NPSA Supply Chain Guidance and Penetration Testing: What Public Bodies Ask

NPSA Supply Chain Guidance and Penetration Testing: What Public Bodies Ask

By EJN Labs · 27 Aug 2026 · 8 min read

NPSA supply chain security guidance does not mandate penetration testing. It asks public bodies to take a risk-based approach to supplier assurance, and in practice buyers ask higher-risk suppliers for independent testing evidence. A CREST-accredited penetration test, priced at £1,100 to £1,400 per tester day in the UK, is in our experience the most common way to provide that evidence.

NPSA supply chain security penetration testing: why public bodies ask for it

The National Protective Security Authority (NPSA) publishes protective security guidance for UK organisations, and its supply chain security material has become a reference point for public-sector procurement. Government departments, local authorities, NHS bodies and arm’s length organisations use it, alongside NCSC guidance, to decide what assurance to demand from suppliers, which is why tender packs increasingly ask about independent security testing.

The logic is straightforward. A public body can harden its own estate and still be compromised through a supplier that holds its data, hosts its services or connects into its network. NPSA guidance responds by asking organisations to understand who their suppliers are, what access and data they hold, and what evidence exists that each supplier’s security actually works. Penetration testing is one of the few forms of evidence that demonstrates controls working in practice rather than on paper.

What the NPSA guidance actually expects

The NPSA guidance expects a proportionate, risk-based programme of supplier assurance: identify your suppliers, tier them by the harm a compromise could cause, set security requirements that match each tier, and verify they are met. It contains no clause requiring every supplier to commission a penetration test.

Precision matters because the guidance is often overstated in tender documents. NPSA supply chain security guidance is exactly that, guidance rather than legislation.

Verification is where testing enters. For low-risk commodity suppliers, a certification such as Cyber Essentials is usually sufficient. For suppliers that process sensitive or official data, run citizen-facing services, hold privileged access into the buyer’s environment or supply critical software, questionnaire answers alone are weak evidence. Risk-based assurance at that tier normally means independent technical testing, typically written into contract as an annual penetration test by an accredited firm, with the report or a summary shared with the buyer.

The honest position is this: the guidance does not name penetration testing as mandatory, but it clearly points towards technical verification for higher-risk suppliers, and testing is how the UK market delivers that verification in practice.

What public bodies typically ask suppliers to test

The scope of a supplier assurance test should follow the risk the supplier represents to the buyer, not a generic template. The most common components we see requested in public-sector supply chains are:

  • External infrastructure. The supplier’s internet-facing perimeter: VPN gateways, mail, remote access and exposed management interfaces. See our external infrastructure penetration testing service for what this covers.
  • The service delivered to the buyer. The web application, portal or platform the public body actually consumes, including authentication, session handling and access control between tenants.
  • APIs and integrations. Data exchange between supplier and buyer systems is a frequent weak point. API penetration testing validates authorisation and data exposure across those interfaces.
  • Cloud configuration. Most public-sector services are now hosted in AWS, Azure or GCP, so a cloud penetration test of identity, storage and network configuration is increasingly written into requirements.
  • Connectivity into the buyer. Where a supplier holds standing access to the public body’s network, buyers may ask for testing of that access path, or in mature programmes a scenario-based exercise.

If you are building a requirement set, our penetration testing checklist is a practical starting point for defining scope before it goes in front of suppliers.

How a supplier assurance engagement runs

A supply chain driven test follows the standard engagement lifecycle, with one difference: three parties are usually involved, so the paperwork matters more.

  1. Scoping. We map the supplier-facing attack surface against the buyer’s requirement: which systems hold the buyer’s data, which entry points exist, and what the contract actually asks for. This is where over-testing and under-testing are both avoided.
  2. Authorisation. Written authority from the system owner, and where buyer-side systems or shared connectivity are in scope, from the public body too.
  3. Testing. UK-based testers work through the agreed scope using recognised methodologies, with daily contact and immediate escalation of critical findings.
  4. Reporting. Findings rated by severity, with evidence and remediation guidance, plus an executive summary a procurement lead or SIRO can read without translation.
  5. Retest. Verified remediation of critical and high findings, with a retest letter the supplier can hand to the buyer as closure evidence.

