[{"data":1,"prerenderedAt":415},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"guide-en-vendor-cyber-due-diligence":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":85,"entities":358,"extension":362,"faq":363,"keywords":382,"meta":388,"navigation":389,"ogImage":390,"path":391,"persona":392,"publishedAt":393,"regulation":390,"relatedFeatures":394,"relatedPages":399,"seo":403,"shortTitle":83,"slug":404,"sources":405,"stem":411,"tldr":412,"updatedAt":413,"__hash__":414},"guides_en\u002Fen\u002Fguides\u002Fvendor-cyber-due-diligence.md","Vendor Cyber Due Diligence: Assessing Security Before You Sign | CISAPP","CISAPP",{"type":108,"value":109,"toc":350},"minimark",[110,115,124,127,130,149,153,159,165,171,174,178,181,187,193,199,205,211,297,301,304,314,320,330,341,347],[111,112,114],"h2",{"id":113},"what-is-vendor-cyber-due-diligence","What is vendor cyber due diligence?",[116,117,118,119,123],"p",{},"Vendor cyber due diligence means assessing a third party's security posture ",[120,121,122],"strong",{},"before"," entrusting them with data, network access, or a business dependency — not after. This is the moment your organization holds the most leverage: the contract isn't signed yet, the vendor is still a candidate, and any security requirement can still be negotiated or made disqualifying.",[116,125,126],{},"Yet this is precisely the moment where rigor is most often sacrificed. Commercial pressure to move fast, the absence of a formalized process across procurement, legal, and security, and the sense that \"it's just a small vendor\" lead to onboardings completed without a serious assessment — or with a cosmetic one, limited to a checked box: \"do you have ISO 27001?\" taken at face value without verification.",[116,128,129],{},"The problem is that risk inherited at signature never really goes away. A poorly assessed vendor at entry remains a weak link for the entire duration of the contract, often several years, with access that grows over time (new integrations, new data flows) without any structured re-examination ever taking place.",[131,132,133],"key-takeaways",{},[134,135,136,140,143,146],"ul",{},[137,138,139],"li",{},"Before signature the organisation has maximum leverage; afterwards only renegotiation remains.",[137,141,142],{},"Three sources cross-check each other: declarative, documentary evidence, external technical findings.",[137,144,145],{},"Depth must follow criticality — one questionnaire for everyone dilutes the effort.",[137,147,148],{},"The final decision, including accepting a gap, must be traced and attributed.",[111,150,152],{"id":151},"why-does-due-diligence-fail-in-practice","Why does due diligence fail in practice?",[116,154,155,158],{},[120,156,157],{},"It's declarative, not verified."," The security questionnaire sent to a candidate vendor is filled out by the vendor itself, without cross-verification. A vendor in a sales cycle has a direct incentive to answer positively to every question — independent verification (external posture score, documentary proof) is often missing.",[116,160,161,164],{},[120,162,163],{},"It isn't proportionate to criticality."," Without a clear classification method, the same generic 40-question questionnaire gets sent to an office-furniture supplier and to a managed service provider with permanent VPN access to the production network. The result: verification effort isn't concentrated where exposure is real.",[116,166,167,170],{},[120,168,169],{},"It stops at signature."," Once the contract is signed, the due diligence file is archived and rarely reopened — while the vendor's posture keeps evolving. Without a periodic reassessment mechanism, the organization navigates on a snapshot that's years old.",[116,172,173],{},"The concrete result: at the moment of an incident or a regulatory audit (NIS2, DORA), the organization discovers it can produce no structured proof of the due diligence performed at entry, nor of its follow-up over time — a direct compliance gap and a legal exposure in case of damage caused by the third party.",[111,175,177],{"id":176},"how-do-you-make-due-diligence-proportionate-and-traceable","How do you make due diligence proportionate and traceable?",[116,179,180],{},"Robust vendor cyber due diligence, aligned with ISO 27001 principles (supplier controls, clauses A.5.19 to A.5.23) and with the third-party risk requirements of NIS2 and DORA, follows a structured