Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Supplier Security Review Report Template

Documents the assessment outcome in a form the business owner can act on and an auditor can rely on.

Available soon

Format
Word
Size
59 KB
Length
19 pages
Version
1.0
Updated

What's inside

  • How to use this template
  • The report
  • Worked example — a completed review
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

How to use this template

Use this report to close every supplier security assessment at [[Organisation Name]]. One report covers one supplier and one assessment. It records what was assessed and how, what was found, the risk left and the decision, in a form the business owner can act on and an auditor can rely on. The Supplier Security Assessment Procedure governs it; the rules are in the Third-Party Security Policy.

Part

Who completes it

When

A — Supplier and service

Assessor

When the assessment starts

B — Tier, and why

Assessor, with the business owner

At intake, or when the service changes (Supplier Criticality & Tiering Model)

C — Scope

Assessor

When the questionnaire is sent

D, E, F — Evidence, findings, residual risk

Assessor

When the evidence has been checked

G, H — Decision and sign-off

Business owner [[the manager who buys and relies on the service]], with the assessor

Within [[10]] (Tier 1), [[10]] (Tier 2), [[5]] (Tier 3) working days of the evidence being validated (Supplier Security Assessment Procedure)

I — Next reassessment

Assessor

With the sign-off; entered in the register

Steps

  1. Complete Parts A to C from the supplier's row in the Supplier Security Risk Register, and send the questionnaire set for the tier from the Tiered Supplier Security Questionnaire — never a set above the tier (TP-03).
  2. Check each piece of evidence against the Supplier Due Diligence Evidence Checklist: scope, dates and legal entity (Part D). Anything that fails is a finding.
  3. Write each finding with its severity; the deadline is the report date plus the severity's days (Part E).
  4. Score the residual risk on the P05 scale and read its position against the appetite (Part F). Outside appetite, enter it in the P05 Information Security Risk Register.
  5. Agree the decision and conditions with the business owner, and both sign (Parts G and H).
  6. Update the register: last assessed, evidence validated, residual scores, decision, contract clauses, exit plan, and each finding on the Findings sheet. The next due date follows from the tier (Part I).

Guidance — delete before approval

Keep the field names in step with the columns of the Supplier Security Risk Register, so the register can be updated from this report without retyping.

Attach or link the evidence you reviewed. The report says what was checked; the evidence shows it.

Choosing the decision

The decision follows from the position and the findings. The business owner may choose a stricter one, never a looser one.

Decision

What it means

Use it when

Approve

Residual risk within appetite; no High finding open.

Within appetite, and no High finding open

Approve with conditions

Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register.

Within appetite, but a High finding is open, or Medium findings the owner wants fixed as a condition

Escalate

Residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06).

Outside appetite for third-party dependency: enter it in the P05 register

Reject

Do not contract, or plan exit (TP-11).

The risk cannot be brought within tolerance, or the supplier will not fix a High finding

Finding severity and deadlines

Severity

What it means

Deadline from the report date

High

A gap that could directly cause a significant incident or data loss at this supplier

90 calendar days

Medium

A gap that weakens a control but has other protection around it

180 calendar days

Low

An improvement; tracked to the next assessment

the next assessment

A High finding past its deadline is escalated to the business owner (TP-08) and counted in TPM-03, high findings past deadline (target: zero).

Field guidance

Field

What a good answer looks like

Common reason a report is returned

B1 Tiering

Each criterion answered for the service we buy, not the supplier in general; the override named where it applies.

Tier chosen by instinct, with no criterion shown.

C1 Out of scope

What was not looked at, and who covers it.

Blank — the decision is read as covering everything.

D Evidence

Each item checked for scope, dates and legal entity, with the result.

"Certificate received" — not checked against the service.

E Findings

The gap and the risk it leaves, in a sentence the business owner understands.

Questionnaire question numbers instead of findings.

F1 Reasons

Why each rating, with the findings that drive it.

A score with no reason.

G1 Conditions

Named findings and dates; who follows them up.

"Supplier to improve security".

The report

Guidance — delete before approval

Replace the placeholders when you adopt the template, or leave them as prompts. Keep the tier, severity and decision tables identical to the Supplier Criticality & Tiering Model and the Supplier Security Assessment Procedure.

Part A — Supplier and service

Completed by the assessor from the supplier's row in the Supplier Security Risk Register.

