High-risk supplier (HRS)
A high-risk supplier (HRS) is, within the national cybersecurity system, a manufacturer or supplier of hardware or software whose products may pose a threat to national security. Designation as an HRS follows a procedure based on technical and non-technical criteria and may lead to an obligation to withdraw its solutions.
What is a high-risk supplier (HRS)?
Definition of HRS
A high-risk supplier (HRS) is, within the national cybersecurity system, a manufacturer or supplier of hardware or software (so-called ICT products) whose solutions — for technical or non-technical reasons (including geopolitical ones) — may pose a threat to national security. Designation of a specific entity as an HRS follows an administrative procedure.
How does the HRS designation procedure work?
The procedure is based on the assessment of both technical criteria (e.g. vulnerabilities, the way updates are managed, transparency of the production chain) and non-technical criteria (including legal and capital ties to a state that creates risk). The result of a designation may be an obligation to withdraw the products of a given supplier within a defined time.
What does an HRS mean for your company?
- The need to inventory ICT suppliers and components in critical infrastructure.
- Accounting for HRS risk in supply chain management and in contracts (exit strategies).
- Readiness for migration should a supplier be designated as high-risk.
Most common misconceptions
The HRS procedure stirs emotions, so it is worth separating facts from simplifications. The scope of obligations depends on the category of the entity and the type of infrastructure — not every organization must react in the same way to the same ruling. Decisions in this area should be based on the current wording of the act and on communications from authorities, not on media shorthand.
Related terms
- NIS2 — the directive implemented through the amendment to the KSC Act
- Essential entity — the category most affected by supply chain requirements
- CSIRT — response teams within the national system
Explore our services
- KSC/NIS2 audit and advisory — including supply chain risk assessment
- Penetration testing — verification of the security of ICT components
The HRS mechanism protects the supply chain — for companies it means a real need to know whose hardware and software make up their infrastructure.