Supply chain visibility

Supplier Criticality Matrix

Score suppliers by impact and likelihood side by side, then see them plotted and sorted automatically. Add your own supplier list below and try it now.

Supplier Criticality & Assurance Matrix

Supplier criticality & assurance matrix

Score impact and likelihood separately for as many suppliers as you want. Sort by risk, spot the ones that get missed.

Click a card to filter the matrix and list below.

Where everyone actually sits

Each dot is a supplier. Hover for the name. Position, not colour, is what matters, colour just follows it.

Likelihood, low to high
Lower priority
Worth resolving
Keep evidence current
Already critical
Often the real risk
Impact, low to high
High impact, high likelihood Moderate on both, real risk High on one axis only Low on both

Your suppliers, sorted by risk

Highest combined impact and likelihood first.

Review frequency should follow risk, not a fixed calendar, and a contract change, a new use of AI, or a shift in what a supplier actually does is reason enough to look again regardless of schedule. For the full framework behind this, read Supplier Criticality Explained, or download the sheet version to work through your full register offline.

See this running on your real supply chain

This is a manual snapshot that resets when you close the tab. Book a consultation to see what continuous, evidence-backed criticality scoring looks like across your actual supplier network.

Book a consultation
RISK, NOT JUST CRITICALITY

What Is a Supplier Criticality Matrix?

A supplier criticality matrix plots suppliers against two things at once: impact (what happens if this supplier fails) and likelihood (how probable a security problem actually is).

Most templates only ever measure one of these and call the result "criticality." That's the gap this tool is built to close.
Suppliers that look important but have never actually been assessed for security
The moderate-impact suppliers most teams never get around to
Suppliers holding sensitive data with no operational role at all
Existing suppliers on your books versus new suppliers coming in
Where regulation designates a supplier as critical regardless of your own score
A single score is not the same as two dimensions. Plotting impact and likelihood separately surfaces suppliers that don't look dangerous on impact alone, moderate in importance, but genuinely uncertain on security, which is often the group carrying the most realistic risk.
CRITICAL VS HIGH-RISK

Why This Tool Tags Critical and High-Risk Separately

A critical supplier is one your business depends on operationally, if they went down, something stops. A high-risk supplier could seriously damage the business even if you'd barely notice them failing, most often through the data or access they hold, not through anything going offline.

Critical suppliers sit inside the wider set of high-risk suppliers, not alongside it.
Operational dependency, would the business actually stop
Data sensitivity, independent of whether anything stops working
System access, what a compromised supplier could reach
Suppliers that fail one test and pass the other entirely
Regulatory designation as a separate override, not a third category
Critical is not the same as high-risk. Score only for criticality and the confidentiality-driven risks quietly fall out of scope. This tool tags both categories separately, so a supplier holding sensitive data but with no real operational weight doesn't get missed just because it isn't "critical" in the traditional sense.
THREE COMMON MISTAKES

Where Most Criticality Matrices Go Wrong

None of these are careless. Each one is a shortcut that feels reasonable under real time pressure, and each one quietly narrows what actually gets looked at.
Asking the supplier how critical they are
Scoring impact and stopping there
Treating full supply chain visibility as impossible
Missing the moderate-impact, high-likelihood group entirely
Treating the exercise as a one-off rather than an ongoing judgement
Impact alone is not the same as risk. The suppliers with moderate impact but real security uncertainty are often more realistic risks than the biggest names on the list, and they're the group most impact-only processes miss completely.
CRITICAL VS HIGH-RISK

Why This Tool Tags Critical and High-Risk Separately

A critical supplier is one your business depends on operationally, if they went down, something stops. A high-risk supplier could seriously damage the business even if you'd barely notice them failing, most often through the data or access they hold, not through anything going offline.

Critical suppliers sit inside the wider set of high-risk suppliers, not alongside it.
Operational dependency, would the business actually stop
Data sensitivity, independent of whether anything stops working
System access, what a compromised supplier could reach
Suppliers that fail one test and pass the other entirely
Regulatory designation as a separate override, not a third category
Critical is not the same as high-risk. Score only for criticality and the confidentiality-driven risks quietly fall out of scope. This tool tags both categories separately, so a supplier holding sensitive data but with no real operational weight doesn't get missed just because it isn't "critical" in the traditional sense.
FOUR QUESTIONS to ask youself

How to Assess Supplier Criticality

The Suppler Criticality Matrix scores against four questions.

The first three combine into an impact score. Likelihood stays on its own axis, deliberately simple enough to run against a real supplier list rather than a hypothetical one.
What does this supplier do for us?
What data do they hold?
What access do they have into our systems?
How confident are you in their security?
Why the supplier is never the right person to ask?
Asking the supplier is not the same as assessing them. It sounds efficient, but a supplier isn't the right party to answer a question about your business, and their incentives aren't always aligned with an honest answer.
FOUR FACTORS, ONE OVERRIDE

What Actually Goes Into a Supplier Criticality Score?

Impact and likelihood aren't single numbers, they're built from four separate questions, plus one override that sits outside the model entirely and can outrank all four.

01

Operational Dependency

Would an essential function stop without this supplier?
02

Data Sensitivity

What sensitive data do they hold, regardless of their operational role?
03

System Access

What could they reach inside your systems if compromised?
04

Security Confidence

How confident are you in their own security posture?
05

Regulatory Override

Could a regulator designate them critical regardless of your own score?
FAQ

Supplier Criticality Matrix FAQ

What's the difference between a criticality matrix and a risk matrix?

How many suppliers should I score in this tool?

Does this replace a formal risk assessment?

FROM SNAPSHOT TO CONTINUOUS

See This Running Across Your Real Supply Chain

This tool scores what you tell it, once. It doesn't notice a contract changing, a supplier's access expanding, or a regulator designating them critical while nobody's looking, that's exactly the gap a spreadsheet always leaves.

Book a consultation to see what continuous, evidence-backed criticality scoring actually looks like across your real supplier network.

Ready to map your exposure?

Speak with a Risk Ledger expert about where hidden dependencies and concentration risks may exist across your supplier ecosystem.