Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Supplier Due Diligence Evidence Checklist

Specifies exactly which evidence to request and how to validate it, so assessments rely on proof rather than self-declaration.

Available soon

Format
Excel
Size
68 KB
Length
10 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Evidence Items
  • Supplier Checklist
  • Review Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Tier first. The supplier's tier comes from the Supplier Criticality & Tiering Model (TP-01, TP-02). The Evidence Items sheet shows what each tier asks for, in columns I to L: Tier 1 — independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results; Tier 2 — a certification or independent report, or key policies with evidence they operate; Tier 3 — self-declaration, with evidence sampled; Tier 4 — none beyond the intake answers.
2Before first use, read the Evidence Items sheet and set the [[placeholders]]: the gap after which a bridge letter is needed ([[3 months]]), the number of items sampled at Tier 3 ([[2]]) and the age of a patch report. Add your own items in the empty rows, with an EV-nn ID and a requirement for each tier.
3For each supplier, save a copy of this workbook. On the Review Summary sheet, enter the supplier's details and its tier. Column E of the Supplier Checklist then shows what each item requires at that tier.
4Request the evidence with the questionnaire set for the tier (the Tiered Supplier Security Questionnaire): every Required item; one Either/or item; each 'If it applies' item whose condition is true (answer Yes or No in column F); and any 'To support an answer' or Sampled item you choose (Yes in column F). Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. (TP-03)
5When evidence arrives, set Received (column G) and the date (column H). If the supplier says it does not exist, choose 'Not available'.
6Validate each item (TP-04): evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. Answer the four checks in columns I to L with Yes, No or N/A: the scope matches the service we buy; it is in date; it is issued to the legal entity we contract with; and, for a report or test result, the opinion and the exceptions have been read. Use the Evidence Items sheet's 'How to validate it' and 'Red flags'.
7Set the Result (column M). Pass only when every check is Yes or N/A and the pass criterion is met. Fail: describe the issue (column N) and propose a severity (column O). N/A: give the reason (column N). Record who validated it and when (columns Q and R).
8Evidence not available: follow the item's 'If it is unavailable' column. Either accept an alternative (answer Yes for the alternative item in column F and collect it), or set Fail with a finding.
9Clear every Record status (column S) that is not Complete, Finding proposed, Covered by another item, Not applicable or Not requested. The Review Summary's completeness check must say Complete before the review report is written.
10Take the proposed findings to the Supplier Security Review Report Template, where the residual risk is scored on the P05 scale and the business owner signs the decision (TP-05, TP-06). Enter each finding in the Supplier Security Risk Register, and put its F-nn reference in column P.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

What the tier columns mean. Required: Always requested from a supplier in this tier. Either/or: The tier's independent assurance: one of the items marked Either/or is enough (a certification with a matching scope, or an independent report; at Tier 2, key policies with evidence they operate also count). If it applies: Required whenever the condition in 'Applies when' is true for this supplier. To support an answer: Requested only when a questionnaire answer depends on it, or the assessor doubts an answer. Sampled: Tier 3: the assessor picks [[2]] of the items marked Sampled to check the supplier's self-declaration, choosing the answers that matter most for this supplier. Not requested: Not asked for at this tier. Accept it if the supplier offers it, but do not chase it (TP-03: no supplier is sent more than its tier's set).

Severity of a finding (TP-08), with its deadline in calendar days from the review: High — a gap that could directly cause a significant incident or data loss at this supplier (90 calendar days); Medium — a gap that weakens a control but has other protection around it (180 calendar days); Low — an improvement; tracked to the next assessment.

The EXAMPLE. The workbook opens with SUP-009, the pallet network used by the example organisation, a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It is Tier 1: its evidence arrived on 2026-09-01, at the start of the Supplier Security Assessment Procedure's validation window, and was reviewed on 2026-09-15. One item failed: the portal user list (EV-09) showed accounts shared by depot staff, which became F-03 (Medium, due 2027-03-14). The supplier was approved with conditions.