A1 Identification

Report reference

[[SSR-YYYY-nnn]]

Supplier ref

as in the register

[[SUP-nnn]]

Supplier

legal entity we contract with

[[Supplier legal name]]

Business owner

signs the decision (TP-05)

[[Role]]

Assessor

[[Role]]

Contract

[[Contract reference; renewal date]]

Reason for the review

TP-01, TP-09

[[New supplier / renewal / reassessment due / material change / incident or breach at the supplier]]

Report date

the date findings are raised

[[YYYY-MM-DD]]

A2 What we buy and what it touches

Critical services it supports

[[Services, as on the register's Critical Services sheet — or none]]

Data it holds or sees

[[e.g. customer data, personal data, internal only, none]]

Access to our systems

[[e.g. privileged, network, remote support, none]]

Part B — Tier, and why

The tier sets the questionnaire set, the evidence, the contract clauses and how often the supplier is reassessed. The tier must be the highest any criterion reaches, and never below an override's minimum. Use the Supplier Criticality & Tiering Model.

B1 Tiering (TP-02)

TC-1 Service

Tier 1: runs or supports a critical service, or a critical or important function

[[Tier n — the description that fits]]

TC-2 Data

Tier 1: sensitive or personal data at scale, or customer data

[[Tier n — the description that fits]]

TC-3 Access

Tier 1: privileged or network-level access to critical systems

[[Tier n — the description that fits]]

TC-4 Substitutability

Tier 1: could not be replaced within [[3 months]] without harm to a critical service

[[Tier n — the description that fits]]

Override

where one applies

[[None / an ICT service supporting a critical or important function of a DORA financial entity: at least Tier 1 / a processor of personal data under GDPR Article 28: at least Tier 2]]

Tier

[[Tier n Name]]

Set by

[[Criteria that reached it, or the override]]

Part C — Scope of the assessment

Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. Say what was and was not looked at, so the decision is not read as covering more than it does.

C1 Scope (TP-03)

Questionnaire set

[[Set A / B / C / D]]

Sent / returned

[[YYYY-MM-DD / YYYY-MM-DD]]

Evidence the tier requires

[[From the tier: see the Supplier Due Diligence Evidence Checklist]]

In scope

[[The service, sites, teams and access assessed]]

Out of scope

and who covers it

[[What was not assessed, and why]]

The supplier's own suppliers

that matter to this service

[[Named sub-contractors or sub-processors, and whether they were covered]]

How the assessment was done

[[Questionnaire, evidence review, call, site visit]]

Part D — Evidence reviewed and how it was validated

Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. One row per item. An item that fails a check is not accepted as evidence; the gap becomes a finding.

Evidence

Date or period

Scope matches the service?

Legal entity matches?

Result

[[e.g. certification, audit report]]

[[Valid to / period covered]]

[[Yes / No — what it covers]]

[[Yes / No]]

[[Validated / Not accepted — why]]

[[e.g. penetration test summary]]

[[Test date]]

[[Yes / No]]

[[Yes / No]]

[[Validated / Not accepted — why]]

[[e.g. continuity test results]]

[[Test date]]

[[Yes / No]]

[[Yes / No]]

[[Validated / Not accepted — why]]

Part E — Findings

Every gap is a finding with an owner and a deadline set by its severity, counted from this report's date (TP-08): High 90 calendar days; Medium 180 calendar days; Low the next assessment. Findings go into the register's Findings sheet.

ID

Finding

Severity

Owner

Deadline

[[F-nn]]

[[What is missing or weak, and the risk it leaves]]

[[High / Medium / Low]]

[[Business owner]]

[[Report date + severity's days]]

[[F-nn]]

[[What is missing or weak, and the risk it leaves]]

[[High / Medium / Low]]

[[Business owner]]

[[Report date + severity's days]]

Part F — Residual risk

Residual supplier risk must be scored on the P05 scale; a supplier outside appetite must be entered in the risk register. Score the risk this supplier still poses with the controls it and we have in place, on the P05 scale, and compare the band with the appetite for third-party dependency.

F1 Score and position (TP-06)

Impact

1 Minor · 2 Moderate · 3 Major · 4 Severe

[[1–4]]

Why this impact

the worst consequence

[[Why this level]]

Likelihood

next 12 months: 1 Unlikely · 2 Possible · 3 Likely · 4 Almost certain

[[1–4]]

Why this likelihood

the findings count here

[[Why this level]]

Residual score

[[I × L = n]]

Band

Low 1–3 · Medium 4–6 · High 8–9 · Critical 12–16

[[Low / Medium / High / Critical]]

Appetite level

RC-05 third-party dependency

[[Level: appetite band, tolerance band]]

Position

[[Within appetite / Outside appetite, within tolerance / Outside tolerance]]

P05 Information Security Risk Register ref

required outside appetite

[[R-nn / not needed]]

Part G — Decision and conditions

Every assessment must end in a documented decision (Approve, Approve with conditions, Escalate, Reject), signed by the business owner. Choose the decision from the table in "How to use this template". Conditions name the findings to be fixed and by when.

