Back to templates
    Template

    Third-party tiering

    A four-sheet workbook that scores suppliers on five closed-option factors, bands the scores into three tiers, and sets the depth of assurance each earns.

    Risk5 Sept 20263 min read

    Directive (EU) 2022/2555Regulation (EU) 2022/2554
    On this page
    Download the template

    third-party-tiering.xlsx · 10 kBLicensed CC BY 4.0

    What this is

    A four-sheet workbook for tiering a supplier estate. Five factors are scored from a closed list, the scores are banded into three tiers, and the tier sets how much due diligence, assurance and exit planning a relationship earns. It is the artefact produced by section 3.1 of Third-party risk across the contract lifecycle.

    The tier is a local label, not a regulatory classification. No instrument defines tiers. What the instruments define is criticality and substitutability.

    How to use it

    1. Delete every row marked EXAMPLE - delete. Three sit on each working sheet.
    2. Agree Tier rules first, before any supplier is scored. The options and the bands are the organisation's own; what matters is that both are fixed in advance.
    3. Fill Tiering next, one row per supplier and service, resolving the five closed-option columns before any free text.
    4. Apply the override, not only the arithmetic. A supplier behind a critical or important function is tier 1 whatever the total says 1.
    5. Score substitutability honestly. A provider that is not easily substitutable is a named pre-contract concern 2.
    6. Set the due-diligence set from the tier, so assessment depth is a rule rather than a negotiation. NIS2 puts supply-chain security among the required measures, framed around direct suppliers and service providers 3.
    7. Fill Assurance calendar last, one row per evidence item due, not one per supplier. An overdue row keeps its due date and an empty Received cell. See section 3.5.

    Sheets and columns

    SheetColumns
    Read firstLicence, scope, scoring rule, closed lists, as prose
    Tier rulesFactor, option, score, meaning; then the three tier bands
    TieringID, supplier, service, the five factors, score, tier, due-diligence set, assurance frequency, exit plan, owner role, next review
    Assurance calendarSupplier, tier, evidence type, due, received, reviewer role, outcome

    Each factor takes one option worth 0 to 3 points, so the score runs from 0 to 15.

    What good looks like

    Six columns from the Tiering sheet, example prefix dropped.

    IDFunction criticalityAccessSubstitutabilityScoreTier
    TP-0011. Critical or important1. Privileged access to production1. Not substitutable141. Tier 1
    TP-0022. Supporting2. Standard access to production2. Substitution is highly complex82. Tier 2
    TP-0033. Other3. Non-production access only4. Easily substitutable13. Tier 3

    Two things make those rows usable. Every factor is a closed-list value, so two readers cannot disagree about a score. The score sits beside the tier, so a challenged tier is re-argued factor by factor.

    Fields

    FieldRequiredMeaningCommon mistake
    Function criticalityyesThe criticality of the function the service supportsScoring the supplier's size instead
    AccessyesWhat the supplier reaches in live systemsRecording the contract, not the accounts
    SubstitutabilityyesHow hard leaving would beOptimism with no transition plan
    Regulatory reachyesWhether a supervisor can ask about this by nameTreating everything as in scope
    Score, TieryesThe total, and the band with the override appliedKeeping the tier, dropping the score
    Exit planyesWhether a plan exists, from a closed listRecording intent rather than a plan

    Download

    • File: third-party-tiering.xlsx (xlsx, 10 KB) — four sheets.
    • Markdown variant: content/templates/assets/_third-party-tiering.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names; example rows are invented.

    References

    1. Regulation (EU) 2022/2554 (DORA). CELEX 32022R2554. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng 4
    2. Directive (EU) 2022/2555 (NIS 2 Directive). CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng 5

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by any standards body.

    Sources

    1. 1EU Publications Office CELEX 32022R2554 Art. 3(22) · verified 2026-09-05
    2. 2EU Publications Office CELEX 32022R2554 Art. 29(1)(a) · verified 2026-09-05
    3. 3EU Publications Office CELEX 32022L2555 Art. 21(2)(d) · verified 2026-09-05
    4. 4EU Publications Office CELEX 32022R2554 · verified 2026-09-05
    5. 5EU Publications Office CELEX 32022L2555 · verified 2026-09-05