To clear the example: on the Supplier Checklist delete the contents of column A and columns F to R (not the rows); on the Review Summary replace every yellow cell. Nothing else needs changing.

Tailoring — small organisation: ask for less, check it properly. For most suppliers the questionnaire answers and a certificate whose scope you have actually read are enough; the value is in the four checks, not in the volume of paper. Keep the full Tier 1 list for the few suppliers that run a critical service.

Tailoring — regulated entity: NIS2 Article 21(3) expects you to take account of each direct supplier's vulnerabilities and cybersecurity practices, so keep the penetration test (EV-06) and secure development (EV-08) items for Tier 1. Under DORA Article 28(1) the financial entity stays fully responsible for services it outsources: for an ICT provider supporting a critical or important function (Tier 1 by override), treat EV-03, EV-06 and EV-14 as Required, record the arrangement in the register of information (Article 28(3)) and keep the validated evidence with it. Under GDPR Article 28(1) you may use only processors that give sufficient guarantees: EV-10 and EV-15 are how you show you checked.

Tailoring — IT run by a service provider: if a managed service provider selects or runs suppliers for you, ask it for the evidence of those suppliers too (EV-15), and check it yourself; the provider's assurance of its own suppliers is not a substitute. The decision and the sign-off stay with your business owner (TP-05).

Evidence Items

16 evidence items in 5 areas. Columns I to L say what each tier asks for; the Supplier Checklist reads them. Add your own items in the empty rows.

