Why these requests are landing on small shops
Scope 3 covers everything upstream and downstream of a company's own operations. Per CDP figures cited by Carbon Trust and Normative, Scope 3 accounts for between 70 and 90 percent of a company's total emissions on average, and CDP's 2024 analysis of more than 23,000 corporate disclosures put supply chain emissions at an average of 11.4 times combined Scope 1 and 2.
That arithmetic explains everything. A large manufacturer cannot report credibly without data from its suppliers, so the request travels down the chain to businesses with no direct regulatory obligation of their own.
Cyber requirements travel the same way. Cyber Essentials is mandated in UK defence procurement through DEFCON 658, which applies across the tiers of the defence supply chain rather than only to prime contractors. The MOD has set Defence Cyber Certification Level 0, with Cyber Essentials as a prerequisite, for defence partners by 31 December 2026 under ISN 2026/02. Check current MOD guidance before relying on that date, as industry security notices are updated.
JOSCAR registration sits alongside these as a common pre-qualification gate in aerospace and defence.
What is realistic to ask a small supplier for
| Request | Realistic for a 10 to 50 person shop | What to ask for instead if not | Notes |
|---|---|---|---|
| Cyber Essentials | Yes | Nothing. This is achievable and inexpensive | Basic certification is within reach of any small business and is a hard gate for defence work |
| Cyber Essentials Plus | Sometimes | Cyber Essentials plus a remediation timeline | Requires independent technical verification, so cost and effort rise |
| Full Scope 3 inventory | No | Scope 1 and 2, plus a per-order estimate | Full category-by-category Scope 3 is beyond most SMEs and will be estimated anyway |
| Per-part carbon figure | Yes, with assumptions stated | A materials and process breakdown | Material mass, process energy and transport gets you most of the way |
| EcoVadis or verified rating | Sometimes | A completed self-assessment questionnaire | The cost and admin load is significant for a small business |
| ISO 14001 | Sometimes | A written environmental policy plus measured energy use | Certification cost may exceed the value for a shop of this size |
| ISO 9001 | Yes, expect it | Evidence of a working quality system and corrective action process | This is the reasonable baseline for precision work |
How to choose what to demand
If you supply defence, Cyber Essentials is not negotiable and you should be checking it before you place work, not after. Ask for the certificate and the expiry date, and diary the renewal.
If you are collecting Scope 3 data for your own reporting, ask for a small number of specific inputs rather than a full inventory. Material grade and mass, primary process and energy source, finishing processes, and transport distance and mode. Those four give you a defensible estimate that you can apply consistently across suppliers.
If you are pre-qualifying for aerospace, JOSCAR and AS9100 are the gates, and you should expect a lead time on both.
Now the counter-argument, because it matters. Every requirement you push down has a cost and it will come back in your unit price, either openly or as margin the supplier stops earning elsewhere. Ask for what you actually need for your own compliance and customers. Requirements collected because they look thorough drive good small suppliers away from your business, and the ones who stay will simply tell you what you want to hear.
Precision is the trap here. A supplier who returns a suspiciously exact carbon figure has probably used a generic factor. One who returns a range with the method stated has done real work. The same logic applies to documentation and traceability, where the detail proves the work.
What this looks like in practice
TrueNorth Engineering treats these as capability rather than as burden, because both are increasingly buying signals.
ISO 9001 accreditation is in progress, and the traceability and corrective action structures were built to that standard from the beginning rather than retro-fitted for an audit.
On the cyber side, the collaboration platform we have been building through 2026 was scoped with Cyber Essentials and ISO 27001 practices as the baseline, hosted in the EU region with row level security in the database. That is a deliberate choice made early, because retro-fitting security to a live platform is expensive and rarely complete.
On carbon, our position is honest rather than impressive. We can give material mass, process route, finishing steps and transport mode per order, because those are already recorded for traceability. That is an estimate with stated assumptions, and we would rather hand a buyer a number they can defend than one that looks precise and cannot survive a question.