Score vendors across eight security domains, weight by tier, data access and geography, surface concentration risk and export a NIST 800-161 report.
Third-party compromise is now one of the most reliable routes into an organisation, and the reason is structural: your security programme covers your systems, while your exposure covers everyone your systems trust. This supply chain risk assessor lets you build a vendor inventory, score each supplier through a structured questionnaire, weight that score by tier, data access and geography, and then look at the portfolio as a whole for the concentration risks that individual vendor scores never reveal.
It produces a scored vendor register, a concentration risk analysis, a criticality-versus-risk portfolio quadrant, a prioritised remediation plan, and a PDF report framed against the NIST SP 800-161 process. Everything runs in your browser with no account and no data leaving your device.
Each vendor is rated across the eight areas that most reliably predict whether a supplier will become your incident:
A questionnaire average alone treats a commodity supplier with no data access the same as a critical vendor holding your customer records. The score here corrects for that: the domain average is multiplied by a tier multiplier, a data-access multiplier and a geographic factor, then capped at 10.
| Factor | Effect |
|---|---|
| Tier 1 (direct/critical) | Highest multiplier — failure is immediately felt |
| Tier 2 (important) / Tier 3 (standard) | Moderate to neutral |
| Tier 4 (commodity) | Discounted — replaceable with minimal disruption |
| Data access: none → limited → significant → full | Escalating multiplier; full access to sensitive data is the single largest amplifier |
| Geographic risk: low, medium, high | Uplift for suppliers operating under adversarial nation-state exposure |
Scores of 7.5 and above are Critical, 5.5 to 7.4 High, 3.5 to 5.4 Medium, and below 3.5 Low. Treat the numbers as a consistent way to rank a portfolio, not as an actuarial estimate — the value is in ordering the queue, and the ordering is only as good as the honesty of the questionnaire answers.
A portfolio in which every vendor scores 3.0 can still be dangerously fragile. Concentration risk is the failure mode that per-vendor scoring cannot see, and the tool checks four kinds:
Concentration is also where fourth-party risk bites. Two vendors that look independent to you may sit on the same hosting region, the same identity provider or the same upstream logistics carrier. The questionnaire’s subcontractor domain is the only place that surfaces, which is why a low score there deserves more attention than its weight suggests.
NIST Special Publication 800-161 Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, is the reference the export is framed against. It addresses the risk that products and services contain malicious code, are counterfeit, or carry vulnerabilities introduced by poor development or manufacturing practice, and it prescribes a multilevel approach rather than a single vendor checklist — C-SCRM has to operate at the enterprise level, at the mission and business process level, and at the operational system level, because a decision made in procurement determines what the system owner is later stuck with.
The risk management process it inherits from the wider NIST risk framework has four steps, and the report reports status against each:
Related requirements you may be picking up simultaneously: CMMC Level 2 draws its requirements from NIST SP 800-171 and includes supplier flow-down obligations; SOC 2 addresses vendor and business partner risk under the CC9 criteria; and ISO 28000 covers security management for the supply chain more broadly.
No. Continuous monitoring platforms pull external attack surface data, breach intelligence and certificate telemetry that no questionnaire can produce. This tool is for the structured internal judgement layer: turning what you know about your suppliers into a ranked, defensible portfolio view. Many organisations need both; almost all need this one first.
No, it is an informational aid. Contractual security requirements, flow-down obligations and regulatory supplier duties depend on your agreements and your sector. Have counsel review anything you intend to put into a contract.
Start with everything in Tier 1 and anything with significant or full access to sensitive data, regardless of tier. That is usually 10–30 suppliers for a mid-sized organisation and covers the large majority of realistic exposure. Assessing 400 commodity suppliers first is how vendor risk programmes stall.
Your vendors’ vendors. A payroll provider using an offshore development contractor, a SaaS platform running on a single cloud region, an MSP reselling another firm’s SOC. You cannot assess them directly, so you assess whether your vendor manages them — contractual flow-down, subcontractor inventory, notification on change.
Annually as a baseline, quarterly for Tier 1, and immediately on a trigger event: an acquisition, a publicly disclosed breach, a material service change, or the loss of a certification you relied on. That is the Monitor step, and it is the one most programmes skip.