EV IDAreaEvidenceWhat to requestHow to validate it (TP-04)Pass criterionRed flagsIf it is unavailableTier 1Tier 2Tier 3Tier 4Applies whenQuestions that ask for it (Tiered Supplier Security Questionnaire)
EV-01AssuranceCompleted questionnaire for the supplier's tierThe questionnaire set for the tier (Set A to D of the Tiered Supplier Security Questionnaire), every question answered, signed or sent by a named person who is accountable for the answers.Every question answered; answers are about the service we buy, not the company in general; the sender works for the legal entity we contract with; answers agree with the other evidence received.Every question answered for the service we buy, by an accountable person at the contracting entity.Answers copied from a marketing document; 'Yes' to everything with no detail; answers for a different product or a parent company; unanswered questions.No assessment without it. For a Tier 4 supplier the intake answers are enough. If the supplier refuses, escalate to the business owner: the decision is Reject or Escalate (TP-05).RequiredRequiredRequiredRequiredEvery question (the answers themselves)
EV-02AssuranceSecurity certification with its scope statementThe current certificate (for example ISO/IEC 27001) and its scope statement; for a cloud service, the statement of which controls cover it.Scope names the service, sites and teams we rely on; certificate in date and not suspended; issued to the legal entity we contract with (not only a parent or sister company); issued by a certification body that is itself accredited.In date, issued to our contracting entity, and its scope covers the service we buy.Scope limited to a head office or one product; certificate issued to a different company in the group; expired or expiring before contract signature; issuer not accredited.Accept an independent report (EV-03) instead. At Tier 2, key policies with evidence they operate (EV-05) are also enough. If none of these exists at Tier 1, propose a finding and consider Escalate.Either/orEither/orSampledNot requestedGOV-02, GOV-05, GOV-06, PHY-02
EV-03AssuranceIndependent assurance reportThe latest report by an independent auditor on the controls of the service (for example a service-auditor report on operating effectiveness over a period), with the auditor's opinion, the exceptions found and management's responses.Covers the service we buy; the period ended recently (otherwise ask for a bridge letter, EV-04); addressed to or about the right legal entity; opinion read (unqualified or qualified) and every exception read; the controls it expects us to operate ourselves noted.Covers our service, period recent or bridged, opinion and exceptions read, no unresolved exception that affects us.Qualified opinion; exceptions in access control or change management; a report on the design of controls only, at a single date; our own responsibilities (complementary controls) never passed on to us.Accept a certification with a matching scope (EV-02) instead. If neither exists at Tier 1, propose a finding and consider Escalate.Either/orEither/orNot requestedNot requestedGOV-02, GOV-06, PHY-03
EV-04AssuranceBridge letterA letter signed by the supplier's management saying whether the controls in the EV-03 report have changed, or failed, between the end of its period and today.Covers the whole gap since the report's period ended; signed by a named manager of the right legal entity; any change it declares is read and followed up.Covers the gap to today, signed by the contracting entity, changes followed up.A gap longer than 12 months; a letter that declares no change while the questionnaire describes one; unsigned.Ask when the next report is due and set a reminder. If the gap is more than 12 months, treat EV-03 as out of date and look for other assurance.If it appliesIf it appliesNot requestedNot requestedAn EV-03 report is used and its period ended more than [[3 months]] before the review.None directly: it completes EV-03
EV-05AssuranceKey security policies with evidence they operateThe information security policy and the access control policy, with evidence that they are followed (for example the last access review record or the approval record for the policy).Approved by the supplier's senior management and reviewed in the last 12 months; the evidence shows the policy working, not only written; issued by the contracting entity or applies to it.Current, approved, and at least one record shows it operating.A template with the supplier's name added; no approval or review date; the evidence predates the policy.At Tier 2, use EV-02 or EV-03 instead. At Tier 3, sample another item.To support an answerEither/orSampledNot requestedGOV-03, GOV-05, DAT-02, VUL-05
EV-06TestingPenetration test summaryThe summary of the latest penetration test by an independent tester: date, scope, the tester's organisation, findings by severity and their fix status.Tested within the last 12 months; scope includes the service or application we use; findings rated High or Critical fixed, or with a dated plan; a retest confirms the fixes.Within 12 months, our service in scope, serious findings fixed or on a dated plan.Older than 12 months; a scope that excludes the part we use; a vulnerability scan presented as a penetration test; no fix status.Propose a finding — High where the service faces the internet or holds our data, because untested weaknesses could directly cause an incident — and ask for the date of the next test.RequiredTo support an answerNot requestedNot requestedDAT-06, VUL-04
EV-07TestingVulnerability and patch status reportA recent report from the supplier's vulnerability scanning or patch management: how many systems behind our service are up to date, and the oldest missing security update.Dated within the last [[3 months]]; covers the systems behind our service; the oldest missing update is within the supplier's stated deadline.Recent, covers our service, no security update older than the supplier's stated deadline.Unsupported (end-of-life) systems; critical updates missing for months; a report that covers office laptops only.Ask for a screenshot or an extract instead. If nothing can be shown, rate the patching answers Partly.To support an answerTo support an answerSampledNot requestedVUL-01, VUL-02, VUL-03
EV-08TestingSecure development evidenceFor software the supplier writes and we use: its secure development procedure, and the record for a recent release (review, security testing, approval).The procedure covers security requirements, peer review and security testing before release; the release record shows it was followed; applies to the product we use.Procedure exists and a recent release record shows it was followed.No code review; security testing only once a year; open-source components never checked for known vulnerabilities.Ask for the penetration test summary (EV-06) and rate the development answers on what it shows.To support an answerTo support an answerNot requestedNot requestedDEV-01, DEV-02, DEV-03, DEV-04, DEV-05
