You probably have a good understanding of your own systems and processes. But how well do you really know your vendors’ security practices?
For most compliance and security professionals, the answer is ‘not well enough’. That is a problem. Supply chain risk is no longer a theoretical concern — it has become an urgent regulatory priority.
NIS2 has made supply chain security a clear regulatory priority across the EU. Organisations within its scope must assess and manage the security risks associated with their vendors and service providers. But the effects extend well beyond the organisations directly covered by the legislation.
Many smaller companies encounter the requirements indirectly because their customers are required to comply. When banks, municipalities or energy companies need to document their third-party risks, they pass those requirements on to their vendors.
The result? A growing number of SMEs are receiving extensive security questionnaires from large customers — often without having an established process for handling them.
DNV’s 2026 research on cyber resilience in the Nordic region underlines how deeply interconnected critical infrastructure has become. Organisations depend on complex networks of vendors, service providers and digital systems, which means that a security incident affecting one organisation can have consequences throughout the wider supply chain.
Establish a consistent structure
Make vendor assessments a regular routine rather than an emergency exercise.
→ Download the guide to risk management based on ISO 27005
The biggest mistake in third-party risk management is attempting to assess every vendor at the same level of detail from day one. This quickly results in cumbersome spreadsheets containing hundreds of rows but very little meaningful insight.
Instead, begin by identifying the vendors that pose a genuine risk. These will typically include vendors that:
Once you have identified this critical group, carry out a thorough assessment of those vendors. The remainder can be screened using a lighter assessment. This creates a sustainable process that your organisation can realistically maintain.
A vendor assessment is not simply about collecting certificates and ticking boxes. Both NIS2 and good information security practice point to four key areas:
A common mistake is treating vendor assessments as a one-off project. The risk landscape changes continuously as new systems, subcontractors and threats emerge. An assessment completed a year ago does not necessarily reflect the vendor’s security today.
Instead, build a regular cycle into your risk management process:
This is also where inherited risk becomes important. Your own system may appear low-risk on paper. But if the vendor behind it has a poor incident history, you inherit that exposure and need to respond accordingly.
Whether you are preparing for a NIS2 audit, ISO 27001 certification or an assessment by a major customer, the decisive question is always the same: ‘Can you provide evidence?’
You need to be able to demonstrate when the assessment took place, who carried it out, the reasoning behind it, and the conclusion reached.
If the documentation is scattered across emails, local drives and spreadsheets, preparing for an audit quickly becomes a stressful exercise.
Third-party risk does not exist in isolation. It is an integral part of your organisation’s overall risk management.
When vendor assessments feed directly into your risk scoring and compliance activities, you gain an accurate view of the organisation’s actual vulnerabilities. You also avoid reinventing the process whenever you onboard a new vendor.
NorthGRC brings contracts, data processing agreements, questionnaires and incident histories together in one place. Vendor responses can automatically update your overall risk assessment. This enables you to meet NIS2 supply chain security requirements while making audit-ready documentation a natural part of day-to-day operations.