A manufacturer we assessed scored 78% against its own security tier. The processes were genuinely good. Then we opened the bill of materials, and more than a third of it by value was made in a country that same standard prohibited.
Almost every supply chain security framework in circulation assesses the same thing: the organisation. Do you have a policy? Is there a named owner? Is there an audit cycle, a supplier questionnaire, a certificate on the wall?
These are reasonable questions. The trouble is that a company can answer all of them well and still be unable to support the claim it is making to its customers, because none of those questions look at the product.
We now score two axes, separately, and treat a tier as achieved only when both clear.
Two axes, but we found most people only measure the first
Capability is what conventional frameworks asses however it’s the supply base composition that a customer’s assurance team looks at when they get ‘serious’, and what a regulator looks at if/when something goes wrong.
So we plotted them against each other and found four positions appear. Most organisations sit in the same one.
We found 3 things the second axis catches
And yet none of these show up in a capability score; even though all three have had an impact and even ended an assurance conversation.
Where a component is actually made
Country of registration (or registrant) and country of manufacture diverge more often than people expect. A supplier headquartered in one jurisdiction may run its plants in another entirely. If your contract, your trade-agreement eligibility or your customer’s expectations depend on origin, the registered address means very little.
So, ask for the plant name and address, not the corporate one. Then write into the contract that the site cannot change without your prior approval, because a supplier free to move production between countries at will has given you nothing.
Who actually holds the purchase order
Commercial control and contractual instrument are frequently in different hands. A company can select its suppliers, negotiate the prices and set the specification, while a contract manufacturer places the actual order on most lines.
That split matters, because the audit right, the screening obligation and the incident notification clause travel with the purchase order unless a separate direct agreement carries them. We have seen organisations discover at the worst moment that the audit right they assumed they held did not exist on the lines that mattered.
Pick your three highest-value components. For each one, name the instrument that would let you walk into that supplier’s factory next month. If the answer takes more than a minute to find, you have the gap.
What each control is actually certified against
We reviewed a facility specification once that was genuinely competent. Patent-protected locking, dual-path alarm transmission, camera coverage, a hosted-visitor policy. Someone had thought about it properly, and no scheme was named anywhere in the document.
Good practice with no accreditation behind it reads as defence-grade right up until a customer asks which standard. Our rule now: above the entry tier, every control cites a named scheme. “Industry best practice”, “internal policy” and “security vetted” all fail that test, and an assurance team will notice.
The number that makes people cancel the programme
Here is a trap worth knowing about before you walk into it.
Roughly three quarters of the recurring cost of supply chain security is fixed. Screening licences, audits, certification maintenance, the people. None of it scales with how much you ship. Which means the per-unit cost is driven almost entirely by volume, and the same control set produces wildly different-looking numbers depending on when you measure it.
And the opposite mistake
Over-specification is just as expensive but maybe not as loud. We recently found four requirements sitting in a client’s top tier that no customer, contract or regulation actually required. Like ‘National security vetting’ for staff who basicall won’t any classified material. We even had A defence information standard planned for implementation but found there was no defence contract. Then, a facility assessment scheme whose own documentation positions it as guidance for the situation the client was in. The highest tier of a cargo-theft standard applied to a modestly-valued product.
There requirements combined would cost about a hundred thousand euros a year for controls nobody had asked for, and were not needed, while the actual binding constraint went unfunded.
What we’re trying to say is that security spend has an opportunity cost like any other. Certifications are visible and satisfying to collect, and determining where your product legally originates is neither, and it is usually the thing that decides whether you can sell.
So what do you do? Here are 5 questions worth an afternoon
You can run these yourself before anyone sends you a proposal.
What percentage of our bill of materials, by value, is made where?
By value, and not by supplier count. Six suppliers commonly carry half the spend, so a count-based number reads green while the concentration sits untouched.
For the top ten lines, is the manufacturing country the same as the registration country?
Where they differ, which one have we been quoting to customers?
Which contract would let us audit our third-largest supplier next month?
If the answer is “our contract manufacturer’s”, the right belongs to them.
Name the scheme each of our security controls is certified against.
Any control where the honest answer is “good practice” is a control we cannot evidence.
Which of our requirements would we drop if a customer asked us to justify each one?
The list is usually longer than expected, and the savings usually belong somewhere more useful.
Where this usually lands
The organisations that get caught are rarely careless. They are typically the ones who did the compliance work properly, scored well, and reasonably assumed the score answered the whole question. It answered one axis of it.
The second axis is mostly arithmetic. The data already exists in your bill of materials and your contract register. Nobody has put the two together and weighted them by value.
If those five questions were uncomfortable
Tryggvi is the secure supply chain practice at Äctvli. We run the two-axis assessment as a three to four week diagnostic: value-weighted exposure across your bill of materials, the contractual visibility position line by line, and a tier target you can actually evidence to a customer.
Most of what we find, clients already had. It was sitting in three different spreadsheets that had never been read against each other.

