Free Tool
Vendor Risk Assessment
Evaluate a vendor's security practices across key domains. Get a risk tier classification and action recommendations.
This tool provides general guidance based on the information you provide. It is an initial starting point, not a substitute for professional assessment. Every organization's environment is unique — results should be reviewed with a qualified advisor before making compliance or security decisions.
Who this tool is for
This assessment is for the moment before a vendor gets access to your data or your systems — and for the renewal nobody has re-examined in three years. It is written for founders and executive directors approving a new SaaS platform, procurement and contracts staff who need a defensible record of due diligence, compliance managers building third-party risk evidence for SOC 2, HIPAA, or CMMC, IT leaders onboarding a managed service provider, and vendor management teams at larger organizations who want a consistent screening baseline. It applies to any vendor that stores, processes, or can reach your data, from a payroll provider to a cloud platform.
What it measures — and what “in scope” means
The questionnaire covers the six areas that most often determine whether a vendor incident becomes your incident: whether the vendor holds a current SOC 2 Type II, a Type I only, another certification such as ISO 27001, or nothing; whether data is encrypted at rest and in transit and whether both are confirmed rather than assumed; how the vendor controls access (password-only, MFA with basic management, or MFA with least privilege and periodic review); whether the vendor has a documented incident response plan; whether the vendor carries cyber insurance; and how data retention and deletion are handled. Answers combine into a risk tier — low, moderate, or high — with recommended actions for each tier: what to require in the contract, what evidence to collect, and how often to reassess. "In scope" means the specific vendor and service you are evaluating; assess each critical vendor separately.
What your result is not
The tier is a screening result based on what the vendor told you or what you could verify, not an independent audit of the vendor's controls. It does not read the vendor's SOC 2 report, negotiate the contract, or monitor performance after signing. A low-risk tier does not mean zero risk; it means the vendor showed the expected baseline. For vendors that handle regulated data or sit in critical operations, pair this with a full review of the SOC 2 report and a security SLA.
Frequently asked questions
QWhich vendors need a risk assessment?
Any vendor with access to sensitive data, production systems, or critical operations. Prioritize by impact: if this vendor failed or was breached tomorrow, what would happen to you?
QA vendor says they are SOC 2 compliant but will not share the report. What now?
Treat the claim as unverified. Ask for the report under NDA; most legitimate vendors provide it. If they refuse, that is itself a finding.
QIs ISO 27001 equivalent to SOC 2?
They overlap substantially. ISO 27001 certifies a management system; SOC 2 attests to specific controls over a period. Either is meaningful evidence; neither guarantees the specific service you buy is in scope.
QHow often should vendors be reassessed?
Annually for critical vendors, and whenever there is a material change — new data types, a breach, an acquisition, or a scope change. Many frameworks expect at least annual review.
QDo I need to assess vendors for CMMC?
Yes, if they handle controlled unclassified information on your behalf. NIST SP 800-171 requirements flow down, and you are responsible for confirming your subcontractors and service providers meet them.
QIs my vendor information stored?
No. The assessment runs entirely in your browser.
Related reading
Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.
Need a Deeper Analysis?
This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.
Schedule a Scope Call