Solutions
Vendor risk management and compliance solutions
Security assessments, questionnaires, posture scoring, dependency mapping, regulatory frameworks: each CISAPP solution covers a specific third-party risk use case and can be enabled independently.
CISAPP covers the full vendor lifecycle: selection and due diligence before signing, continuous assessment during the contract, incident and remediation handling, and audit-ready evidence. The modules below are enabled according to your regulatory obligations and programme maturity — you only pay for what you use.
DORA + ISO 27001
Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.
Read moreNIS2 vendors
Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.
Read moreSupply chain
Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.
Read moreThird-party GRC
CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.
Read moreTPRM SaaS
CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.
Read moreVendor risk
Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.
Read moreQuestionnaires
Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.
Read moreSecOps score
Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.
Read more
FAQ
No. Most organisations start with vendor mapping and assessment questionnaires, then enable regulatory frameworks (NIS2, DORA, ISO 27001) as their obligations require.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours