Evidence
Assessing suppliers without becoming a questionnaire factory
Both frameworks expect supplier risk to be managed. Sending every vendor the same 200-question form manages nothing and annoys everyone.
Facts checked — 2026-09-11
How should you assess supplier security?
Tier suppliers by exposure: those processing personal or customer data, those with production access, those whose outage stops you delivering, and everyone else. The first three warrant real diligence; the last warrants a record that you considered them.
For the tiers that matter, ask for evidence rather than assertions — a current SOC 2 report or ISO certificate with a scope that actually covers the service you buy, a penetration test summary, a breach notification commitment in the contract. And re-check on a cadence, because a certificate expires and a scope changes.
The bottom line
Check that the certificate scope covers the service you are buying. A valid certificate for a different part of their business answers nothing.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.