Every framework tells you to manage third-party risk; none of them hand you a template. This series takes the supply-chain requirement in each major regime, NIS2 Article 21(2)(d), the DORA Register of Information, ISO 27001 A.5.19–A.5.23, NIST CSF GV.SC, and CIS Control 15, and turns it into the same practical object: a supplier register you can defend, with criticality tiering, contractual flow-down, and the evidence an assessor or supervisor actually samples. Read one for your framework, or read across them to see where they agree.