Threat actors are employing increasingly sophisticated techniques to target both IT and OT environments. Thus, it is important that operators work to strengthen their supplier risk management and align with evolving expectations. This paper consolidates the challenges and translate them into a set of best practices to support operators in enhancing their supply chain security posture.