, algorithms and key types.

TRUST

PKI & identity providers

External trust services introduce certificate, signing and key-management dependencies.

SUB-TIERS

Supplier supply chains

The real constraint may sit with a supplier's own provider or component.

Risk lens

A supplier dependency becomes material when the organisation lacks sufficient visibility, influence, alternatives or transition capability if cryptography must change.

Critical supplier dependencies are segmented and monitored.

SegmentationDeeper oversight is focused where dependency is material.
Defined requirementsSecurity and transition expectations are proportionate to impact.
Due diligenceRelevant supplier capability and technology dependencies are assessed.
Contractual coverageResponsibilities, notification and evidence expectations are explicit where appropriate.
Ongoing monitoringMaterial standards changes and supplier roadmaps trigger reassessment.
Exit & contingencyPortability, alternatives and concentration are understood.

Manage dependencies that can block your own treatment plan.

Identify critical external dependenciesStart with suppliers supporting critical services and sensitive data.
Ask decision-relevant questionsFocus on capability, ownership, roadmap and transition constraints.
Set proportionate requirementsMatch assurance expectations to business impact.
Track roadmap dependencyMake supplier-controlled dates visible in internal plans.
Plan alternativesUnderstand portability and exit before urgency removes options.

Your PQC timeline may depend on someone else's roadmap.

Post-quantum migration depends on products and external services supporting suitable transition paths.

Early supplier engagement is therefore part of managing the organisation's own readiness.

Further reading

Previous knowledge area← Key ManagementNext knowledge areaQuantum Readiness →