Glossary
What is a vendor security assessment?
A vendor security assessment is the process a company uses to evaluate the security and privacy risk of a third-party vendor — typically before signing a contract and periodically afterward. It usually combines a security questionnaire, a review of compliance reports and certifications, and sometimes evidence requests or a call, and it feeds the buyer’s third-party risk management (TPRM) program.
What it involves
A typical assessment gathers a questionnaire response (often a SIG or CAIQ), supporting evidence such as a SOC 2 report or ISO 27001 certificate, and documentation of policies and controls. The buyer’s risk team scores the results and decides whether the vendor meets its bar.
The vendor’s side
For the vendor being assessed, the assessment is inbound work: answering the questionnaire accurately, attaching the right evidence, and doing it fast enough not to stall the deal. Answers that cite live evidence and carry a confidence signal make the review defensible when a buyer pushes back.