[{"data":1,"prerenderedAt":310},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-vendor-security-score":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":35,"entities":262,"extension":265,"faq":266,"keywords":284,"meta":288,"navigation":289,"ogImage":290,"path":34,"persona":291,"publishedAt":290,"regulation":290,"relatedFeatures":292,"relatedPages":295,"seo":298,"shortTitle":33,"slug":299,"sources":300,"stem":306,"tldr":307,"updatedAt":308,"__hash__":309},"solutions_en\u002Fen\u002Fsolutions\u002Fvendor-security-score.md","Vendor Security Score (SecOps Score) | CISAPP","CISAPP",{"type":108,"value":109,"toc":255},"minimark",[110,115,129,148,152,234,237,241,244],[111,112,114],"h2",{"id":113},"what-is-a-vendor-security-score","What is a vendor security score?",[116,117,118,128],"p",{},[119,120,121,122,127],"strong",{},"A ",[123,124,126],"a",{"href":125},"\u002Fen\u002Fglossary\u002Fsecurity-posture-score","posture score"," is a summary rating computed from technical signals observable from the outside, without access to the third party's information system."," CISAPP's SecOps score therefore gives an immediate reading of a vendor's technical maturity — not a self-declaration.",[130,131,132],"key-takeaways",{},[133,134,135,139,142,145],"ul",{},[136,137,138],"li",{},"The score measures what is publicly exposed, not internal practices.",[136,140,141],{},"It is dated and recomputed at every scan, unlike an annual questionnaire.",[136,143,144],{},"It costs the vendor no effort: its main operational advantage.",[136,146,147],{},"A contradiction between score and questionnaire is the most useful signal to investigate.",[111,149,151],{"id":150},"what-the-score-measures","What the score measures",[153,154,156],"comparison-table",{"caption":155},"SecOps score dimensions and what they reveal",[157,158,159,175],"table",{},[160,161,162],"thead",{},[163,164,165,169,172],"tr",{},[166,167,168],"th",{},"Dimension",[166,170,171],{},"Signal observed",[166,173,174],{},"What it indicates",[176,177,178,190,201,212,223],"tbody",{},[163,179,180,184,187],{},[181,182,183],"td",{},"DNS",[181,185,186],{},"Exposed records and configuration",[181,188,189],{},"Domain management hygiene",[163,191,192,195,198],{},[181,193,194],{},"TLS",[181,196,197],{},"Versions, ciphers, certificate validity",[181,199,200],{},"Configuration maintenance",[163,202,203,206,209],{},[181,204,205],{},"Exposure surface",[181,207,208],{},"Publicly reachable services",[181,210,211],{},"Breadth of the attack surface",[163,213,214,217,220],{},[181,215,216],{},"Data breaches",[181,218,219],{},"Presence in known breaches",[181,221,222],{},"Credential exposure",[163,224,225,228,231],{},[181,226,227],{},"HTTP headers",[181,229,230],{},"Security headers present or missing",[181,232,233],{},"Attention paid to web good practice",[116,235,236],{},"History keeps the score's evolution over time, with the findings attached to each scan.",[111,238,240],{"id":239},"a-score-that-serves-both-sides","A score that serves both sides",[116,242,243],{},"On the company side, the score prioritises reviews and reminders on the most exposed vendors. On the vendor side, a score visible from the My exposure workspace becomes a commercial argument with its own customers — it can run a scan and track its improvement before sharing it.",[116,245,246,247,250,251,254],{},"See also the ",[123,248,249],{"href":30},"vendor security questionnaire"," and ",[123,252,253],{"href":26},"vendor risk management",".",{"title":256,"searchDepth":257,"depth":257,"links":258},"",2,[259,260,261],{"id":113,"depth":257,"text":114},{"id":150,"depth":257,"text":151},{"id":239,"depth":257,"text":240},[263,264],"Security posture score","Security questionnaire","md",[267,269,272,275,278,281],{"q":114,"a":268},"It is a summary rating of a third party's security posture, computed from technical signals observable from the outside, without access to its information system. It gives a dated, comparable reading where a questionnaire gives a statement.",{"q":270,"a":271},"How is the SecOps score computed?","The score is a technical composite computed from external scans: DNS configuration, TLS, exposure surface, presence in known data breaches and HTTP security headers. It updates with every new scan.",{"q":273,"a":274},"Does a good score mean a vendor is safe?","No. The score measures what is visible from outside: it says nothing about internal access management, subcontracting or backups. A high score alongside an empty questionnaire is still an unassessed risk.",{"q":276,"a":277},"Does the vendor see its own score?","Yes. The vendor can see its score, its history and the findings from its My exposure workspace, and can run new scans before sharing the score with customers.",{"q":279,"a":280},"How often is the score recomputed?","At every scan, scheduled or triggered manually. That is precisely its advantage over an annual questionnaire: a configuration regression becomes visible between two assessments.",{"q":282,"a":283},"Can a finding be disputed?","Each finding is detailed with the element observed, so the vendor can fix it, document a compensating measure, or explain a false positive directly from its workspace.",[285,33,286,287],"vendor security score","vendor cybersecurity rating","vendor security rating",{},true,null,"both",[33,293,294],"Certifications","Assessment campaigns",[296,297],"vendor-security-questionnaire","vendor-risk-management",{"title":105,"description":35},"vendor-security-score",[301],{"label":302,"url":303,"publisher":304,"date":305},"ISO\u002FIEC 27001:2022, control A.5.22 — monitoring and review of supplier services","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fsolutions\u002Fvendor-security-score","A vendor security score is a rating computed from findings observable from the outside: DNS and TLS configuration, exposure surface, HTTP headers, presence in known data breaches. It does not replace a declarative assessment, but it dates it and sometimes contradicts it — and it costs the vendor no effort.","2026-08-16","4mHuCpiXq2HgTDm6t2WvhoMgyH7C_8N3hBLQ9hkytO8",1791391139231]