RICHARD FORD | South Africa’s exporters face new hurdles as tariffs hit
As a new round of US tariffs hit, local exporters diversifying to other markets are managing to dodge some of the shocks.
Keeping their contracts will soon depend less on notices from the US trade office, though; they will depend more on the likes of a European buyer’s compliance department, and the subject line will be “cybersecurity”.
On July 24 the US hit South Africa with a fresh 12.5% tariff, the latest in a series of trade shocks just this year. The government’s response to the uncertainty in global trade has been to push exporters toward the markets the old preferential agreements with the US never fully covered anyway: the EU, Asia and the rest of the African continent through the African Continental Free Trade Area.
That diversification is widely considered the right call, but what it hasn’t fully reckoned with is that some of those replacement markets are starting to check South African suppliers’ cybersecurity credentials before they check anything else.
In January the European Commission proposed updates to two of the EU’s core cyber instruments, including new guidelines on supply chain security assessments and a mechanism for Brussels to formally flag suppliers from countries it considers high risk.
This builds on requirements already in force under the NIS2 Directive, which obliges EU organisations in critical sectors to assess the cybersecurity practices of their direct suppliers, regardless of where those suppliers are based.
In practice, for a supplier outside the bloc this means renegotiated contracts, more intensive due diligence and, in some cases, replacement when a supplier’s security standards fall short of what the buyer now has to prove to its own regulator.
None of this is confined to Europe as a unique case or outlier. The trend shows that it is where every serious procurement process is headed, and it explains why a credential like ISO 27001 has become a boarding pass of sorts. A South African exporter chasing a contract in Rotterdam or Singapore now needs to be assessed on price, reliability and whether its security posture would survive its buyer’s own audit.
There’s also a very real domestic case for taking this seriously. An analysis of South Africa’s breach economics has put the cumulative cost of the country’s reported data breaches at more than R142bn in a single financial year , equivalent to about 1.8% of GDP.
A South African exporter chasing a contract in Rotterdam or Singapore now needs to be assessed on price, reliability and whether its security posture would survive its buyer’s own audit.
That figure covers direct remediation, lost business and regulatory response. It does not cover the contracts that were never signed because a prospective buyer looked at a supplier’s security controls and walked away without saying why — a decision that never makes a headline.
This is the part boards still underestimate. A weak cybersecurity posture used to be an internal risk, the kind that showed up in an incident report after the fact.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.businesslive.co.za — the content belongs to Business Day.