ISO 27001 Maturity Assessment
Extend Annex A supplier controls with detailed ISMS assessment.
Learn moreEvaluate third-party and supply chain cybersecurity risks with a structured vendor assessment framework.
The Third-Party & Supply Chain Security Assessment provides a structured framework for evaluating your organisation's management of vendor and supply chain cybersecurity risks. With 96 questions across 8 domains, this assessment covers the vendor lifecycle from due diligence through to exit management.
Through structured evaluation criteria aligned to TPRM best practices and regulatory expectations, you will assess your organisation's governance, vendor risk classification, onboarding controls, contractual requirements, ongoing monitoring, incident management, concentration risk, and offboarding processes.
The assessment employs a maturity-based scoring model to help you understand your current TPRM posture, identify programme gaps, and develop a prioritised remediation roadmap for enhanced supply chain security.
This assessment is designed for:
Organisations using this assessment typically gain:
The assessment evaluates TPRM across 8 domains:
Watch a walkthrough of the Third-Party & Supply Chain Security Assessment to see how it identifies programme gaps, scores maturity across vendor lifecycle domains, and generates prioritised remediation actions.
Board-ready overview with maturity scores by TPRM domain, exportable to Word format.
Findings mapped to vendor lifecycle stages with risk ratings, exportable to Excel.
Charts showing domain-by-domain programme maturity for Board presentations.
Actionable recommendations ranked by risk for TPRM programme improvement.
Get in touch to discuss access to the Third-Party & Supply Chain Security Assessment Tool.
Contact for PricingCyberAssure tools are structured self-assessments. They help you evaluate your own readiness, identify gaps, prioritise remediation and prepare for formal assessment. They are not a certification, conformity assessment, audit or legal advice, and CyberAssure is not a notified body, accredited certifier or auditor.
We design our question sets to address the requirements we identify as applicable, and we publish a coverage map showing which provisions each question is drawn from. Because these regimes evolve, and because which requirements apply depends on facts about your own organisation and products, we cannot warrant that a question set addresses every requirement applicable to you. Identifying the full scope of your obligations remains your responsibility.
CyberAssure is not affiliated with, endorsed by, or accredited by any standards, certification or regulatory body.
Complement TPRM with broader security assessments.
Extend Annex A supplier controls with detailed ISMS assessment.
Learn moreComplement TPRM with broader cybersecurity programme evaluation.
Learn moreHave questions about how our assessments work?
Read the Enterprise Assessment FAQ →