Guide

Vendor Risk Assessment: A Practical Walkthrough

How to run a vendor risk assessment without a procurement team: which suppliers to assess, what to ask them, how to score the answers, and what to do when a critical vendor scores badly.

By SecureBusinessHub Editorial, International cybersecurity desk — · 8 min read

A vendor risk assessment is the process of working out how much damage a supplier could do to your business if their security failed, and then deciding what to do about it. For a large company that means a procurement function, a questionnaire platform and a team of analysts. For a business with ten or thirty people it means an afternoon, a spreadsheet, and a short list of honest questions sent to the handful of suppliers who actually hold your data or have access to your systems. This guide walks through how to do the smaller version properly.

Third-party security has become something small businesses get asked about as well as something they need to do. If your customers are sending you supplier questionnaires, the reason is usually explained in our guide to what the NIS2 directive is, which names supply chain security as an explicit obligation for the organisations it covers. This article is the other side of that: assessing your own suppliers.

Why this matters more than it used to

Almost nothing a small business runs on is built in-house any more. Email, file storage, accounting, payroll, the CRM, the booking system, the website, the backup service: each one is a company you do not control, holding data you are responsible for, usually with a standing connection into your systems. Your security is genuinely the sum of theirs, and an attacker who cannot get into your network directly may find it much easier to get in through a supplier who already has legitimate access.

There is a responsibility angle too. Under most data protection regimes, handing personal data to a processor does not hand over your accountability for it. If your payroll provider leaks your employees' records, your employees, and quite possibly a regulator, will be asking you what checks you did before you chose them. Being able to show that you asked reasonable questions and acted on the answers is a materially better position than having nothing to point at.

Deciding which vendors to assess

The single biggest mistake here is trying to assess everyone. A business with thirty suppliers on the books does not need thirty assessments, because most of those suppliers cannot hurt it. The coffee delivery does not hold customer records. Start by listing every supplier that holds your data, has login access to your systems, or would stop you operating if they went down for a week, and assess only those. For most small businesses that list is between five and fifteen names.

Then sort that list into rough tiers, because a critical vendor deserves more scrutiny than a minor one. Tiering is what keeps the exercise finishable: it lets you spend real effort on the three suppliers that matter and ask a much shorter set of questions of the rest.

  • Critical: holds sensitive personal or financial data, or an outage stops the business. Payroll, accounting, your main line-of-business system, your hosting provider.
  • Important: holds some business data or has system access, but you could work around a failure for a few days. The CRM, a marketing platform, an IT support contractor.
  • Low: no access to your data or systems, and easily replaced. Most suppliers land here, and a name on the list is all the assessment they need.
  • Record who owns the relationship internally for each one. An assessment nobody owns does not get repeated next year.

What to actually ask

Enterprise questionnaires run to hundreds of questions and mostly go unanswered by small suppliers. A short, pointed set gets far better response rates and tells you nearly as much, because the value is less in the specific answers than in whether the vendor can answer at all. A supplier who replies within a week with clear, specific answers is telling you something real about how they operate. One who cannot say where your data is stored is telling you something too.

  • What data of ours do you hold, and where is it stored geographically?
  • Who at your company can access it, and how is that access controlled and reviewed?
  • Do you enforce multi-factor authentication for staff and for our account?
  • Do you hold a recognised security certification or independent audit report, and can we see it?
  • How do you back up our data, and have you tested restoring it?
  • What is your process if you have a breach, and how quickly will you tell us?
  • Which of your own subprocessors touch our data?
  • How do we get our data back, in a usable format, if we leave?

Send the same questions to everyone in a tier so the answers are comparable, and give a deadline. For critical vendors, ask for evidence rather than assertions where it exists: a certification report, a penetration test summary, a data processing agreement. For the important tier, the answers alone are usually enough.

Scoring without inventing a methodology

Resist the temptation to build a weighted numerical model. A three-level rating per question, applied consistently, is all a business this size needs and is far more likely to be repeated next year. Rate each answer as satisfactory, needs follow-up, or a concern, then give the vendor an overall rating that reflects the worst answers rather than the average, because averaging is how a critical gap gets buried under six good responses.

Write a single sentence of justification next to every rating that is not satisfactory. This is the part people skip, and it is the part that has value twelve months later, when nobody remembers why the hosting provider was flagged amber and the person who ran the assessment has moved on. The register, not the questionnaire, is the actual deliverable of this exercise.

What to do when a vendor scores badly

A poor score is not automatically a reason to leave. Switching payroll providers is disruptive and expensive, and the replacement may be no better. The useful question is whether the gap can be closed, how quickly, and what you can do on your own side in the meantime. Often the practical fix sits with you rather than with them: reducing what data they hold, turning on a security feature they offer but you never enabled, tightening who at your company has an account, or getting a data processing agreement signed that was never in place.

Where the gap is theirs and it matters, put it in writing, ask for a date, and record the answer. If a critical vendor cannot tell you how they would notify you of a breach, and will not commit to finding out, that is a genuine input to your next renewal decision. Keep the standard proportionate: you are not auditing them, you are deciding whether the risk they carry is one your business can live with.