sequence.",[116,182,183,186],{},[120,184,185],{},"1. Classify before assessing."," Define objective criticality criteria upfront: access to personal or sensitive data, connection to the information system, whether the vendor is replaceable, the impact of downtime on a business activity. This classification determines the required depth of assessment — not the other way around.",[116,188,189,192],{},[120,190,191],{},"2. Match the questionnaire to the risk profile."," A critical vendor justifies a detailed questionnaire aligned with a recognized framework (ISO 27001, NIS2), with expected documentary evidence. A low-stakes vendor can go through a lighter check. Reusing a question library structured by theme (governance, access management, encryption, incident response, subcontracting) avoids reinventing the assessment for every new candidate.",[116,194,195,198],{},[120,196,197],{},"3. Cross-check self-reported data against external signal."," Vendor answers should be complemented by an independent source: verifiable certifications, external posture scan results (exposure, DNS\u002FTLS configuration, breach history). This cross-check quickly reveals gaps between what's declared and what's observable.",[116,200,201,204],{},[120,202,203],{},"4. Document the decision, not just the result."," Serious due diligence keeps a record of the criticality assigned, the gaps identified, and the decision made (acceptance, remediation required, rejection). This traceability is what protects the organization in the event of a dispute or regulatory review.",[116,206,207,210],{},[120,208,209],{},"5. Plan for reassessment from day one."," Due diligence shouldn't be a one-off milestone but the starting point of a cycle: periodic reassessment proportional to criticality, automatically triggered by an incident or a change in contractual scope.",[212,213,215],"comparison-table",{"caption":214},"Due diligence depth expected by vendor criticality",[216,217,218,237],"table",{},[219,220,221],"thead",{},[222,223,224,228,231,234],"tr",{},[225,226,227],"th",{},"Criticality",[225,229,230],{},"Access and data",[225,232,233],{},"Evidence to collect",[225,235,236],{},"Decision",[238,239,240,255,269,283],"tbody",{},[222,241,242,246,249,252],{},[243,244,245],"td",{},"Critical",[243,247,248],{},"Sensitive data, network access, no fallback",[243,250,251],{},"Full questionnaire, certification and scope, audit report, external score, sub-processors",[243,253,254],{},"Formal sign-off before signature",[222,256,257,260,263,266],{},[243,258,259],{},"High",[243,261,262],{},"Personal or confidential data",[243,264,265],{},"Targeted questionnaire, certifications, external score",[243,267,268],{},"Sign-off with recorded reservations",[222,270,271,274,277,280],{},[243,272,273],{},"Moderate",[243,275,276],{},"Limited access, substitutable activity",[243,278,279],{},"Short questionnaire, external score",[243,281,282],{},"Standard sign-off",[222,284,285,288,291,294],{},[243,286,287],{},"Low",[243,289,290],{},"No access to systems or data",[243,292,293],{},"Minimal documentary check",[243,295,296],{},"Sign-off at contract review",[111,298,300],{"id":299},"how-does-cisapp-structure-due-diligence","How does CISAPP structure due diligence?",[116,302,303],{},"CISAPP covers this entire cycle in a single workflow, built for procurement, security, and risk teams.",[116,305,306,309,310,313],{},[120,307,308],{},"Guided search and onboarding."," Directory search (SIRENE, GLEIF, web search) pre-fills legal and sector information for a candidate vendor, cutting down manual entry. The six-step onboarding wizard (search → selection → information → criticality → contacts → access) requires criticality to be documented ",[120,311,312],{},"at creation",", with justification — not as an afterthought.",[116,315,316,319],{},[120,317,318],{},"Proportionate, reusable questionnaires."," The library of preconfigured questionnaires (ISO 27001, NIS2, DORA, GDPR) and the reusable question bank let you match assessment depth to the chosen criticality level, without starting from scratch for every vendor. The visual builder lets you adapt a questionnaire to a sector or engagement type.",[116,321,322,325,326,329],{},[120,323,324],{},"Independent verification via the SecOps score."," When the vendor is present in CISAPP or agrees to share its posture through ",[120,327,328],{},"My Exposure",", its composite security score (DNS, TLS, exposure, breach, security