ISO 27001 Maturity Assessment
Extend Annex A supplier controls with comprehensive ISMS assessment.
Learn moreEvaluate third-party and supply chain cybersecurity risks with a comprehensive vendor assessment framework.
The Third-Party & Supply Chain Security Assessment provides a comprehensive framework for evaluating your organisation's management of vendor and supply chain cybersecurity risks. With 96 questions across 8 domains, this assessment covers the full vendor lifecycle from due diligence through to exit management.
Through structured evaluation criteria aligned to TPRM best practices and regulatory expectations, you will assess your organisation's governance, vendor risk classification, onboarding controls, contractual requirements, ongoing monitoring, incident management, concentration risk, and offboarding processes.
The assessment employs a maturity-based scoring model to help you understand your current TPRM posture, identify programme gaps, and develop a prioritised remediation roadmap for enhanced supply chain security.
This assessment is designed for:
Organisations using this assessment typically gain:
The assessment comprehensively evaluates TPRM across 8 domains:
Watch a walkthrough of the Third-Party & Supply Chain Security Assessment to see how it identifies programme gaps, scores maturity across vendor lifecycle domains, and generates prioritised remediation actions.
Board-ready overview with maturity scores by TPRM domain, exportable to Word format.
Comprehensive findings mapped to vendor lifecycle stages with risk ratings, exportable to Excel.
Charts showing domain-by-domain programme maturity for Board presentations.
Actionable recommendations ranked by risk for TPRM programme improvement.
Get immediate access to the Third-Party & Supply Chain Security Assessment Tool.
Launch special — ends 30 June 2026
Buy NowComplement TPRM with broader security assessments.
Extend Annex A supplier controls with comprehensive ISMS assessment.
Learn moreComplement TPRM with broader cybersecurity programme evaluation.
Learn moreHave questions about how our assessments work?
Read the Enterprise Assessment FAQ →