G1 Decision (TP-05)

Decision

[[Approve / Approve with conditions / Escalate / Reject]]

Why this decision

[[Residual band, position and open High findings]]

Conditions

findings to fix, and by when

[[F-nn by YYYY-MM-DD; who follows up]]

Contract clauses for the tier in place?

TP-07

[[Yes / No — what is missing, and when it is added]]

Exit plan in place?

TP-11, Tier 1 and 2

[[Yes / No — when it will be written]]

Supplier requirement not met?

if yes, a P02 exception

[[None / exception reference, recorded in the Security Exception Register]]

Part H — Sign-off

The assessor signs for the assessment; the business owner signs for the decision and its conditions. Escalate and Reject also go to the Head of Information Security.

H1 Signatures

Assessor

[[Role]]

Signature and date

[[Signature, date]]

Business owner

TP-05

[[Role]]

Signature and date

[[Signature, date]]

Head of Information Security

Escalate or Reject only

[[Role — or not required]]

Signature and date

[[Signature, date]]

Recorded in the register by

[[Name or role, date]]

Part I — Next reassessment and monitoring

Suppliers must be reassessed within their tier's interval, and on any material change, incident or breach at the supplier.

I1 Next steps (TP-09)

Next reassessment due

report date + the tier's interval

[[YYYY-MM-DD]]

Monitoring until then

by tier

[[From the tier]]

Worked example — a completed review

The review of SUP-004, the ERP software provider (hosted), for a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It is the same supplier and findings as in the Supplier Security Risk Register; the organisation, roles and dates are fictional.

Guidance — delete before approval

Note why the decision is Approve with conditions: the residual score is 6, Medium, and Cautious allows up to Medium, so the supplier is within appetite; but F-01 is High, and no High finding may be open under a plain Approve.

What happened next, as the register shows at 2026-09-30: F-01 passed its deadline on 2026-07-20 and was escalated to the Chief Financial Officer on 2026-07-21 (TP-08); F-02 is due 2026-10-18. A reassessment before 2027-04-21 is needed if the supplier's service or access changes (TP-09).

Delete this worked example from your adopted template.

Part A — Supplier and service

Completed by the assessor from the supplier's row in the Supplier Security Risk Register.

A1 Identification — EXAMPLE

Report reference

SSR-2026-004

Supplier ref

as in the register

SUP-004

Supplier

legal entity we contract with

ERP software provider (hosted)

Business owner

signs the decision (TP-05)

Chief Financial Officer

Assessor

Information Security Manager

Contract

[[Contract reference]]; renews [[YYYY-MM-DD]]

Reason for the review

TP-01, TP-09

First assessment of an existing supplier, before its contract renewal (TP-01, TP-09)

Report date

the date findings are raised

2026-04-21

A2 What we buy and what it touches — EXAMPLE

Critical services it supports

Finance and payroll; Warehouse dispatch

Data it holds or sees

Personal data

Access to our systems

Remote support

Part B — Tier, and why

The tier sets the questionnaire set, the evidence, the contract clauses and how often the supplier is reassessed. The tier must be the highest any criterion reaches, and never below an override's minimum. Use the Supplier Criticality & Tiering Model.

B1 Tiering (TP-02) — EXAMPLE

TC-1 Service

Tier 1: runs or supports a critical service, or a critical or important function

Tier 1 — runs or supports a critical service, or a critical or important function

TC-2 Data

Tier 1: sensitive or personal data at scale, or customer data

Tier 2 — personal data

TC-3 Access

Tier 1: privileged or network-level access to critical systems

Tier 2 — remote user access to our systems

TC-4 Substitutability

Tier 1: could not be replaced within [[3 months]] without harm to a critical service

Tier 1 — could not be replaced within [[3 months]] without harm to a critical service

Override

where one applies

GDPR processor: at least Tier 2 (a processor of personal data under GDPR Article 28)

Tier

Tier 1 Critical

Set by

TC-1, TC-4; the override's minimum (Tier 2) is lower

Part C — Scope of the assessment

Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. Say what was and was not looked at, so the decision is not read as covering more than it does.

