People, devices and suppliers
Devices, training and supplier assurance - the parts of the standard that live outside your firewall.
The controls that trip small suppliers up are rarely technical. They are the leaver whose access is still live, the training nobody completed, and the supplier questionnaire that has been sitting in someone's drafts for five weeks.
This module covers the human estate: who works here, what they use, what they have been trained on, and which of your suppliers can actually answer for their own security. Suppliers and staff take part through links, not accounts - so there is no seat to buy and nothing for them to install.
Who works here, and what they can reach
The joiner–mover–leaver picture, synchronised from the identity provider and cross-referenced with device and training state.

Training that is tracked, not assumed
Campaign completion by person, with reminders and contractor invites handled for you.

Campaigns with real completion rates
Draft, active and completed campaigns with material sets and enrolment rules.

What staff see - no login required
The learner's view: assigned modules, progress and the certificate at the end.

Access reviews an auditor will accept
Periodic entitlement certification with per-item decisions and a defensible trail.

Your suppliers, and their risk to you
Every supplier with criticality, contract value, assessment state and the evidence they returned.

One supplier, fully evidenced
Assessment answers, evidence, contract terms and the risks this supplier carries.

The chain beyond your first tier
Upstream and downstream relationships, information requests and shared assurance status.

The questionnaire suppliers actually finish
The supplier-facing questionnaire: no login, evidence upload, progress saved as they go.

What you choose to share back
A read-only posture dashboard shared with a customer, without giving them an account.
