🇬🇧 Made in Britain — UK-first ISO-certified suppliers · Mutual NDA standard · DFM review & quote within 48 hours
Home/Buyer Guides/ESG & Cyber
Buyer Guide 8 of 9 · ESG & Cyber

Scope 3 carbon and cyber requirements for small UK suppliers.

Ask small suppliers for two things and stop there: Cyber Essentials certification, and a per-part or per-order carbon figure using a recognised method with the assumptions stated. Full Scope 3 accounting is beyond most SME machine shops and asking for it produces guesses. A modest, honest, documented number is more useful to your own reporting than a precise-looking one nobody can defend.

Why these requests are landing on small shops

Scope 3 covers everything upstream and downstream of a company's own operations. Per CDP figures cited by Carbon Trust and Normative, Scope 3 accounts for between 70 and 90 percent of a company's total emissions on average, and CDP's 2024 analysis of more than 23,000 corporate disclosures put supply chain emissions at an average of 11.4 times combined Scope 1 and 2.

That arithmetic explains everything. A large manufacturer cannot report credibly without data from its suppliers, so the request travels down the chain to businesses with no direct regulatory obligation of their own.

Cyber requirements travel the same way. Cyber Essentials is mandated in UK defence procurement through DEFCON 658, which applies across the tiers of the defence supply chain rather than only to prime contractors. The MOD has set Defence Cyber Certification Level 0, with Cyber Essentials as a prerequisite, for defence partners by 31 December 2026 under ISN 2026/02. Check current MOD guidance before relying on that date, as industry security notices are updated.

JOSCAR registration sits alongside these as a common pre-qualification gate in aerospace and defence.

What is realistic to ask a small supplier for

RequestRealistic for a 10 to 50 person shopWhat to ask for instead if notNotes
Cyber EssentialsYesNothing. This is achievable and inexpensiveBasic certification is within reach of any small business and is a hard gate for defence work
Cyber Essentials PlusSometimesCyber Essentials plus a remediation timelineRequires independent technical verification, so cost and effort rise
Full Scope 3 inventoryNoScope 1 and 2, plus a per-order estimateFull category-by-category Scope 3 is beyond most SMEs and will be estimated anyway
Per-part carbon figureYes, with assumptions statedA materials and process breakdownMaterial mass, process energy and transport gets you most of the way
EcoVadis or verified ratingSometimesA completed self-assessment questionnaireThe cost and admin load is significant for a small business
ISO 14001SometimesA written environmental policy plus measured energy useCertification cost may exceed the value for a shop of this size
ISO 9001Yes, expect itEvidence of a working quality system and corrective action processThis is the reasonable baseline for precision work

How to choose what to demand

If you supply defence, Cyber Essentials is not negotiable and you should be checking it before you place work, not after. Ask for the certificate and the expiry date, and diary the renewal.

If you are collecting Scope 3 data for your own reporting, ask for a small number of specific inputs rather than a full inventory. Material grade and mass, primary process and energy source, finishing processes, and transport distance and mode. Those four give you a defensible estimate that you can apply consistently across suppliers.

If you are pre-qualifying for aerospace, JOSCAR and AS9100 are the gates, and you should expect a lead time on both.

Now the counter-argument, because it matters. Every requirement you push down has a cost and it will come back in your unit price, either openly or as margin the supplier stops earning elsewhere. Ask for what you actually need for your own compliance and customers. Requirements collected because they look thorough drive good small suppliers away from your business, and the ones who stay will simply tell you what you want to hear.

Precision is the trap here. A supplier who returns a suspiciously exact carbon figure has probably used a generic factor. One who returns a range with the method stated has done real work. The same logic applies to documentation and traceability, where the detail proves the work.

What this looks like in practice

TrueNorth Engineering treats these as capability rather than as burden, because both are increasingly buying signals.

ISO 9001 accreditation is in progress, and the traceability and corrective action structures were built to that standard from the beginning rather than retro-fitted for an audit.

On the cyber side, the collaboration platform we have been building through 2026 was scoped with Cyber Essentials and ISO 27001 practices as the baseline, hosted in the EU region with row level security in the database. That is a deliberate choice made early, because retro-fitting security to a live platform is expensive and rarely complete.

On carbon, our position is honest rather than impressive. We can give material mass, process route, finishing steps and transport mode per order, because those are already recorded for traceability. That is an estimate with stated assumptions, and we would rather hand a buyer a number they can defend than one that looks precise and cannot survive a question.

ESG & Cyber — Common Questions

Straight answers, before you ask.

Scope 3 covers all indirect emissions in a company's value chain, upstream and downstream. Per CDP data cited by Carbon Trust and Normative it averages 70 to 90 percent of a company's total emissions, and CDP's 2024 analysis of over 23,000 disclosures put supply chain emissions at around 11.4 times Scope 1 and 2 combined. Large manufacturers cannot report credibly without supplier data, so the request travels down the chain.

Generally no. Most SMEs have no direct reporting obligation. The pressure is commercial rather than regulatory, and it arrives through customer requirements. Suppliers who cannot produce credible data increasingly lose contracts even though no law compels them to produce it.

DEFCON 658 is the UK Ministry of Defence contract condition covering cyber security risk in the defence supply chain. It applies through the tiers rather than only to prime contractors, with Cyber Essentials as the baseline certification. The MOD has set Defence Cyber Certification Level 0, with Cyber Essentials as a prerequisite, for defence partners by 31 December 2026 under ISN 2026/02. Verify current guidance before relying on a date.

Yes. Basic Cyber Essentials certification is a self-assessment against five technical controls, and it is achievable and affordable for a small business. Cyber Essentials Plus adds independent technical testing and is a larger step, so allow more time and budget.

Material grade and mass per part, the primary process and its energy source, any finishing processes, and transport distance and mode. Those four inputs allow a defensible estimate applied consistently across suppliers, and they are the things a supplier can actually evidence.

Only if the requirement is genuinely yours rather than inherited enthusiasm. Every requirement pushed down carries a cost that returns in your price. A good supplier with a written policy, measured energy use and an honest estimate is usually a better outcome than a weaker supplier with a certificate.

Compliance answers you can actually defend.

Material mass, process route, finishing steps and transport mode per order, recorded as part of traceability. Ask us about our compliance position before you place work.