CyberSec Update #33: Identifying a HRV | KWKR
A High-Risk Vendor You Must Identify Yourself
The UKSC introduces a procedure for declaring an entity a High-Risk Vendor (HRV). The process is conducted through administrative proceedings involving, among others, the minister responsible for digital affairs. Its purpose is to limit the use of hardware or software that may pose a threat to national security, public security, or public order.
Administrative Proceedings Are Not the Whole Story
The possibility of initiating proceedings under the UKSC does not relieve essential and important entities of their obligations related to proper supply chain risk management. In this context, assessing the risks associated with ICT solution providers becomes particularly important.
A properly implemented information security management system, as one of the required technical and organizational measures, should address the security and continuity of the supply chain for ICT products, ICT services, and ICT processes on which service delivery depends.
In practice, this means assessing the risks associated with the potential withdrawal of hardware or software from the IT systems of an essential or important entity if the supplier assessment no longer supports continued cooperation with that vendor.
Do Not Look for Trusted Suppliers in a Registry
As stated by the Ministry of Digital Affairs in its FAQ on the National Cybersecurity System available on cyber.gov.pl, there is no official registry of trusted and verified hardware or software suppliers for essential and important entities.
At the same time, no proceedings have yet been initiated to classify any ICT solutions provider as a High-Risk Vendor.
Where Should Trust in a Supplier Come From?
Every essential and important entity should continuously verify whether its ICT solutions originate from trusted suppliers and meet relevant security requirements.
This raises an important question: what criteria should organizations use when selecting a supplier if no administrative decision has been issued against that vendor?
Stay Up to Date with Official Recommendations
One option is to monitor recommendations issued by the Government Plenipotentiary for Cybersecurity under Articles 33 and 67a of the UKSC. These recommendations may identify vulnerabilities and technological solutions whose use could negatively affect the security level of ICT solutions.
For organizations, such recommendations may serve as an indication that a particular supplier does not meet the required security standards.
Audit Your Suppliers
Another important step is conducting your own audits of suppliers. If current contracts do not provide such rights, they should be established through broader information security and cybersecurity documentation, such as amendments, agreements, or framework contracts.
A properly conducted supplier self-assessment can provide an initial indication of the level of cybersecurity awareness and maturity demonstrated by a business partner.





