How do I do a vendor security assessment?
A vendor security assessment checks whether a third party protects the data you would share with it. Tier the vendor by the data and access it needs, gather evidence (a SOC 2 report, an ISO 27001 certificate, or a completed security questionnaire), review the gaps, record a risk rating with an owner and a decision, and set a re-assessment date so it happens on a cadence.
Step by step
- Tier by data access. Rank the vendor by the sensitivity of the data and the access it needs. A tool with access to customer data warrants far more scrutiny than one with none.
- Request evidence. Ask for a current SOC 2 Type II report or ISO 27001 certificate; if there is none, send a security questionnaire and ask for supporting documents.
- Review controls and gaps. Check access control, encryption, incident response, and business continuity, and note where the vendor falls short of what the data requires.
- Record a risk decision and owner. Assign a risk rating, decide to accept, mitigate, or avoid, and give the vendor an accountable owner.
- Set a review cadence. Schedule a re-assessment (at least annually for important vendors, and after any material change or incident).
Prioritize by data access, not spend
A small, inexpensive tool with access to customer records can carry more risk than a costly vendor that never touches sensitive data. Tier your effort accordingly.
What evidence to accept
A current SOC 2 Type II report or ISO 27001 certificate is the strongest evidence. Absent that, a completed questionnaire plus artifacts (policies, a recent penetration test summary) is the fallback.
Make it a cadence, not a one-off
Vendor risk changes over time. Track review dates and reassess on a schedule so your inventory stays current between audits.
FAQ
What evidence should I ask for?
A current SOC 2 Type II report or an ISO 27001 certificate is strongest. Otherwise, a completed security questionnaire plus supporting documents.
How often should I reassess a vendor?
At least annually for important vendors, and sooner after a material change (new data access, an acquisition) or a security incident.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free