EV-09Access and dataAccess control evidence for people who reach our data or systemsThe list of the supplier's accounts that can reach our data or systems (name, role, access level), and the setting or report that shows multi-factor authentication is enforced for them.Every account belongs to a named person or a listed service account; multi-factor authentication enforced by setting, not by habit; the list is current (leavers removed); it covers support and administrator staff.Named accounts only, multi-factor authentication enforced, list current.Shared or generic accounts; support staff excluded from multi-factor authentication; accounts of people who have left.A supplier that cannot show who reaches our data does not control it: propose a finding, High if the access is privileged or reaches personal data at scale.If it appliesTo support an answerSampledNot requestedThe supplier's people or systems can reach our data or systems (tiering criterion TC-3).ACC-02, ACC-03, ACC-04, ACC-05, ACC-06, ACC-07, ACC-08, DEV-04
EV-10Access and dataData processing termsThe data processing agreement or contract schedule that meets GDPR Article 28(3), and the supplier's security measures annex.Signed by the legal entity that processes the data; covers documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits; the security annex matches the questionnaire answers.Signed with the processing entity and covers every Article 28(3) point.The supplier's standard terms that allow it to change sub-processors without notice; no deletion or return clause; signed by a different group company.Do not share personal data until the terms are signed. Involve Legal and the Data Protection Officer.If it appliesIf it appliesNot requestedNot requestedThe supplier processes personal data on our behalf (GDPR Article 28). A processor is at least Tier 2.GOV-07, DAT-04, DAT-07, INC-03, SUB-03
EV-11Access and dataData location and hosting statementWhere our data is stored, processed and supported from (countries and hosting providers), including backups.Names every location, including backups and support; matches the sub-processor list (EV-15) and the contract; any transfer of personal data outside the agreed countries has a legal basis.All locations named, consistent with EV-15 and the contract.'Worldwide' or 'as required'; backups or support in a country the contract does not name; locations that differ from the sub-processor list.Treat the location as unknown: propose a finding if personal data is involved.To support an answerTo support an answerNot requestedNot requestedDAT-03, SUB-05, PHY-01, PHY-02, PHY-03
EV-12Access and dataData return and deletion procedureThe procedure for returning and deleting customer data at contract end, including backups, and an example (anonymised) deletion certificate.States the format for return, the time to delete from live systems and from backups, and the written confirmation given; the example certificate shows it has been done before.Return, deletion from live and backup, and written confirmation all covered.'Data is deleted in line with our retention policy' with no time or confirmation; backups excluded.Propose a finding and add the deletion clause and the exit plan to the contract (TP-11).If it appliesIf it appliesNot requestedNot requestedThe supplier holds our data (TP-11: every Tier 1 and Tier 2 contract has an exit plan).DAT-05, CON-06, PHY-04
EV-13Incidents and continuityIncident contacts and notification commitmentNamed incident contacts reachable at all times for a critical service, the contract term that commits the supplier to tell us about incidents affecting us, and a summary of its incident response plan with the date it was last tested.Contacts named and tested (a test call or email answered); the commitment has a time limit short enough for our own reporting duties; plan tested within 12 months.Contacts named and tested, notification time stated, plan tested within 12 months.A general sales inbox as the only contact; notification 'as soon as practicable' with no limit; no plan test.Add the contacts and the notification clause before signature (TP-07, TP-10).RequiredTo support an answerSampledNot requestedINC-01, INC-02, INC-03, INC-04, INC-06
EV-14Incidents and continuityContinuity and recovery test resultsThe results of the latest continuity or disaster recovery test for the service we use: date, what was tested, the recovery time and data loss achieved, and what failed.Tested within the last 12 months; the test covered our service; the recovery time and data loss achieved meet what we need; failures have fixes.Within 12 months, our service covered, results meet our recovery needs.A plan with no test; a test of the office, not the service; results worse than the contract promises.Propose a finding and plan for the service's failure in our own continuity plan (TP-10).RequiredTo support an answerSampledNot requestedINC-05, CON-03, CON-04, CON-05, CON-07
EV-15Supply chain and peopleSubcontractor and sub-processor listThe companies that handle our data or deliver part of the service, what each does, and where.Complete (hosting, support, software and any partner that touches our data); locations match EV-11; the supplier checks their security; changes notified to us.Complete, locations consistent, the supplier checks each one.A provider we already rely on for other critical services (concentration, TPM-04); unnamed 'partners'; a list that has not changed in years.For a processor, no sub-processor may be used without our authorisation (GDPR Article 28(2)): hold the processing until the list is given.If it appliesIf it appliesSampledNot requestedOther companies handle our data or deliver part of the service, or the supplier processes personal data for us.CON-07, SUB-01, SUB-02, SUB-03, SUB-04, SUB-05, SUB-06
EV-16Supply chain and peopleStaff screening and training summaryA summary of the screening done before staff can reach customer data, and security training completion for those staff in the last 12 months.Screening described for the roles that reach our data; training completion stated for the last 12 months; applies to the staff and subcontractors who deliver our service.Screening described and training completed within 12 months for the staff who reach our data.Screening only for permanent staff when contractors deliver the service; no training records.Accept a statement signed by the supplier's HR lead; rate the people answers Partly if even that is not given.To support an answerTo support an answerSampledNot requestedPPL-01, PPL-02, PPL-03, PPL-04