headers) complements its self-reported answers — a direct cross-check between what's said and what's technically observable.",[116,331,332,335,336,340],{},[120,333,334],{},"Structured comparison across candidates."," The vendor comparison module (",[337,338,339],"code",{},"\u002Fvendors\u002Fcompare",") lets you place several candidates side by side on the same questionnaires and scope — a direct asset for arbitrating an RFP on objectified security criteria, not just commercial ones.",[116,342,343,346],{},[120,344,345],{},"Full traceability and reassessment."," Every assessment, identified gap, and decision made stays attached to the vendor record, with history. Criticality reassessment can be triggered at any time — notably after an incident — keeping the due diligence file alive rather than frozen on signature day.",[116,348,349],{},"Granting access or data to a vendor without structured due diligence means inheriting its risk level without knowing it. CISAPP gives procurement and security teams a shared, proportionate, traceable workflow to make that decision with eyes open — before signing, not after an incident.",{"title":351,"searchDepth":352,"depth":352,"links":353},"",2,[354,355,356,357],{"id":113,"depth":352,"text":114},{"id":151,"depth":352,"text":152},{"id":176,"depth":352,"text":177},{"id":299,"depth":352,"text":300},[359,360,361],"Vendor due diligence","Security questionnaire","Security posture score","md",[364,367,370,373,376,379],{"q":365,"a":366},"When should vendor cyber due diligence start?","Before the contract is signed, as early as the selection phase. Once the contract is signed and access is granted, the balance of power shifts and it becomes far harder to demand remediation or walk away from the vendor.",{"q":368,"a":369},"Is an ISO 27001 certificate enough to validate a vendor?","It's a good signal but insufficient alone: a certificate covers a given scope and audit date, not the actual technical exposure right now. It should be complemented by a targeted questionnaire and, ideally, an external posture score.",{"q":371,"a":372},"Do all vendors need the same level of due diligence?","No. Assessment depth should be proportional to criticality: access to sensitive data, network connectivity, business dependency. Applying the same questionnaire to everyone dilutes effort where it matters least.",{"q":374,"a":375},"How does CISAPP speed up vendor due diligence?","CISAPP centralizes search, onboarding wizard, preconfigured questionnaires, and SecOps score into one workflow, and lets you compare several candidate vendors on the same criteria before the final decision.",{"q":377,"a":378},"What evidence should you request beyond the questionnaire?","Depending on criticality: an ISO 27001 certificate with its scope and Statement of Applicability, a recent audit or penetration test report, the security policy, the continuity plan, the list of sub-processors and the data location.",{"q":380,"a":381},"What do you do when a candidate vendor fails due diligence?","Three outcomes, all traceable: require remediation with a deadline before signature, contract for compensating measures, or walk away. The decision must be formalised by a named owner — that is what an auditor examines, not just the questionnaire.",[383,384,385,386,387],"vendor cyber due diligence","vendor security assessment","pre-contract security audit","vendor onboarding security","third-party risk assessment",{},true,null,"\u002Fen\u002Fguides\u002Fvendor-cyber-due-diligence","entreprise","2026-07-11",[395,396,397,398],"Vendors","Evaluations","Questionnaires & library","SecOps",[400,401,402],"questionnaire-securite-fournisseur","tprm-saas","iso-27001",{"title":105,"description":85},"vendor-cyber-due-diligence",[406],{"label":407,"url":408,"publisher":409,"date":410},"ISO\u002FIEC 27001:2022, controls A.5.19 and A.5.20 — supplier relationships and agreements","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fguides\u002Fvendor-cyber-due-diligence","Vendor cyber due diligence assesses a third party's security posture before signature, while the organisation still has the leverage to negotiate or walk away. It combines three sources: the declarative (questionnaire), the documentary (certifications, audit reports) and the observed (external technical score). Its depth should follow the vendor's criticality.","2026-08-16","T0PPUVwWw8TVovM2-56eE_yJT6xCJeVIp0h8a3k5w9A",1791391139329]