Then you are managing a risk rather than fixing one. Tighten what you can control: reduce the data they hold, segment their access, add contractual notification and audit rights, build a tested contingency plan, and record the acceptance decision with a named owner and a review date. Documented acceptance is a legitimate outcome; undocumented acceptance is what an incident report calls negligence.
No. All assessment data stays in your browser, and the PDF is generated locally.
For the maturity of the vendor management programme itself rather than the individual suppliers, use the VRM breach-proof scorecard. For software supply chain specifically, generate and review a bill of materials with the SBOM generator. To convert risk rankings into financial terms for a budget discussion, the quantitative risk analysis tool and the risk matrix calculator handle the SLE, ARO and ALE arithmetic.
Supply chain risk assessment evaluates the security posture of vendors, suppliers, and third-party service providers that have access to your organization's data, systems, or infrastructure. As organizations increasingly rely on external services (cloud hosting, SaaS applications, managed security, outsourced development), the security of the supply chain directly impacts organizational risk.
Major breaches including SolarWinds (2020), Kaseya (2021), and MOVEit (2023) demonstrated that attackers increasingly target suppliers to gain access to their downstream customers. A single compromised vendor can expose thousands of organizations simultaneously. Supply chain risk assessment identifies these dependencies and evaluates whether vendors meet security standards commensurate with the access and data they handle.
| Factor | What to Evaluate | Risk Indicators |
|---|---|---|
| Data access | What data does the vendor process or store? | PII, PHI, financial data, intellectual property |
| System access | What systems can the vendor access? | Network access, admin privileges, API integrations |
| Security certifications | What compliance certifications does the vendor hold? | SOC 2, ISO 27001, FedRAMP, HITRUST |
| Incident history | Has the vendor experienced breaches? | Public breach disclosures, SEC filings |
| Financial stability | Is the vendor financially viable? | Revenue trends, funding, customer concentration |
| Geographic risk | Where is data processed and stored? | Data sovereignty, legal jurisdiction, geopolitical risk |
| Dependency depth | How critical is this vendor to operations? | Single point of failure, replacement difficulty |
| Tier | Criteria | Assessment Frequency | Example |
|---|---|---|---|
| Critical | Processes sensitive data, deep system access, hard to replace | Annual full assessment + continuous monitoring | Cloud hosting provider, EHR system |
| High | Accesses internal systems or moderate data | Annual questionnaire + periodic review | SaaS HR platform, payment processor |
| Medium | Limited data access, replaceable | Biennial questionnaire | Marketing analytics tool, office supplies |
| Low | No data access, no system integration | Initial assessment only | Janitorial service, catering |
Supply chain risk management (SCRM) identifies, assesses, and mitigates risks arising from dependencies on external vendors, suppliers, and service providers. Cyber SCRM specifically addresses risks like compromised software updates, hardware tampering, third-party data breaches, and vendor concentration risk.
NIST SP 800-161 "Cybersecurity Supply Chain Risk Management Practices" provides guidance for managing cybersecurity risks in supply chains. It covers risk assessment methodologies, supplier evaluation criteria, contractual requirements, and ongoing monitoring. This tool aligns vendor assessments with 800-161 recommendations.
Supply chain tiers classify suppliers by their distance from your organization: Tier 1 (direct suppliers you contract with), Tier 2 (suppliers to your suppliers), Tier 3 (suppliers to Tier 2), and Tier 4 (raw materials or foundational services). Risk visibility decreases with each tier, making Tier 2+ risks harder to assess.
Concentration risk occurs when multiple critical functions depend on a single vendor or a small group of vendors. If that vendor experiences a breach, outage, or business failure, multiple areas of your operations are affected simultaneously. This tool analyzes your vendor portfolio for concentration risk and recommends diversification.
Vendor risk assessment typically includes: security questionnaires, SOC 2/ISO 27001 certification review, penetration test results, business continuity plans, incident response capabilities, data handling practices, and financial stability. This tool provides a structured questionnaire covering these areas with automated risk scoring.
Vendor Risk Management assessment tool to evaluate third-party security posture, data protection practices, and breach resilience. Assess vendor risk across security controls, compliance, and incident response capabilities.
Create risk matrices and calculate risk scores. Prioritize risks by likelihood and impact. Free privacy-first risk assessment tool.
Compliance readiness assessment for HIPAA, SOC 2, PCI-DSS, ISO 27001, and NIST CSF. Evaluate compliance gaps and get prioritized remediation roadmap.