[{"data":1,"prerenderedAt":312},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-vendor-risk-management":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":27,"entities":261,"extension":265,"faq":266,"keywords":284,"meta":289,"navigation":290,"ogImage":291,"path":26,"persona":292,"publishedAt":291,"regulation":291,"relatedFeatures":293,"relatedPages":297,"seo":300,"shortTitle":25,"slug":301,"sources":302,"stem":308,"tldr":309,"updatedAt":310,"__hash__":311},"solutions_en\u002Fen\u002Fsolutions\u002Fvendor-risk-management.md","Vendor Risk Management: A Complete Platform | CISAPP","CISAPP",{"type":108,"value":109,"toc":254},"minimark",[110,115,123,142,146,232,236,239],[111,112,114],"h2",{"id":113},"what-is-vendor-risk-management","What is vendor risk management?",[116,117,118,122],"p",{},[119,120,121],"strong",{},"Vendor risk management means identifying the third parties whose failure would affect your operations, assessing their level of control in proportion to that criticality, then tracking the identified risks to closure."," It is not a questionnaire sent once a year: it is a state to maintain, not a file to assemble.",[124,125,126],"key-takeaways",{},[127,128,129,133,136,139],"ul",{},[130,131,132],"li",{},"Criticality derives from the activity supported, not from the contract value.",[130,134,135],{},"Assessment effort must be proportionate: auditing everything means examining nothing.",[130,137,138],{},"An untreated risk must be formally accepted, not left open.",[130,140,141],{},"Periodic, timestamped reassessment is what separates a programme from a snapshot.",[111,143,145],{"id":144},"how-to-prioritise-assessment-effort","How to prioritise assessment effort",[147,148,150],"comparison-table",{"caption":149},"Vendor criticality levels and the assessment depth expected",[151,152,153,172],"table",{},[154,155,156],"thead",{},[157,158,159,163,166,169],"tr",{},[160,161,162],"th",{},"Criticality",[160,164,165],{},"Typical situation",[160,167,168],{},"Assessment depth",[160,170,171],{},"Reassessment",[173,174,175,190,204,218],"tbody",{},[157,176,177,181,184,187],{},[178,179,180],"td",{},"Critical",[178,182,183],{},"Supports an essential activity, no quick alternative",[178,185,186],{},"Full questionnaire, evidence, audit or certification",[178,188,189],{},"Annual and on events",[157,191,192,195,198,201],{},[178,193,194],{},"High",[178,196,197],{},"Access to sensitive data",[178,199,200],{},"Targeted questionnaire, certifications, external scan",[178,202,203],{},"Annual",[157,205,206,209,212,215],{},[178,207,208],{},"Moderate",[178,210,211],{},"Limited access, substitutable activity",[178,213,214],{},"Short questionnaire, external scan",[178,216,217],{},"Every 2 years",[157,219,220,223,226,229],{},[178,221,222],{},"Low",[178,224,225],{},"No access to systems or data",[178,227,228],{},"Minimal documentary check",[178,230,231],{},"At contract review",[111,233,235],{"id":234},"how-cisapp-keeps-this-view-current","How CISAPP keeps this view current",[116,237,238],{},"The risk register is shared between internal compliance and third parties: every risk points to the vendor concerned, the assessment that surfaced it and the remediation plan in progress. Dependency mapping links each third party to the activities it supports, which makes criticality defensible rather than declarative.",[116,240,241,242,246,247,249,250,253],{},"See also the ",[243,244,245],"a",{"href":34},"vendor security score",", the ",[243,248,21],{"href":22}," platform and the ",[243,251,252],{"href":84},"vendor cyber due diligence"," guide.",{"title":255,"searchDepth":256,"depth":256,"links":257},"",2,[258,259,260],{"id":113,"depth":256,"text":114},{"id":144,"depth":256,"text":145},{"id":234,"depth":256,"text":235},[262,263,264],"TPRM","Vendor SPOF","Vendor due diligence","md",[267,269,272,275,278,281],{"q":114,"a":268},"It is the discipline of identifying the third parties whose failure — outage, compromise, non-compliance — would affect your organisation, assessing their level of control in proportion to that criticality, and tracking residual risks in a register until they are treated.",{"q":270,"a":271},"How does CISAPP map vendor risk?","CISAPP links each vendor to your internal activities, to its assessments and to its score, so you see your organisation's real exposure rather than a list of contracts.",{"q":273,"a":274},"How do you determine a vendor's criticality?","By the activity it supports, not the contract value: data access, role in a critical process, availability of an alternative. A cheap provider with no fallback is a [vendor SPOF](\u002Fen\u002Fglossary\u002Fvendor-spof).",{"q":276,"a":277},"Can you prioritise critical vendors?","Yes. The risk register and dependency mapping identify the most critical vendors so assessment effort concentrates there, rather than treating every third party the same way.",{"q":279,"a":280},"How often should a vendor be reassessed?","Frequency follows criticality: annually for critical third parties, less often for others, and off-cycle on events — reported incident, hosting change, acquisition, certificate expiry.",{"q":282,"a":283},"What do you do with a risk a vendor refuses to address?","It must be formally accepted, along with its compensating measures, by a named owner — the traceability of that decision is exactly what an auditor looks for, and what CISAPP retains.",[285,286,287,288],"vendor risk management","supplier risk management","vendor mapping","vendor assessment",{},true,null,"entreprise",[294,295,296],"Risk register","Dependency mapping","Assessment campaigns",[298,299],"tprm-saas","vendor-security-score",{"title":105,"description":27},"vendor-risk-management",[303],{"label":304,"url":305,"publisher":306,"date":307},"ISO\u002FIEC 27001:2022, controls A.5.19 to A.5.23 — supplier relationships","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fsolutions\u002Fvendor-risk-management","Vendor risk management means identifying the third parties whose failure would affect your operations, assessing their security level in proportion to that criticality, then tracking the identified risks to closure. CISAPP connects vendors, internal activities, assessments and the risk register in one repository.","2026-08-16","K4iFDuLU3ps9xpq6NNNcXW91bzXfIZM6TurXypThtaQ",1791391139079]