Supply Chain Assurance
Technical assurance and verification across the electricity supply chain — a CAPA core specialisation.
Under SOCI in Australia, and the Cyber Resilience Act in Europe, utility-scale solar, storage and wind vendors and OEMs are increasingly required to provide ongoing assurance to utilities and operators around key risk points in critical control systems.
CAPA provides independent supply chain assurance services to OEMs, IPPs and utilities to address foreign ownership, control and influence requirements, automated and attested by a trusted third party.
Operators hold the obligation. Vendors are managing the day-to-day.
Assurance is how you close the gap.
Supply Chain Mapping
Who are your suppliers? How do they get access?
- Mapping the supply chain is the baseline capability
- Systematic collation of the systems, software and hardware versions running in production
- Capture and real-time detection on remote access logs
- Reconciliation and correlation against vendor access logs
Vulnerability assurance
Proving the build is what is on the box
- New releases sent to CAPA landing zone for verification
- SBOM validation and vulnerability status
- Compiled firmware scanning, where applicable
- Spot security code review and audit, where applicable
- Checks for cryptographic signing and release attestation
- Online reporting, deployment tracking and audit trail