Supplier Checklist

One supplier's evidence. Column E follows the tier on the Review Summary sheet. Yellow cells are yours. EXAMPLE rows: SUP-009 (Pallet network), reviewed 2026-09-15.

RowEV IDAreaEvidenceRequired at this tierApplies or requestedReceivedDate receivedScope matches the serviceIn dateRight legal entityOpinion and exceptions readResultIssue found, or reason for N/AProposed severityFinding refValidated byDate validatedRecord statusFinding no. (calc)
EXAMPLEEV-01AssuranceCompleted questionnaire for the supplier's tierRequiredYes1 Sep 2026YesYesYesN/APassSet A answered for the pallet network service by its Head of IT.Information Security Manager15 Sep 2026Complete
EXAMPLEEV-02AssuranceSecurity certification with its scope statementEither/orYes1 Sep 2026YesYesYesN/APassCertificate valid to 2027-05; scope covers network operations, the consignment portal and hub IT; issued to the operating company we contract with.Information Security Manager15 Sep 2026Complete
EXAMPLEEV-03AssuranceIndependent assurance reportEither/orNot availableN/ANo independent report: the certificate (EV-02) is accepted instead.Information Security Manager15 Sep 2026Covered by another item
EXAMPLEEV-04AssuranceBridge letterIf it appliesNoNot applicable
EV-05AssuranceKey security policies with evidence they operateTo support an answerNot requested
EXAMPLEEV-06TestingPenetration test summaryRequiredYes1 Sep 2026YesYesYesYesPassTested 2026-03 by an independent tester: portal and hub network in scope; both Medium findings fixed and retested.Information Security Manager15 Sep 2026Complete
EXAMPLEEV-07TestingVulnerability and patch status reportTo support an answerYesYes1 Sep 2026YesYesYesN/APassRequested to support the patching answers. Report dated 2026-08; no security update older than 30 days.Information Security Manager15 Sep 2026Complete
EV-08TestingSecure development evidenceTo support an answerNot requested
EXAMPLEEV-09Access and dataAccess control evidence for people who reach our data or systemsIf it appliesYesYes1 Sep 2026YesYesYesN/AFailThe portal user list shows accounts named after depots, shared by shift staff: access to our customer addresses cannot be traced to a person or removed when one leaves. The portal enforces multi-factor authentication and limits these accounts to consignment look-up.MediumF-03Information Security Manager15 Sep 2026Finding proposed1
EXAMPLEEV-10Access and dataData processing termsIf it appliesYesYes1 Sep 2026YesYesYesN/APassData processing agreement is schedule 4 of the contract; covers every Article 28(3) point.Information Security Manager15 Sep 2026Complete
EV-11Access and dataData location and hosting statementTo support an answerNot requested
EXAMPLEEV-12Access and dataData return and deletion procedureIf it appliesYesYes1 Sep 2026YesYesYesN/APassDeletion from live systems and backups, with a written certificate; an anonymised certificate from another customer was supplied.Information Security Manager15 Sep 2026Complete
EXAMPLEEV-13Incidents and continuityIncident contacts and notification commitmentRequiredYes1 Sep 2026YesYesYesN/APassDuty manager line and named security contact, both tested; notification commitment in the contract; plan exercised 2026-02.Information Security Manager15 Sep 2026Complete
EXAMPLEEV-14Incidents and continuityContinuity and recovery test resultsRequiredYes1 Sep 2026YesYesYesN/APassHub failover test 2026-05: consignment tracking restored within the time the contract promises.Information Security Manager15 Sep 2026Complete
EXAMPLEEV-15Supply chain and peopleSubcontractor and sub-processor listIf it appliesYesYes1 Sep 2026YesYesYesN/APassMember depots and the portal's hosting provider listed, with what each does.Information Security Manager15 Sep 2026Complete
EV-16Supply chain and peopleStaff screening and training summaryTo support an answerNot requested

