Solutions

TPRM SaaS: Vendor Risk Management Platform

CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.

TL;DR

A TPRM SaaS platform centralises the assessment and monitoring of vendor risk: third-party inventory, questionnaire campaigns, technical scoring, dependency mapping and mapping to regulatory frameworks. CISAPP covers both sides of the relationship — the company assessing and the vendor answering — with no infrastructure to run.

What is a TPRM SaaS platform?

TPRM — Third-Party Risk Management — is the set of processes used to identify, assess and monitor the risk posed by an organisation's vendors and service providers. Delivered as SaaS, it replaces spreadsheets and email threads with a single, current repository where every piece of evidence stays tied to a third party, a risk and an obligation.

CISAPP is built for both sides of the relationship: the company assessing, and the vendor answering.

What the platform covers

TPRM lifecycle stages and the corresponding CISAPP tooling
Lifecycle stageQuestion it answersCISAPP tooling
Inventory and criticalityWhich third parties, for which activities?Vendor record, dependency mapping
Initial assessmentWhat security level is claimed and observed?Questionnaire campaigns, SecOps score
Contracting decisionAccept, require measures, or walk away?Risk register, remediation plan
Continuous monitoringIs the level degrading?Recurring scans, alerts, certificate tracking
Periodic reassessmentIs the evidence still valid?Scheduled campaigns, validity dates
ExitWhat is left to retrieve or delete?Access and data traceability

Why move from an internal tool to a TPRM platform

NIS2 or DORA compliance projects run by hand take months, mostly in re-keying: the same vendor answer is copied into an assessment spreadsheet, then a regulatory tracker, then an audit file. A TPRM platform removes those successive copies — the answer is captured once and read in all three contexts.

See also vendor risk management, the third-party GRC platform and the NIS2 page.

FAQ

Third-Party Risk Management (TPRM) covers all the processes used to assess and monitor the risk posed by your vendors and service providers. A TPRM SaaS platform delivers those processes online — inventory, campaigns, scoring, mapping, evidence — with nothing to deploy or maintain.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Article 21 — supply chain security — EUR-Lex, 2022-12-14

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account