EDIH, EEN, Interreg: the platform for European programmes.Find out more

Supply chain resilience index maturity

Your upstream resilience, measured theme by theme and turned into a roadmap.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Supply chain resilience index maturity

Supplier base mappingN1 → N5
Criticality and dependenciesN1 → N5
Visibility and data qualityN1 → N5
Detection and early warning signalsN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Supplier base mapping6484
Criticality and dependencies5379
Visibility and data quality6182
Detection and early warning signals3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Datamensio maturity framework, supply chain resilience index (capability-based approach, 5-level CMMI scale) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism (a level, a level above, and the action linking the two) that turns an observation into a trajectory.

Do you know the origin and production sites of your critical components beyond your tier 1 suppliers?

  1. N1

    Knowledge stops at the tier 1 supplier. Nothing documents upstream production sites.

  2. N2

    Tier 2 information exists for a few families, gathered as incidents arise and kept in individual files.

  3. N3

    Critical families are mapped to tier 2 in a shared database, updated annually.

  4. N4

    The mapping is kept current as contracts evolve, geographic points of convergence are identified and tracked as risks.

  5. N5

    The mapping feeds disruption scenarios and sourcing decisions, with traceable updates and automatic cross referencing against external signals.

Action to move from L2 to L3

Define the list of critical families, add the declaration of tier 2 sites to the supplier questionnaire and the annual contract review, then consolidate responses in a single supplier database.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

The supply chain resilience index measures four capabilities: anticipate, detect, absorb, learn. It covers knowledge of the supplier base beyond tier 1, visibility of physical and information flows, redundancy of sources and sites, flexibility of production and transport plans, and speed of decision when a link fails. This is not a framework of binding requirements: it is a capability grid that places an organisation on a progressive scale and describes what moves it up.

In practice, upstream resilience is difficult to steer because it sits across several functions. Procurement holds the contract, supply chain holds the flow, manufacturing holds the capacity, finance holds the cost of stock. Three questions quickly separate rhetoric from reality: do you know the production sites of your tier 2 suppliers for your critical families? How long elapses between an incident at a supplier and the decision to activate an alternative source? Have your continuity plans been tested beyond the document itself?

The context has changed in nature. Upstream mapping is becoming a regulatory expectation rather than just good practice, driven by duty of care obligations, the EU deforestation regulation, or forced labour requirements. A confusion often recurs: resilience is not security. ISO 28000 addresses the security of flows and malicious threats. Resilience addresses continuity of supply against any cause of disruption, including a climate hazard, a supplier’s financial failure or a component shortage. The two overlap, but they do not replace each other.

Data is the tipping point of this subject. A resilient chain is first and foremost an observable chain: a maintained supplier database, bills of materials linked to sites, external signals integrated, real lead times measured rather than declared. This is why the assessment asks a different question from the audit. An audit concludes with compliant or non compliant. The assessment places each capability on five levels, then names the precise action that moves it to the next level, with its cost, timeframe and effect on the score.

Within Datamensio, the framework is ready to use and you adapt it to your model. AI adjusts themes, questions and levels to your sector, whether distribution, process industry, pharmaceuticals or capital goods, or builds a tailored version from your own documents, risk maps and existing continuity plans.

Reference standard: Datamensio maturity framework, supply chain resilience index (capability-based approach, 5-level CMMI scale)

The themes assessed

  • Supplier base mapping

    Knowledge of tier 1 and tier 2, linking of components to production sites, identification of geographic points of convergence, upkeep of the supplier database.

  • Criticality and dependencies

    Ranking of purchasing families, measurement of single sourcing, assessment of substitutability, cost and lead time to qualify an alternative.

  • Visibility and data quality

    Completeness of supplier and item data, reliability of real lead times, traceability of orders and shipments, integration between procurement, ERP and transport systems.

  • Detection and early warning signals

    External sources used, financial monitoring of suppliers, leading indicators of lead time drift, time between an incident occurring and its internal awareness.

  • Scenario analysis and stress tests

    Formalised disruption scenarios, quantification of impact on revenue and service, simulation exercises, frequency of testing and use made of results.

  • Redundancy and flexibility

    Dual sourcing policy, safety stock and its sizing, ability to shift between sites and transport modes, contracting of capacity options.

  • Response and crisis management

    Escalation arrangements, dedicated cell with defined roles, shortage allocation rules, decision authority and lead time to activate an alternative source.

  • Supplier continuity

    Continuity requirements in contracts, continuity plans obtained and verified, tooling transfer clauses, robustness audits at critical suppliers.

  • Analytics and decision support

    Predictive models for delay or disruption, digital twin of the logistics network, use of AI to support arbitration, uptake of results by operational teams.

  • Governance and learning

    Resilience governance structure, indicators tracked at executive committee level, post incident lessons learned, updating of scenarios and progress measured over time.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this framework lead to certification?

No. The resilience index is a capability grid, with no certification body behind it. It measures where you stand and what moves you forward. If your need concerns the security of flows with a certifying scheme, ISO 28000 is what to look at.

How does the maturity assessment differ from a supplier audit?

A supplier audit covers a third party and checks specific points at their premises. The assessment covers your own capabilities: your visibility, your decision speed, your flexibility. The two feed each other, the audit supplies the data, the assessment says what to do with it.

How long does the assessment take?

The short version can be completed in a single working session. The full version involves several contributors, procurement, supply chain, manufacturing, data, and spans one to two weeks, most of the time spent gathering factual elements.

Can the framework be adapted to our sector?

Yes. Themes, questions and levels can be modified, and AI produces a version tailored to your model from your documents, risk maps or existing continuity plans. The framework belongs to you.

Do we need perfect data to start the assessment?

No, and it is often the opposite. Data gaps are themselves a result of the assessment and feed into the action plan. You get a list of the data to recover as a priority, ranked by effect on the score.

Can several business units be compared?

Yes. Assessments can be run in series across multiple entities or regions, with an internal benchmark and comparison against your own past results. A cross entity roadmap then consolidates the action plans of the different units.

How is the action plan costed?

The gap between the score obtained and the target generates the actions. The service catalogue matches a solution to each action, with its cost, timeframe and expected impact on the score. AI groups these into a prioritised roadmap.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurement