Madrid · Domestic and International Service info@imts.es
ES / EN / PT
ICT Supplier Management

Your technology (ICT) providers,
under control. Without you
having to keep an eye on them.

An organization’s technology (ICT) supply chain is one of its most significant risk factors and, at the same time, one of the most neglected. Rigorous ICT supplier management is not just about tracking invoices. It involves ensuring that each supplier delivers on its promises, that your contracts truly protect you, and that your technology supply chain does not become a point of failure or regulatory noncompliance.

Regulations
NIS2 · DORA · GDPR
NORM
ISO 27001 · ENS
CONTROL
CONTROL
FORMAT
On time · ongoing management
The problem we solve

A quiet model that fails when it's already too late.

Most organizations have a relationship with their IT providers that could be described as follows: they contract a service, sign a contract that no one ever reads again, pay the monthly bill, and call the provider when something goes wrong. As long as nothing goes wrong, they assume everything is working.

This model has consequences that inevitably surface sooner or later: contracts that do not reflect what was actually agreed upon or that have become outdated; SLAs that no one monitors and that the provider violates without consequences; critical dependence on a single provider with no alternative or contingency plan; costs that rise progressively without review; providers accessing sensitive systems or data without the required safeguards; and violations of the GDPR, NIS2, or standards such as ISO 27001 or ENS.

ICT supplier management is not an administrative task. It is a strategic function that directly impacts security, operational effectiveness, and regulatory compliance.
What the regulations require

A critical issue that goes unnoticed until the audit findings are released.

Supplier management is an explicit requirement in the major ICT standards and regulations applicable in Spain.

×

Passages that explicitly require it:

  • ISO/IEC 27001 — Annex A includes a specific section on security in supplier relationships: policies, security agreements, monitoring, and incident management with third parties.
  • ENS — Establishes specific measures for controlling third-party access, contracts with suppliers, and oversight of outsourced services.
  • NIS2 — Special emphasis on supply chain security as one of the main risk vectors.
  • DORA — Provides detailed regulations governing contracts with IT suppliers, record-keeping, and third-party risk management in the financial sector.
  • GDPR — Any vendor that accesses or processes personal data must be bound by a data processor agreement.
  • Poor management is not just an operational problem. It is a regulatory risk with direct financial and reputational consequences.
Services

Six lines of action. Real control, not just for show.

01

Supplier Map Analysis and Audit

Identification and cataloging of all ICT providers: what services they provide, what systems or data they have access to, what contracts govern the relationship, and their current status. An essential starting point.

02

Contract Review and Negotiation

Technical and functional analysis of contracts: unfair terms, gaps in protection, nonexistent or insufficient SLAs, outdated terms and conditions. Renegotiation based on technical knowledge of the service, not just legal considerations.

03

SLA Definition and Monitoring

Design of service level agreements: availability, response and resolution times, capacity, security, and reporting. Continuous monitoring of compliance, recording of non-compliance, and management of penalties.

04

Evaluation and Certification

Structured evaluation process: technical capability, financial stability, references, certifications, guarantees of continuity, and regulatory compliance. Applicable to new contracts and the existing vendor pool.

05

Third-Party Risk Management

Identification and assessment: degree of dependency, lack of alternatives, unsecured access to critical systems, uncertain financial situation. Mitigation, exit, and contingency plans.

06

Regulatory Compliance

Review and alignment with the GDPR (data processor), ISO 27001 (Annex A), ENS, NIS2, and DORA. Drafting or reviewing agreements, records, and procedures required by each framework.

The advantage of having someone manage it

Five Tangible Results When IMTS Takes Over ICT Supplier Management.

Real control, not just for show. Know what you’ve contracted for, with whom, under what terms, and whether those terms are being met. Not just a snapshot, but an ongoing status.

Effective contractual protection. Contracts that truly protect you, enforceable SLAs, and exit clauses that don’t leave you trapped. The difference between a well-drafted and a poorly drafted contract can mean years of costly dependence.

Sustained regulatory compliance. Compliance with the GDPR, ISO 27001, ENS, NIS2, or DORA is not a one-time achievement. Every new IT provider, renewal, or change can create a compliance gap.

Proven cost savings. An independent technical review systematically identifies over-provisioned services, conditions that can be improved, and costs that have become normalized without justification.

Reclaimed management time. Every hour spent managing vendors, addressing non-compliance, or reviewing contracts is an hour not spent on activities that generate value.

Who is this service for?

Any organization that relies on third-party technology.

SMEs without an in-house IT or legal department In the process of certification With critical dependence on suppliers General Guidelines They've grown up so fast Financial Sector (DORA) That process data through IT service providers
How We Work

Five phases. Regular reporting to management.

01

Initial diagnosis

Overview of suppliers, active contracts, management status, risks, and gaps.

02

Proposed Action Plan

Plan prioritized by risk, scope, effort, and delivery method.

03

Implementation

Review and renegotiation, SLA definition, standardization, records.

04

Ongoing Management

Dashboard monitoring, SLA monitoring, incident management, reporting.

05

Reporting a la dirección

Reporting to Management

Supply Chain

Every IT provider is a link in the chain. Managing and auditing third-party risk means protecting your organization.

IMTS is not committed to selling a one-time service. It is committed to being a reliable and specialized partner in security, compliance, and intelligence. Fifteen years of working alongside companies and public agencies back this up.

Do you really know what your IT providers are delivering—and what they aren't?

Tell us about your situation. We'll analyze your supplier map.

We clearly explain the risks you face and what we can do to address them. No obligation.

EMAIL info@imts.es
WEB www.imts.es/en
Seats Madrid · Domestic and International Service
Request a meeting →
IMTS manages its ICT suppliers based on independent technical criteria and with full knowledge of the applicable regulatory framework: GDPR, ISO/IEC 27001, ENS, NIS2, and DORA.