Solutions
TPRM SaaS: Vendor Risk Management Platform
CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.
TL;DR
A TPRM SaaS platform centralises the assessment and monitoring of vendor risk: third-party inventory, questionnaire campaigns, technical scoring, dependency mapping and mapping to regulatory frameworks. CISAPP covers both sides of the relationship — the company assessing and the vendor answering — with no infrastructure to run.
What is a TPRM SaaS platform?
TPRM — Third-Party Risk Management — is the set of processes used to identify, assess and monitor the risk posed by an organisation's vendors and service providers. Delivered as SaaS, it replaces spreadsheets and email threads with a single, current repository where every piece of evidence stays tied to a third party, a risk and an obligation.
CISAPP is built for both sides of the relationship: the company assessing, and the vendor answering.
What the platform covers
| Lifecycle stage | Question it answers | CISAPP tooling |
|---|---|---|
| Inventory and criticality | Which third parties, for which activities? | Vendor record, dependency mapping |
| Initial assessment | What security level is claimed and observed? | Questionnaire campaigns, SecOps score |
| Contracting decision | Accept, require measures, or walk away? | Risk register, remediation plan |
| Continuous monitoring | Is the level degrading? | Recurring scans, alerts, certificate tracking |
| Periodic reassessment | Is the evidence still valid? | Scheduled campaigns, validity dates |
| Exit | What is left to retrieve or delete? | Access and data traceability |
Why move from an internal tool to a TPRM platform
NIS2 or DORA compliance projects run by hand take months, mostly in re-keying: the same vendor answer is copied into an assessment spreadsheet, then a regulatory tracker, then an audit file. A TPRM platform removes those successive copies — the answer is captured once and read in all three contexts.
See also vendor risk management, the third-party GRC platform and the NIS2 page.
FAQ
Third-Party Risk Management (TPRM) covers all the processes used to assess and monitor the risk posed by your vendors and service providers. A TPRM SaaS platform delivers those processes online — inventory, campaigns, scoring, mapping, evidence — with nothing to deploy or maintain.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 21 — supply chain security — EUR-Lex, 2022-12-14
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours