Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

Vendor risk reviews that show which third parties need attention

We review the vendors and service providers that handle your data or connect to your systems, rate the risk each one poses, and give you prioritized follow-up actions.

What we deliver

Third-party and vendor-risk reviews with prioritized remediation guidance.

References
NIST CSF 2.0

Who it's for

A good fit for

  • Organizations that have added many SaaS tools and service providers without a consistent review
  • Teams whose customers, auditors, or regulators ask how third-party risk is managed
  • Organizations that share sensitive or regulated data, such as health information, with vendors
  • Procurement and legal teams that need security input before signing with a new vendor

Not the right fit for

  • Organizations that need on-site audits of vendor facilities
  • Teams looking for a software platform to automate vendor questionnaires
  • Anyone who needs a legal opinion on vendor contracts

Problems it addresses

  • No one has a complete list of the vendors that store your data or connect to your systems.
  • Every vendor gets the same long questionnaire, and the answers are rarely read.
  • SOC 2 reports are collected but not checked for scope, exceptions, or the controls you're expected to run.
  • When a vendor has a security incident, you can't quickly tell what data or access they had.

Scope

Included

  • Building or refining an inventory of vendors, the data they handle, and the access they have
  • Tiering vendors by risk so review effort matches what's at stake
  • Review of vendor evidence such as SOC 2 reports, ISO/IEC 27001 certificates, penetration test summaries, and questionnaire responses
  • Checking SOC 2 reports for scope, period covered, exceptions, and the complementary user entity controls you're expected to operate
  • Prioritized follow-up actions for each reviewed vendor
  • A repeatable intake and reassessment process your team can run

Not included

  • On-site audits of vendor facilities or testing of vendor systems
  • Negotiating or drafting contract language
  • Ongoing automated monitoring of vendors

Deliverables

  • Vendor inventory with data types, access, and risk tier
  • Review summary for each in-scope vendor, with a risk rating and follow-up actions
  • Portfolio view showing where third-party risk is concentrated
  • Tiered questionnaire set and review criteria
  • Documented intake, review, and reassessment procedure

How the engagement runs

Every engagement begins with a written scope and proposal.

  1. Inventory

    We gather vendor lists from finance, IT, and procurement, and identify which vendors handle sensitive data or have system access.

  2. Tier

    We agree on risk tiers with you and decide how deeply to review vendors in each one.

  3. Review

    We request and review vendor evidence, follow up on gaps, and rate each vendor's risk.

  4. Prioritize

    We report which vendors need action and what that action should be.

  5. Hand off

    We document the process and train your team to run intake and reassessment on its own.

Standards and methods

  • NIST CSF 2.0 Cybersecurity Supply Chain Risk Management category (GV.SC)
  • Vendor assurance reports, such as SOC 2 reports and ISO/IEC 27001 certificates, read for scope and relevance to how you use the vendor

How to read a vendor's SOC 2 report

A vendor's SOC 2 report helps only if it covers what you rely on. Work through it in this order:

  • Report type and timing: a Type 1 report speaks to control design as of one date; a Type 2 report adds operating effectiveness throughout a period. Note how recent the date or period is.
  • Scope and system description: confirm that the services and system you use are the ones described, and which Trust Services Criteria categories are in scope.
  • Subservice organizations: see which of the vendor's own vendors the report depends on, and whether each is included (the inclusive method) or carved out. For a carved-out vendor, the report describes the controls it assumes that vendor operates, and you may want that vendor's own report.
  • Complementary user entity controls: list the controls the vendor assumed its customers would operate, and confirm you actually operate them.
  • Tests and results: in a Type 2 report, read the service auditor's description of tests and results, and follow up on any exceptions with the vendor.
  • The opinion and its issuer: check whether the opinion is modified, and why, and confirm the report comes from a licensed CPA firm.

Sources: AICPA & CIMA: 2018 SOC 2 Description Criteria (With Revised Implementation Guidance – 2022); AICPA & CIMA: 2017 Trust Services Criteria (With Revised Points of Focus – 2022)

Vendor risk in NIST CSF 2.0 (GV.SC)

NIST CSF 2.0 treats vendor risk as Cybersecurity Supply Chain Risk Management (GV.SC), a category of the Govern Function in which cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders. Several of its outcomes follow the life of a supplier relationship:

  • GV.SC-05: requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other agreements
  • GV.SC-06: planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • GV.SC-07: the risks posed by a supplier, its products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • GV.SC-08: relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • GV.SC-10: supply chain risk management plans include provisions for activities after a partnership or service agreement ends

Source: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0 (February 26, 2024)

Prerequisites and your responsibilities

  • Vendor lists from finance or procurement, plus existing contracts and questionnaires
  • A contact in each business area that owns a vendor relationship
  • Authority to request evidence from vendors, or introductions to vendor contacts
  • Agreement on who approves risk acceptance when a vendor falls short

Pricing

There's no published starting price for this service. Pricing is set in your proposal after scoping.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

What a vendor review can and can't tell you

Vendor-risk reviews are based on the evidence a vendor provides or publishes at the time of review. They aren't audits of the vendor and don't guarantee the vendor's security.

Guides

Frequently asked questions

Do you contact our vendors directly?

If you'd like us to. Some clients prefer to send requests themselves and have us review what comes back; others introduce us so we can follow up on gaps directly. Either way, requests go out under your name and your relationship with the vendor.

What if a vendor won't share a SOC 2 report?

It happens, especially with smaller vendors. We look for other evidence, such as a completed questionnaire, a security overview, a penetration test summary, or a call with their security contact, and we note the reduced assurance in the rating.

How many vendors can you review?

Tiering means the vendors with the most data and access get the deepest review, while lower-risk vendors get a lighter check. The number of vendors in each tier is agreed in your written scope.

How often should vendors be reassessed?

It depends on risk. Higher-risk vendors are commonly reviewed at least once a year and whenever their service or your use of it changes; lower-risk vendors can be reviewed less often. We'll set a schedule that fits your tiers and obligations.

Primary sources

Talk to a practitioner about vendor risk

Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.

What happens next

  1. Tell us about your environment and what's driving the request.
  2. Talk through goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.