Control Third-Party Access
Give third parties access without giving them a permanent doorway.
Give third parties access without giving them a permanent doorway.
Time-bounded vendor and supplier access
Financial services, Healthcare, Energy, Public sector
How CP-03 controls third-party access.
A FIRE+VAULT pattern. The vendor path is severed by default and exists only as a validated, time-bound Relay session, with every artefact preserved.
Grounded in NIS2 Art. 21(2)(d), DORA Art. 28-30 and ISO 27001 A.5.15, A.5.19.
Vendor or supplier
External party
External party seeking a maintenance window
Request validated. Window opened for the engagement only.
Maintenance edge
The only
The only place a vendor session ever lands
Changes scoped, recorded and revocable on signal.
Managed estate
The systems
The systems the vendor is allowed to touch
Crown jewels · detail callout
Session evidence archive
Every vendor session, command and artefact preserved offline for audit and dispute.
Modules & symbols
Modules in this Blueprint
How the CP-03 pattern composes.
Validate checks the request before any door opens. Relay creates a controlled, time-bound access window. Lock ensures only approved users, roles or conditions can use it. Transfer governs what moves between environments, Archive preserves the activity for audit and Execute can revoke the path on signal.
Related Blueprints
Compose alongside.
Protect Critical Infrastructure
Keep critical systems available, controlled and disconnected from unnecessary exposure.
View BlueprintStop Kill-Chain Ransomware
Stop ransomware moving, spreading or reaching the crown jewels.
View BlueprintContain Active Breaches
When prevention fails, containment must be physical, immediate and provable.
View Blueprint


Build control around your environment
Talk to our team about composing this Blueprint for your estate.
Takes about 2 minutes. No account needed.