01
Who it's for
A good fit for
- Organizations that have added many SaaS tools and service providers without a consistent review
- Teams whose customers, auditors, or regulators ask how third-party risk is managed
- Organizations that share sensitive or regulated data, such as health information, with vendors
- Procurement and legal teams that need security input before signing with a new vendor
Not the right fit for
- Organizations that need on-site audits of vendor facilities
- Teams looking for a software platform to automate vendor questionnaires
- Anyone who needs a legal opinion on vendor contracts
02
Problems it addresses
- No one has a complete list of the vendors that store your data or connect to your systems.
- Every vendor gets the same long questionnaire, and the answers are rarely read.
- SOC 2 reports are collected but not checked for scope, exceptions, or the controls you're expected to run.
- When a vendor has a security incident, you can't quickly tell what data or access they had.
03
Scope
Included
- Building or refining an inventory of vendors, the data they handle, and the access they have
- Tiering vendors by risk so review effort matches what's at stake
- Review of vendor evidence such as SOC 2 reports, ISO/IEC 27001 certificates, penetration test summaries, and questionnaire responses
- Checking SOC 2 reports for scope, period covered, exceptions, and the complementary user entity controls you're expected to operate
- Prioritized follow-up actions for each reviewed vendor
- A repeatable intake and reassessment process your team can run
Not included
- On-site audits of vendor facilities or testing of vendor systems
- Negotiating or drafting contract language
- Ongoing automated monitoring of vendors
04
Deliverables
- Vendor inventory with data types, access, and risk tier
- Review summary for each in-scope vendor, with a risk rating and follow-up actions
- Portfolio view showing where third-party risk is concentrated
- Tiered questionnaire set and review criteria
- Documented intake, review, and reassessment procedure
05
How the engagement runs
Every engagement begins with a written scope and proposal.
- 01
Inventory
We gather vendor lists from finance, IT, and procurement, and identify which vendors handle sensitive data or have system access.
- 02
Tier
We agree on risk tiers with you and decide how deeply to review vendors in each one.
- 03
Review
We request and review vendor evidence, follow up on gaps, and rate each vendor's risk.
- 04
Prioritize
We report which vendors need action and what that action should be.
- 05
Hand off
We document the process and train your team to run intake and reassessment on its own.
06
Standards and methods
- NIST CSF 2.0 Cybersecurity Supply Chain Risk Management category (GV.SC)
- Vendor assurance reports, such as SOC 2 reports and ISO/IEC 27001 certificates, read for scope and relevance to how you use the vendor
07
How to read a vendor's SOC 2 report
A vendor's SOC 2 report helps only if it covers what you rely on. Work through it in this order:
- Report type and timing: a Type 1 report speaks to control design as of one date; a Type 2 report adds operating effectiveness throughout a period. Note how recent the date or period is.
- Scope and system description: confirm that the services and system you use are the ones described, and which Trust Services Criteria categories are in scope.
- Subservice organizations: see which of the vendor's own vendors the report depends on, and whether each is included (the inclusive method) or carved out. For a carved-out vendor, the report describes the controls it assumes that vendor operates, and you may want that vendor's own report.
- Complementary user entity controls: list the controls the vendor assumed its customers would operate, and confirm you actually operate them.
- Tests and results: in a Type 2 report, read the service auditor's description of tests and results, and follow up on any exceptions with the vendor.
- The opinion and its issuer: check whether the opinion is modified, and why, and confirm the report comes from a licensed CPA firm.
Sources: AICPA & CIMA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); AICPA & CIMA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)
Read the full guide: SOC 2 Type 1 vs Type 2: which report do you need?
08
Vendor risk in NIST CSF 2.0 (GV.SC)
NIST CSF 2.0 treats vendor risk as Cybersecurity Supply Chain Risk Management (GV.SC), a category of the Govern Function in which cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders. Several of its outcomes follow the life of a supplier relationship:
- GV.SC-05: requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other agreements
- GV.SC-06: planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
- GV.SC-07: the risks posed by a supplier, its products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
- GV.SC-08: relevant suppliers and other third parties are included in incident planning, response, and recovery activities
- GV.SC-10: supply chain risk management plans include provisions for activities after a partnership or service agreement ends
Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)
09
Prerequisites and your responsibilities
- Vendor lists from finance or procurement, plus existing contracts and questionnaires
- A contact in each business area that owns a vendor relationship
- Authority to request evidence from vendors, or introductions to vendor contacts
- Agreement on who approves risk acceptance when a vendor falls short
10
Pricing
Pricing // USD
There's no published starting price for this service. Pricing is set in your proposal after scoping.
What affects the final price
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Compare published prices for every service
What a vendor review can and can't tell you
Vendor-risk reviews are based on the evidence a vendor provides or publishes at the time of review. They aren't audits of the vendor and don't guarantee the vendor's security.
Frequently asked questions
Do you contact our vendors directly?
If you'd like us to. Some clients prefer to send requests themselves and have us review what comes back; others introduce us so we can follow up on gaps directly. Either way, requests go out under your name and your relationship with the vendor.
What if a vendor won't share a SOC 2 report?
It happens, especially with smaller vendors. We look for other evidence, such as a completed questionnaire, a security overview, a penetration test summary, or a call with their security contact, and we note the reduced assurance in the rating.
How many vendors can you review?
Tiering means the vendors with the most data and access get the deepest review, while lower-risk vendors get a lighter check. The number of vendors in each tier is agreed in your written scope.
How often should vendors be reassessed?
It depends on risk. Higher-risk vendors are commonly reviewed at least once a year and whenever their service or your use of it changes; lower-risk vendors can be reviewed less often. We'll set a schedule that fits your tiers and obligations.