[{"data":1,"prerenderedAt":329},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-tprm-saas":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":23,"entities":280,"extension":283,"faq":284,"keywords":302,"meta":306,"navigation":307,"ogImage":308,"path":22,"persona":309,"publishedAt":308,"regulation":308,"relatedFeatures":310,"relatedPages":314,"seo":317,"shortTitle":21,"slug":318,"sources":319,"stem":325,"tldr":326,"updatedAt":327,"__hash__":328},"solutions_en\u002Fen\u002Fsolutions\u002Ftprm-saas.md","TPRM SaaS: Vendor Risk Management Platform | CISAPP","CISAPP",{"type":108,"value":109,"toc":273},"minimark",[110,115,128,131,155,159,252,256,259],[111,112,114],"h2",{"id":113},"what-is-a-tprm-saas-platform","What is a TPRM SaaS platform?",[116,117,118,127],"p",{},[119,120,121,126],"strong",{},[122,123,125],"a",{"href":124},"\u002Fen\u002Fglossary\u002Ftprm","TPRM"," — Third-Party Risk Management — is the set of processes used to identify, assess and monitor the risk posed by an organisation's vendors and service providers."," Delivered as SaaS, it replaces spreadsheets and email threads with a single, current repository where every piece of evidence stays tied to a third party, a risk and an obligation.",[116,129,130],{},"CISAPP is built for both sides of the relationship: the company assessing, and the vendor answering.",[132,133,134],"key-takeaways",{},[135,136,137,141,149,152],"ul",{},[138,139,140],"li",{},"A third-party inventory with justified criticality is the foundation of any TPRM programme.",[138,142,143,144,148],{},"Declarative questionnaires and technical ",[122,145,147],{"href":146},"\u002Fen\u002Fglossary\u002Fsecurity-posture-score","posture scores"," complement each other — neither is sufficient alone.",[138,150,151],{},"Periodic reassessment is what an audit checks, more than the initial assessment.",[138,153,154],{},"Evidence collected should feed the NIS2, DORA, ISO 27001 and GDPR frameworks directly.",[111,156,158],{"id":157},"what-the-platform-covers","What the platform covers",[160,161,163],"comparison-table",{"caption":162},"TPRM lifecycle stages and the corresponding CISAPP tooling",[164,165,166,182],"table",{},[167,168,169],"thead",{},[170,171,172,176,179],"tr",{},[173,174,175],"th",{},"Lifecycle stage",[173,177,178],{},"Question it answers",[173,180,181],{},"CISAPP tooling",[183,184,185,197,208,219,230,241],"tbody",{},[170,186,187,191,194],{},[188,189,190],"td",{},"Inventory and criticality",[188,192,193],{},"Which third parties, for which activities?",[188,195,196],{},"Vendor record, dependency mapping",[170,198,199,202,205],{},[188,200,201],{},"Initial assessment",[188,203,204],{},"What security level is claimed and observed?",[188,206,207],{},"Questionnaire campaigns, SecOps score",[170,209,210,213,216],{},[188,211,212],{},"Contracting decision",[188,214,215],{},"Accept, require measures, or walk away?",[188,217,218],{},"Risk register, remediation plan",[170,220,221,224,227],{},[188,222,223],{},"Continuous monitoring",[188,225,226],{},"Is the level degrading?",[188,228,229],{},"Recurring scans, alerts, certificate tracking",[170,231,232,235,238],{},[188,233,234],{},"Periodic reassessment",[188,236,237],{},"Is the evidence still valid?",[188,239,240],{},"Scheduled campaigns, validity dates",[170,242,243,246,249],{},[188,244,245],{},"Exit",[188,247,248],{},"What is left to retrieve or delete?",[188,250,251],{},"Access and data traceability",[111,253,255],{"id":254},"why-move-from-an-internal-tool-to-a-tprm-platform","Why move from an internal tool to a TPRM platform",[116,257,258],{},"NIS2 or DORA compliance projects run by hand take months, mostly in re-keying: the same vendor answer is copied into an assessment spreadsheet, then a regulatory tracker, then an audit file. A TPRM platform removes those successive copies — the answer is captured once and read in all three contexts.",[116,260,261,262,265,266,269,270,272],{},"See also ",[122,263,264],{"href":26},"vendor risk management",", the ",[122,267,268],{"href":18},"third-party GRC platform"," and the ",[122,271,54],{"href":55}," page.",{"title":274,"searchDepth":275,"depth":275,"links":276},"",2,[277,278,279],{"id":113,"depth":275,"text":114},{"id":157,"depth":275,"text":158},{"id":254,"depth":275,"text":255},[125,281,282],"Security posture score","Vendor due diligence","md",[285,287,290,293,296,299],{"q":114,"a":286},"Third-Party Risk Management (TPRM) covers all the processes used to assess and monitor the risk posed by your vendors and service providers. A TPRM SaaS platform delivers those processes online — inventory, campaigns, scoring, mapping, evidence — with nothing to deploy or maintain.",{"q":288,"a":289},"How does a TPRM tool differ from an assessment spreadsheet?","A spreadsheet records answers at a point in time; a TPRM platform maintains a living state. Reassessments are scheduled, evidence is timestamped, risks are tracked to closure and every item ties back to a regulatory obligation — none of which a shared file can evidence at audit.",{"q":291,"a":292},"Does CISAPP replace vendor assessment spreadsheets?","Yes. Assessment campaigns, scoring and dependency mapping replace scattered spreadsheets and emails with a single, current source of truth.",{"q":294,"a":295},"How long does deployment take?","Being SaaS, there is nothing to install: most of the time goes into importing your third-party inventory and choosing your starting questionnaires, and the preconfigured library (ISO 27001, NIS2, DORA, GDPR) removes the need to write them.",{"q":297,"a":298},"Do vendors have to pay to respond?","No. The vendor workspace is free: the third party answers, reuses previous answers across customers and shares certifications from a single account.",{"q":300,"a":301},"Does CISAPP cover NIS2, DORA, ISO 27001 and GDPR?","Yes, those four frameworks are pre-wired and linked to vendor assessments: one piece of evidence received feeds both the third-party record and the relevant regulatory framework.",[21,303,304,305],"TPRM platform","third-party risk management SaaS","TPRM software",{},true,null,"entreprise",[311,33,312,313],"Assessment campaigns","Dependency mapping","Regulatory frameworks",[315,316],"vendor-risk-management","third-party-grc-platform",{"title":105,"description":23},"tprm-saas",[320],{"label":321,"url":322,"publisher":323,"date":324},"Directive (EU) 2022\u002F2555 (NIS2), Article 21 — supply chain security","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdir\u002F2022\u002F2555\u002Foj","EUR-Lex","2022-12-14","en\u002Fsolutions\u002Ftprm-saas","A TPRM SaaS platform centralises the assessment and monitoring of vendor risk: third-party inventory, questionnaire campaigns, technical scoring, dependency mapping and mapping to regulatory frameworks. CISAPP covers both sides of the relationship — the company assessing and the vendor answering — with no infrastructure to run.","2026-08-16","KdSIsc4KeKuWVaJTEkAbxc-OA310qxaX9yHerym7tQE",1791391139064]