People often ask me if buyers actually use the cyber information suppliers provide through JOSCAR. The answer is we do, and probably more often than you think.
It helps us understand supplier risk, identify where we might need further conversations and make informed decisions. But for that to work, the information needs to be accurate, up to date and completed by the right people.
So, if I could give suppliers a few pieces of advice, these are the things I'd suggest they focus on.
Keep your profile up to date
Sounds simple right? I know people are busy, but much can change in a year, especially when it comes to cyber security. That's why buyers look at a supplier’s JOSCAR profile consistently throughout the year.
Using JOSCAR, I can quickly pull a report showing which suppliers have achieved Cyber Essentials, ISO27001 etc and where there may be gaps. That gives me an immediate picture of what's happening across the supply chain from a compliance perspective and potentially whether we need to have further conversations before a contract is awarded.
If something changes, whether that's a new certification, stronger cyber controls or anything else, update your profile. Don't wait until renewal, be proud to show off what you have achieved and put in place. Buyers don't just look at your profile when it's time to renew; we rely on that information throughout the year.
Make sure the right person fills it in
If there's one thing I'd encourage suppliers to do, it's make sure the right person completes the cyber section.
If you can, involve the person responsible for cyber or IT security or a CISO if you have one. They'll understand the controls you have in place and be best placed to answer the questions accurately.
If you're unsure about a question, don't guess. The Hellios and JOSCAR teams are there to support you. It's always better to ask than submit information that doesn't accurately reflect your organisation.
The information you put into JOSCAR doesn't just sit there...we do actually use it!
If it's not accurate, it's much harder for us to understand the level of risk or decide whether we need to ask more questions. The more confidence we have in the information, the more confidence we have in the supplier.
Buyers really do work together
I know JOSCAR can sometimes feel like just another questionnaire. But there is a reason we all ask the same questions.
Buyers across the JOSCAR community have worked together to agree the information we need. Instead of every organisation asking suppliers slightly different questions, we've aligned around one set. That saves suppliers time and gives buyers more consistent information.
Getting ahead of what’s coming next
Cyber expectations aren't standing still; they're increasing all the time. Earlier this year, at CYBER UK the UK Government announced the Cyber Resilience Pledge, encouraging organisations to strengthen cyber resilience across their supply chains through wider adoption of Cyber Essentials. This was reinforced by Number 10 in July 2026 - the new Cyber Resilience Pledge comes as businesses face an increasingly urgent threat environment – with over 5 million cyber-crimes committed against UK firms last year, which is equivalent to 1 every 6 seconds (source: NCSC Annual Review 2025).
My advice is to get ahead of those expectations now, rather than waiting until customers start asking for more. Organisations need to protect themselves from this ever-evolving threat and not just wait for contractual requirements.
I'd also recommend taking a look at the National Cyber Security Centre's free Early Warning service. It's quick to set up, it's free, and it'll tell you if there are any obvious vulnerabilities you should know about.
At the end of the day, JOSCAR isn't just about compliance.
For me, it's about buyers working together to build stronger, more resilient supply chains. The better the information suppliers can give us, the better decisions we can make - and that's good for everyone.
Looking to learn more about the JOSCAR Community?
Explore the pages below to see how JOSCAR connects Buyers and suppliers across the Defence, Aerospace and Security sectors. Discover the organisations that make up the JOSCAR Buyer community and find out how to join the community.