Review Summary

Review summary and sign-off

The supplier's details drive the checklist. Completeness, the proposed findings and the reassessment date are calculated; the decision and sign-off are yours.

Supplier and review

FieldValueNote
Supplier referenceSUP-009EXAMPLE — replace with your supplier's reference.
Supplier namePallet networkEXAMPLE.
Services it supportsWarehouse dispatchEXAMPLE.
Our data it holdsCustomer addressesEXAMPLE.
Its access to usPortalEXAMPLE.
TierTier 1EXAMPLE. From the Supplier Criticality & Tiering Model. Drives column E of the Supplier Checklist.
Evidence reviewed on15 Sep 2026EXAMPLE date (SUP-009's assessment). Replace it with the date of your review: finding deadlines and the reassessment date count from it.
Assessor[[Name, role]]
Questionnaire setSet A — about 60Calculated: the Tiered Supplier Security Questionnaire set for this tier (TP-03).
Evidence this tier asks forIndependent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test resultsCalculated (TIERS).
Reassess by15 Sep 2027Calculated: the tier's maximum interval from the review date (TP-09); sooner on any material change, incident or breach.

Completeness

MeasureCountIndependent assurance (Either/or)
Items listed16Met: at least one Either/or item has passed.
Complete (passed)9Tier 3 sample
Finding proposed (failed)1Not used at this tier.
Covered by another item1Completeness check
Not applicable1Complete, with 1 finding(s) proposed below.
Not requested at this tier4
Outstanding0

Proposed findings

Evidence itemSeverityEvidenceDeadlineDue dateFinding refIssue found
EV-09MediumAccess control evidence for people who reach our data or systems180 calendar days14 Mar 2027F-03The portal user list shows accounts named after depots, shared by shift staff: access to our customer addresses cannot be traced to a person or removed when one leaves. The portal enforces multi-factor authentication and limits these accounts to consignment look-up.

Deadlines are calendar days from the review date (TP-08). Enter each finding in the Supplier Security Risk Register.

Decision and sign-off

FieldValueNote
Residual risk (P05 scale)EXAMPLE: impact 2 × likelihood 2 = 4 (Medium)Scored in the Supplier Security Review Report Template. Outside appetite: enter it in the P05 risk register (TP-06).
DecisionApprove with conditionsEXAMPLE. Approve / Approve with conditions / Escalate / Reject (TP-05).
ConditionsEXAMPLE: F-03 fixed by 2027-03-14.For Approve with conditions: the findings, with their deadlines.
Business owner[[Name, role]]Signs the decision (TP-05). EXAMPLE: the Head of Logistics.
Business owner's signature date[[YYYY-MM-DD]]
Assessor[[Name, role]]Confirms the evidence was validated as recorded.
Assessor's signature date[[YYYY-MM-DD]]
The decision follows the residual risk and the findings, not the number of items passed. A Tier 1 or Tier 2 supplier also needs its contract clauses (TP-07) and an exit plan (TP-11) before signature.