C1 Scope (TP-03) — EXAMPLE

Questionnaire set

Set A (about 60 questions)

Sent / returned

2026-03-10 / 2026-04-02

Evidence the tier requires

Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results

In scope

The hosted ERP service (finance, payroll and warehouse modules); the supplier's hosting, operations and support centre; its remote support access to our ERP.

Out of scope

and who covers it

Our own ERP configuration and user administration, which our IT team runs under our own controls.

The supplier's own suppliers

that matter to this service

Hosting in a cloud data centre run by the supplier's own cloud provider (named in the supplier's answers). Covered by the supplier's certification scope.

How the assessment was done

Questionnaire set answered in writing; evidence requested and checked; a 90-minute call with the supplier's security lead on 2026-04-14 to test the answers on remote support and data deletion.

Part D — Evidence reviewed and how it was validated

Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. One row per item. An item that fails a check is not accepted as evidence; the gap becomes a finding.

Evidence

Date or period

Scope matches the service?

Legal entity matches?

Result

Information security certification (ISO/IEC 27001)

Valid to February 2027

Yes — development, hosting and support of the hosted ERP service

Yes — the legal entity we contract with

Validated

Penetration test summary (independent tester)

Tested February 2026

Yes — the hosted ERP application and hosting

Yes

Validated; every High finding fixed and retested by March 2026

Continuity test results

Failover test January 2026

Yes — failover between the ERP data centres

Yes

Validated; results shared with us

Questionnaire set answers

Returned 2026-04-02

—

Yes — signed for the contracting entity by its security lead

Reviewed; two gaps, raised as F-01 and F-02

Data processing terms in the contract (GDPR Art 28(3))

Contract signed [[YYYY-MM-DD]]

Yes — covers the personal data in the ERP

Yes

Present; no evidence that deletion at contract end is carried out (F-02)

Part E — Findings

Every gap is a finding with an owner and a deadline set by its severity, counted from this report's date (TP-08): High 90 calendar days; Medium 180 calendar days; Low the next assessment. Findings go into the register's Findings sheet.

ID

Finding

Severity

Owner

Deadline

F-01

Support staff reach our ERP without multi-factor authentication

High

Chief Financial Officer

2026-07-20

F-02

No evidence that our data is deleted at contract end

Medium

Chief Financial Officer

2026-10-18

Part F — Residual risk

Residual supplier risk must be scored on the P05 scale; a supplier outside appetite must be entered in the risk register. Score the risk this supplier still poses with the controls it and we have in place, on the P05 scale, and compare the band with the appetite for third-party dependency.

F1 Score and position (TP-06) — EXAMPLE

Impact

1 Minor · 2 Moderate · 3 Major · 4 Severe

3 Major

Why this impact

the worst consequence

Finance and payroll and warehouse dispatch both depend on the ERP, which holds personal data (staff pay and bank details, supplier contacts) with our order and stock records: a compromise could stop both services for days and be a notifiable breach.

Likelihood

next 12 months: 1 Unlikely · 2 Possible · 3 Likely · 4 Almost certain

2 Possible

Why this likelihood

the findings count here

Strong, certified controls and a penetration test in February 2026 with every High finding fixed; but the provider's support staff reach our ERP without multi-factor authentication (F-01), a known route for attackers.

Residual score

3 × 2 = 6

Band

Low 1–3 · Medium 4–6 · High 8–9 · Critical 12–16

Medium

Appetite level

RC-05 third-party dependency

Cautious: appetite Medium, tolerance High

Position

Within appetite

P05 Information Security Risk Register ref

required outside appetite

Not needed (within appetite)

Part G — Decision and conditions

Every assessment must end in a documented decision (Approve, Approve with conditions, Escalate, Reject), signed by the business owner. Choose the decision from the table in "How to use this template". Conditions name the findings to be fixed and by when.

G1 Decision (TP-05) — EXAMPLE

Decision

Approve with conditions

Why this decision

Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. Residual Medium is within appetite, but a High finding is open, so the decision cannot be a plain Approve.

Conditions

findings to fix, and by when

F-01 and F-02 fixed by their deadlines. The business owner follows them up; the assessor checks the evidence of each fix. A High finding past its deadline is escalated to the business owner (TP-08).

Contract clauses for the tier in place?

TP-07

Yes — the Tier 1 clauses from the Supplier Contract Security Clause Library

Exit plan in place?

