Skip to content
SecuriFii

Evidence

Assessing suppliers without becoming a questionnaire factory

Both frameworks expect supplier risk to be managed. Sending every vendor the same 200-question form manages nothing and annoys everyone.

Facts checked2026-09-11

How should you assess supplier security?

Tier suppliers by exposure: those processing personal or customer data, those with production access, those whose outage stops you delivering, and everyone else. The first three warrant real diligence; the last warrants a record that you considered them.

For the tiers that matter, ask for evidence rather than assertions — a current SOC 2 report or ISO certificate with a scope that actually covers the service you buy, a penetration test summary, a breach notification commitment in the contract. And re-check on a cadence, because a certificate expires and a scope changes.

The bottom line

Check that the certificate scope covers the service you are buying. A valid certificate for a different part of their business answers nothing.

Related insights