Lists

TierRequirementYesNoReceivedCheckResultSeveritySeverityDaysSeverityDeadlineDecisionAreaTierSetTierMonthsTierEvidence
Tier 1RequiredYesYesYesPassHigh9090 calendar daysApproveAssuranceSet A — about 6012Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results
Tier 2Either/orNoNot availableNoFailMedium180180 calendar daysApprove with conditionsTestingSet B — about 3524A certification or independent report, or key policies with evidence they operate
Tier 3If it appliesN/AN/ALowNoneNext assessmentEscalateAccess and dataSet C — about 1536Self-declaration, with evidence sampled
Tier 4To support an answerRejectIncidents and continuitySet D — about 5 (intake screening only)NoneNone beyond the intake answers
SampledSupply chain and people

Not requested

Definitions

Definitions

TermMeaning in this workbook
Evidence item (EV-nn)A piece of evidence this checklist defines, with how to validate it. The questionnaire's 'Evidence to request' column names these IDs.
RequiredAlways requested from a supplier in this tier.
Either/orThe tier's independent assurance: one of the items marked Either/or is enough (a certification with a matching scope, or an independent report; at Tier 2, key policies with evidence they operate also count).
If it appliesRequired whenever the condition in 'Applies when' is true for this supplier.
To support an answerRequested only when a questionnaire answer depends on it, or the assessor doubts an answer.
SampledTier 3: the assessor picks [[2]] of the items marked Sampled to check the supplier's self-declaration, choosing the answers that matter most for this supplier.
Not requestedNot asked for at this tier. Accept it if the supplier offers it, but do not chase it (TP-03: no supplier is sent more than its tier's set).
Validation (TP-04)Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy.
Scope statementThe part of a certificate or report that says which services, sites and teams it covers. Evidence counts only for what is in scope.
Legal entityThe company named in the contract. Evidence issued to a parent, sister or subsidiary company may not cover it.
Independent assurance reportA report by an independent auditor on how well a supplier's controls worked over a period, with an opinion and a list of exceptions.
OpinionThe auditor's overall conclusion in an assurance report: unqualified (controls worked as described) or qualified (they did not, in some respect).
ExceptionA test in an assurance report where a control did not work as described.
Bridge letterA letter from the supplier's management covering the time between the end of an assurance report's period and today; needed when the gap is more than [[3 months]].
Complementary controlsControls an assurance report expects the customer to operate for the supplier's controls to work, such as reviewing its own users' access.
Accredited certification bodyA certification company that a national accreditation body has checked is competent to certify.
Record statusColumn S of the Supplier Checklist: what each row still needs. Complete, Finding proposed, Covered by another item, Not applicable and Not requested need nothing more.
High findingA gap that could directly cause a significant incident or data loss at this supplier. Deadline: 90 calendar days from the review.
Medium findingA gap that weakens a control but has other protection around it. Deadline: 180 calendar days from the review.
Low findingAn improvement; tracked to the next assessment. Deadline: tracked to the next assessment.
FindingA shortfall with an owner and a deadline, recorded in the Supplier Security Risk Register as F-nn (TP-08).
Processor, sub-processorUnder GDPR, a company that processes personal data on our behalf; a sub-processor is a company the processor engages to do part of that processing.
EXAMPLEThe example organisation's review of SUP-009 (Pallet network) on the Supplier Checklist and the Review Summary. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.19 — Information security in supplier relationshipsWhole workbook: evidence requested in proportion to the supplier's tier
ISO/IEC 27001:2022Annex A 5.22 — Monitoring, review and change management of supplier servicesEvidence Items (in date, red flags) and the Review Summary's reassessment date
NIST CSF 2.0GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship”Supplier Checklist and Review Summary: supplier risks assessed, recorded and responded to
NIS2 — Directive (EU) 2022/2555Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure developmentEV-06, EV-07 and EV-08: the supplier's vulnerabilities, practices and secure development
DORA — Regulation (EU) 2022/2554Article 28(1) — ICT third-party risk managed as part of ICT risk, proportionately; the financial entity remains fully responsibleTailoring for regulated entities; the financial entity stays responsible for what it outsources
GDPR — Regulation (EU) 2016/679Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measuresEV-10 and EV-15: the processor's sufficient guarantees
GDPR — Regulation (EU) 2016/679Article 28(2) — no sub-processor without the controller's prior written authorisationEV-15
GDPR — Regulation (EU) 2016/679Article 28(3) — a binding contract with the processor, covering documented instructions, confidentiality, security, sub-processors, assistance, return or deletion of data, and auditsEV-10

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)