One first-hand observation from scoping these engagements: the highest-value finding is often not in the application itself but in the seams, such as a staging environment sharing credentials with production, or a supplier support account with far wider access to buyer data than the contract anticipated. That is why we enumerate data flows between supplier and buyer during scoping rather than testing the named system in isolation.

What it costs and how scope drives the price

UK penetration testing is priced by scoped effort at a day rate, typically £1,100 to £1,400 per tester day. The number of days is driven by the size of the attack surface: how many hosts, applications, APIs, cloud accounts and user roles are in scope. Typical ranges for supply chain assurance work look like this:

EngagementTypical effortTypical UK cost
External infrastructure test3 to 5 days£3,300 to £7,000
Web application or API test4 to 6 days£4,400 to £8,400
Cloud configuration review4 to 7 days£4,400 to £9,800
Combined external, application and cloud6 to 9 days£6,600 to £12,600

These are typical UK ranges rather than fixed prices; the exact figure depends on scope, which is why a short scoping call comes first. For a fuller breakdown of what moves the number, see our guide to penetration testing cost in the UK. Public bodies comparing quotes across a supplier base should insist on like-for-like scope, since a narrow cheap test produces evidence that will not survive assurance review.

How EJN Labs approaches NPSA-aligned supplier testing

EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. That matters here because public-sector buyers routinely specify accredited testing, and a report from a CREST penetration testing firm is accepted evidence across government supply chains without argument.

We work on both sides of the relationship. For public bodies, we help translate NPSA-aligned assurance requirements into testable scopes, so the requirement you put into a contract produces evidence you can actually evaluate. For suppliers, we scope tests against what your buyer has asked for, deliver a report written for both technical teams and procurement reviewers, and include remediation retesting so you can close the loop with a clean letter. If you are weighing up firms, our guide to choosing the best UK penetration testing provider sets out the questions worth asking any vendor, including us.

Frequently Asked Questions

Does NPSA supply chain security guidance make penetration testing mandatory?

No. NPSA supply chain security guidance is not legislation and does not name penetration testing as a mandatory control. It asks organisations to take a risk-based approach to supplier assurance, which in practice leads public bodies to request testing evidence from their higher-risk suppliers.

The evidence requested is usually independent technical testing, and a penetration test from a CREST-accredited firm is, in our experience, the most common way to provide it.

What does NPSA-aligned penetration testing cost?

Expect £1,100 to £1,400 per scoped day. An external infrastructure test typically takes 3 to 5 days (£3,300 to £7,000), a web application or API test 4 to 6 days (£4,400 to £8,400), and a combined external, application and cloud assessment 6 to 9 days (£6,600 to £12,600).

Exact pricing depends on scope, so request a quote.

Which suppliers do public bodies ask for penetration testing evidence?

Suppliers handling official or sensitive data, hosting citizen-facing services, holding privileged network access or supplying critical software are usually placed in the highest risk tier and asked for independent testing evidence. Buyers tier suppliers by risk, so the tier decides what evidence is requested.

Low-risk commodity suppliers are more often asked for Cyber Essentials certification instead. The NPSA guidance supports exactly this kind of proportionate, risk-based segmentation.

How often should testing be repeated for supplier assurance?

Test annually, plus after significant change such as a new platform, a major release or an infrastructure migration. Annual testing is the most common cadence in public-sector supplier assurance, and many public bodies write it into contracts as a standing requirement.

Contract clauses usually ask for the latest report plus evidence that previous findings were remediated. Align the testing window with contract renewal or assurance review dates where possible.

What should a penetration test report include for a public-sector buyer?

Include scope and methodology, an executive summary in plain English, findings rated by severity with supporting evidence, realistic remediation guidance and a statement of the testing firm’s accreditation. Everything should serve one goal, a report the buyer can act on.

Public bodies increasingly ask for a retest letter confirming critical and high findings were fixed. EJN Labs includes remediation retesting in every engagement.

Get supplier assurance evidence buyers accept first time

Whether you are a public body writing NPSA-aligned requirements or a supplier who has just received them, the fastest route to a defensible answer is a properly scoped test from an accredited UK firm. Tell us what is being asked for and we will return a fixed scope and price within one working day. Get a CREST penetration testing quote.

Leave a Reply

Your email address will not be published. Required fields are marked *