Glossary
Vendor due diligence
Vendor due diligence is the assessment carried out before contracting, and periodically thereafter, to verify that a third party's security, compliance and continuity posture matches the criticality of the service it delivers and of the data it accesses.
The proportionality principle
Sending the same questionnaire to a video conferencing tool and to the host of the payroll system is the most common failure: it saturates low-risk vendors and delays the analysis of genuinely critical ones. Due diligence is sized from three variables — nature of the data accessed, criticality of the activity supported, level of integration into the information system — which set the required depth: simple declaration, full questionnaire, certifications and evidence, or audit.
What it must produce
Useful due diligence does not produce an isolated score but a traceable decision: contract, contract subject to compensating measures with a deadline, or walk away. That decision and its supporting evidence are what an ISO 27001 auditor or a NIS2 authority will ask for — not the questionnaire itself. Full method in the vendor cyber due diligence guide.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours