Resources

Vendor Cyber Due Diligence: Assessing Security Before You Sign

How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.

TL;DR

Vendor cyber due diligence assesses a third party's security posture before signature, while the organisation still has the leverage to negotiate or walk away. It combines three sources: the declarative (questionnaire), the documentary (certifications, audit reports) and the observed (external technical score). Its depth should follow the vendor's criticality.

What is vendor cyber due diligence?

Vendor cyber due diligence means assessing a third party's security posture before entrusting them with data, network access, or a business dependency — not after. This is the moment your organization holds the most leverage: the contract isn't signed yet, the vendor is still a candidate, and any security requirement can still be negotiated or made disqualifying.

Yet this is precisely the moment where rigor is most often sacrificed. Commercial pressure to move fast, the absence of a formalized process across procurement, legal, and security, and the sense that "it's just a small vendor" lead to onboardings completed without a serious assessment — or with a cosmetic one, limited to a checked box: "do you have ISO 27001?" taken at face value without verification.

The problem is that risk inherited at signature never really goes away. A poorly assessed vendor at entry remains a weak link for the entire duration of the contract, often several years, with access that grows over time (new integrations, new data flows) without any structured re-examination ever taking place.

Why does due diligence fail in practice?

It's declarative, not verified. The security questionnaire sent to a candidate vendor is filled out by the vendor itself, without cross-verification. A vendor in a sales cycle has a direct incentive to answer positively to every question — independent verification (external posture score, documentary proof) is often missing.

It isn't proportionate to criticality. Without a clear classification method, the same generic 40-question questionnaire gets sent to an office-furniture supplier and to a managed service provider with permanent VPN access to the production network. The result: verification effort isn't concentrated where exposure is real.

It stops at signature. Once the contract is signed, the due diligence file is archived and rarely reopened — while the vendor's posture keeps evolving. Without a periodic reassessment mechanism, the organization navigates on a snapshot that's years old.

The concrete result: at the moment of an incident or a regulatory audit (NIS2, DORA), the organization discovers it can produce no structured proof of the due diligence performed at entry, nor of its follow-up over time — a direct compliance gap and a legal exposure in case of damage caused by the third party.

How do you make due diligence proportionate and traceable?

Robust vendor cyber due diligence, aligned with ISO 27001 principles (supplier controls, clauses A.5.19 to A.5.23) and with the third-party risk requirements of NIS2 and DORA, follows a structured sequence.

1. Classify before assessing. Define objective criticality criteria upfront: access to personal or sensitive data, connection to the information system, whether the vendor is replaceable, the impact of downtime on a business activity. This classification determines the required depth of assessment — not the other way around.

2. Match the questionnaire to the risk profile. A critical vendor justifies a detailed questionnaire aligned with a recognized framework (ISO 27001, NIS2), with expected documentary evidence. A low-stakes vendor can go through a lighter check. Reusing a question library structured by theme (governance, access management, encryption, incident response, subcontracting) avoids reinventing the assessment for every new candidate.

3. Cross-check self-reported data against external signal. Vendor answers should be complemented by an independent source: verifiable certifications, external posture scan results (exposure, DNS/TLS configuration, breach history). This cross-check quickly reveals gaps between what's declared and what's observable.

4. Document the decision, not just the result. Serious due diligence keeps a record of the criticality assigned, the gaps identified, and the decision made (acceptance, remediation required, rejection). This traceability is what protects the organization in the event of a dispute or regulatory review.

5. Plan for reassessment from day one. Due diligence shouldn't be a one-off milestone but the starting point of a cycle: periodic reassessment proportional to criticality, automatically triggered by an incident or a change in contractual scope.

Due diligence depth expected by vendor criticality
CriticalityAccess and dataEvidence to collectDecision
CriticalSensitive data, network access, no fallbackFull questionnaire, certification and scope, audit report, external score, sub-processorsFormal sign-off before signature
HighPersonal or confidential dataTargeted questionnaire, certifications, external scoreSign-off with recorded reservations
ModerateLimited access, substitutable activityShort questionnaire, external scoreStandard sign-off
LowNo access to systems or dataMinimal documentary checkSign-off at contract review

How does CISAPP structure due diligence?

CISAPP covers this entire cycle in a single workflow, built for procurement, security, and risk teams.

Guided search and onboarding. Directory search (SIRENE, GLEIF, web search) pre-fills legal and sector information for a candidate vendor, cutting down manual entry. The six-step onboarding wizard (search → selection → information → criticality → contacts → access) requires criticality to be documented at creation, with justification — not as an afterthought.

Proportionate, reusable questionnaires. The library of preconfigured questionnaires (ISO 27001, NIS2, DORA, GDPR) and the reusable question bank let you match assessment depth to the chosen criticality level, without starting from scratch for every vendor. The visual builder lets you adapt a questionnaire to a sector or engagement type.

Independent verification via the SecOps score. When the vendor is present in CISAPP or agrees to share its posture through My Exposure, its composite security score (DNS, TLS, exposure, breach, security headers) complements its self-reported answers — a direct cross-check between what's said and what's technically observable.

Structured comparison across candidates. The vendor comparison module (/vendors/compare) lets you place several candidates side by side on the same questionnaires and scope — a direct asset for arbitrating an RFP on objectified security criteria, not just commercial ones.

Full traceability and reassessment. Every assessment, identified gap, and decision made stays attached to the vendor record, with history. Criticality reassessment can be triggered at any time — notably after an incident — keeping the due diligence file alive rather than frozen on signature day.

Granting access or data to a vendor without structured due diligence means inheriting its risk level without knowing it. CISAPP gives procurement and security teams a shared, proportionate, traceable workflow to make that decision with eyes open — before signing, not after an incident.

FAQ

Before the contract is signed, as early as the selection phase. Once the contract is signed and access is granted, the balance of power shifts and it becomes far harder to demand remediation or walk away from the vendor.

Sources

  1. ISO/IEC 27001:2022, controls A.5.19 and A.5.20 — supplier relationships and agreements — ISO, 2022-10-25

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account