SLA Performance Tracker

Monitor your vendors' service level agreements. Compare commitments against actual performance and flag issues.

✓ Your data stays in your browser
✓ No signup required
✓ No tracking or data collection

Who this tool is for

This check is for anyone accountable for a vendor relationship that could take the business down if it failed: operations leads managing a hosting or SaaS provider, IT managers with a managed service provider, practice administrators depending on an EHR or practice-management platform, contracts and procurement staff negotiating renewals, and executives who assume "we have an SLA" means "we are protected." It is relevant to a two-vendor nonprofit and to an enterprise with a vendor management office — the questions test governance, not vendor count.

What it measures — and what “in scope” means

The questions establish whether your service level agreements are real instruments or paperwork: whether critical vendors have documented SLAs at all, whether those SLAs cover security metrics (incident notification, patch timelines, breach response) as well as availability, how performance is tracked (not at all, ad hoc, periodic review, or automated monitoring), whether breaches are formally documented, whether vendor performance reviews are conducted on a schedule, and whether there are financial or contractual consequences for missed commitments. The score reflects how much leverage and visibility you actually have. "In scope" means vendors whose failure would materially affect operations, data, or customers — start with the top five.

What your result is not

This tool does not track SLA metrics for you and does not evaluate any specific vendor's performance. It assesses whether your organization has the framework to do so. It is not a replacement for contract review by counsel, and a strong score does not mean your vendors are performing — it means you would know if they were not. Security SLAs also do not substitute for reviewing a vendor's SOC 2 report or running a risk assessment; they are complementary controls.

Frequently asked questions

QWhat should a security SLA include?

Incident notification timelines (hours, not days), vulnerability patching windows by severity, breach response cooperation, right-to-audit or evidence provisions, and data return or deletion at termination.

QOur vendor's SLA has no penalties. Does it matter?

Yes. An SLA without consequences is a statement of intent. Service credits, termination rights, or step-in rights are what give a commitment weight.

QHow does this relate to vendor risk assessment?

Risk assessment tells you how much a vendor's failure would hurt and whether their controls are adequate. SLA governance tells you whether you would know about a failure and what you could do about it. Both belong in a third-party risk program.

QShould we review a vendor's SOC 2 report or their SLA first?

The SOC 2 report tells you whether controls exist and were tested; the SLA tells you what the vendor is contractually obligated to do for you. Review both — the related article explains what to look for in the report.

QDoes the tracker store anything?

No. It runs in your browser and nothing is saved or sent.

Related reading

How to Review a Vendor SOC 2 Report: The 20-Minute Checklist Most Owners SkipWhat CMMC 2.0 Actually Means for Small Contractors

Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.

Need a Deeper Analysis?

This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.

Schedule a Scope Call