A worked example

A twenty-person recruitment agency lists its suppliers and finds eleven worth assessing, of which three are critical: the applicant tracking system that holds every candidate's CV, the payroll bureau, and the outsourced IT provider with administrator access to every laptop. Eight short questions go out. The applicant tracking vendor responds in two days with a certification report and a clear data location. The payroll bureau takes three weeks and cannot say whether multi-factor authentication is enforced on its side. The IT provider answers well on everything except breach notification, where the answer is that they would "let us know as soon as possible."

Nobody gets fired as a vendor. The agency asks the payroll bureau for a written answer on authentication and gets one within a fortnight once there is a named person chasing it. It agrees a specific notification window with the IT provider and writes it into the next contract renewal. It also finds, while doing the exercise, that four former employees still had accounts on the applicant tracking system, which was entirely its own doing and the single most valuable thing the assessment surfaced. Total effort: about two days spread across a month.

Keeping it alive

An assessment done once is a snapshot of a moment that has already passed. Re-run the critical tier annually and the important tier every couple of years, and trigger an off-cycle review whenever something changes materially: a vendor gets acquired, suffers a publicly reported breach, or starts handling a new category of your data. Add a lightweight version of the questionnaire to your onboarding process for new suppliers, so the assessment happens before the contract is signed rather than a year afterwards, when your leverage is gone.

Where this fits

Vendor risk sits inside the wider compliance picture covered in our guide to NIS2 requirements and GDPR for small business, and it is the practical answer to the supply chain obligation described in what the NIS2 directive is. The attacker's-eye view of the same problem is in third-party and supply chain attacks. If you would rather start from a structured questionnaire and a scoring register than build both from scratch, our editable policy template pack includes a vendor and third-party risk assessment questionnaire and a matching risk register and scoring spreadsheet, written for businesses without a procurement team.

NIS2 requirements: the second regime to know about

Data protection law is not the only European regime a business gets asked about. The NIS2 directive sets baseline cybersecurity and incident-reporting obligations for organisations in a defined list of sectors, and it is the source of most of the security questions that now arrive attached to contracts. The two regimes cover different ground: data protection law governs personal data and what people can ask you to do with it, while the NIS2 requirements govern the security and resilience of network and information systems, whether or not personal data is involved. A single incident can engage both, on separate clocks, to separate authorities.

The directive applies to organisations in its listed sectors that are at least medium-sized, meaning broadly fifty or more employees or turnover and balance sheet above ten million euros. That size rule puts most small businesses outside its direct scope, and the honest answer for a ten-person company is usually that the directive does not regulate it. What the size rule does not do is keep the requirements away, because one of them is supply chain security: organisations inside scope are expected to consider the security practices of their direct suppliers, and the way that expectation shows up in the world is as a questionnaire in your inbox.

The measures the directive names are a reasonable checklist for any business, which is why they are worth knowing even when they do not apply to you directly. They cover risk analysis and written security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, basic cyber hygiene and training including for management, encryption and access control policies, and multi-factor authentication. Reporting is staged and fast for the organisations it covers: an early warning within twenty-four hours of becoming aware of a significant incident, a fuller notification within seventy-two hours, and a final report within one month.

Because the directive is national law in each member state rather than a single rulebook, the details of scope, thresholds and reporting differ by country. For a fuller explanation of the instrument itself, see our guide to what the NIS2 directive is, and for the supplier side of the supply chain obligation, our walkthrough of vendor risk assessment. The reporting clocks that run alongside data protection deadlines are covered in data breach notification requirements.

Frequently asked questions

Does NIS2 apply to a small business?

NIS2 generally applies to organisations in its listed sectors that are at least medium-sized, meaning broadly fifty or more employees or turnover and balance sheet total above ten million euros. Most smaller businesses fall outside its direct scope, unless a member state has specifically designated them or they sit in one of the size-independent categories such as DNS service providers or trust service providers. Being outside scope does not stop the directive reaching you through customers who are inside it.

What is the difference between GDPR and NIS2?

GDPR governs personal data: what you may collect, why you may hold it, and what rights people have over it. NIS2 governs the security and resilience of network and information systems in specific sectors, whether or not personal data is involved. One incident can engage both regimes at once, on separate reporting clocks and to separate authorities.

How long do you have to report a data breach?

Under the European model, a personal data breach is reported to the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of it, and affected individuals are told without undue delay where the risk to them is high. Organisations in scope of NIS2 carry a separate obligation: an early warning within twenty-four hours, a fuller notification within seventy-two hours, and a final report within one month.

Does a small business need a data protection officer?

Under GDPR a data protection officer is required where the organisation is a public authority, where its core activities involve regular and systematic monitoring of people on a large scale, or where its core activities involve large-scale processing of special category or criminal offence data. Most small businesses meet none of those tests and are not required to appoint one, though naming someone internally as the contact for privacy questions is worth doing regardless.

What should a small business do when a client's security questionnaire asks about NIS2?

Answer what you actually do rather than what you think the client wants to hear. The questions usually cover written security policies, incident handling and how fast you would notify them, multi-factor authentication, access control when staff join and leave, backup and recovery arrangements, and which of your own subprocessors touch their data. Gaps are common, and disclosing one with a date for closing it lands far better than an answer that does not survive the follow-up question.

Do these rules reach a business based outside the EU?

They can. GDPR reaches organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour, and other regions have their own regimes with their own triggers. NIS2 obligations follow the sectors and the member states that transpose it, but its supply chain expectations travel through contracts, which is how they reach suppliers anywhere in the world.

Related reading