TP-11, Tier 1 and 2

Yes — data return and deletion, access removal and a transition period (TP-11)

Supplier requirement not met?

if yes, a P02 exception

None

Part H — Sign-off

The assessor signs for the assessment; the business owner signs for the decision and its conditions. Escalate and Reject also go to the Head of Information Security.

H1 Signatures — EXAMPLE

Assessor

Information Security Manager (assessor)

Signature and date

Signed, 2026-04-21

Business owner

TP-05

Chief Financial Officer (business owner)

Signature and date

Signed, 2026-04-21

Head of Information Security

Escalate or Reject only

Not required (not Escalate or Reject)

Signature and date

—

Recorded in the register by

Information Security Manager, 2026-04-21

Part I — Next reassessment and monitoring

Suppliers must be reassessed within their tier's interval, and on any material change, incident or breach at the supplier.

I1 Next steps (TP-09) — EXAMPLE

Next reassessment due

report date + the tier's interval

2027-04-21

Monitoring until then

by tier

Continuous: breach news, certificate and report expiry, material changes

Related documents

Document

Relationship

Third-Party Security Policy

The rules this report applies (TP-01 to TP-12)

Supplier Security Assessment Procedure

The procedure that governs this report

Supplier Criticality & Tiering Model

The tiering criteria and overrides in Part B

Tiered Supplier Security Questionnaire

The questionnaire set sent for the tier (Part C)

Supplier Due Diligence Evidence Checklist

What evidence each tier needs and how to validate it (Part D)

Supplier Contract Security Clause Library

The contract clauses for each tier (Part G)

Supplier Security Risk Register

Where the result is recorded: the supplier's row and its findings

Third-Party Risk Dashboard

Reports coverage, overdue reviews, late findings and concentration each quarter

P05 Information Security Risk Register

Where a supplier outside appetite is entered and treated

P02 Security Exception & Waiver Standard

The route when a supplier requirement is not met

Adapting this template

Guidance — delete before approval

Small organisation: for Tier 3 and Tier 4 suppliers, Parts A, B, G and H are enough. Where the assessor is also the business owner — common when one person runs IT and buys the services — ask a second manager to countersign the decision, so nobody approves their own supplier alone.

Regulated entity (NIS2, DORA, GDPR): NIS2 Article 21(3) expects each direct supplier's vulnerabilities and the quality of its products and security practices to be taken into account; Parts D to F are that record. For a DORA financial entity, a supplier of ICT services supporting a critical or important function is Tier 1 by override; keep the report with the register of information (Art 28(3)) and check the contract content required by Art 30. Where the supplier processes personal data for you, GDPR Article 28(1) allows only processors with sufficient guarantees: Part D is where you show you checked them, and the Data Protection Officer [[where one is appointed]] should see the report.

IT run by a service provider: the provider is assessed with this report like any Tier 1 supplier. Ask it to name the suppliers it relies on for your service (Part C) and to report changes to them as a material change (TP-09).

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR).

Framework

Reference

Supported by

ISO/IEC 27001:2022

Annex A 5.19 — Information security in supplier relationships

Parts B and G: security requirements set by tier and agreed with the supplier, recorded with the decision

ISO/IEC 27001:2022

Annex A 5.22 — Monitoring, review and change management of supplier services

Parts D, E and I: supplier security reviewed against evidence, findings tracked and the next review set

NIST CSF 2.0

GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship”

Parts E to G: supplier risk assessed, recorded, prioritised and responded to

NIST CSF 2.0

GV.SC-06 — “Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships”

Parts C and D: due diligence before contracting or renewal

NIS2 — Directive (EU) 2022/2555

Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development

Parts D to F: the supplier's vulnerabilities and security practices taken into account

GDPR — Regulation (EU) 2016/679

Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures

Part D: evidence that a processor provides sufficient guarantees

Definitions

Term

Meaning in this report

Assessor

The person who runs the assessment and signs Part H: [[e.g. Information Security Manager]].

Business owner

[[the manager who buys and relies on the service]]. Signs the decision (TP-05) and receives escalated findings (TP-08).

Evidence validated

Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy.

Finding

A gap between what the supplier does and what its tier requires, with a severity, an owner and a deadline.

Position

Where the residual band stands against the appetite for third-party dependency: Within appetite; Outside appetite, within tolerance; Outside tolerance.

Residual risk

The risk the supplier still poses with the controls in place, scored impact × likelihood on the P05 scale (bands Low 1–3 · Medium 4–6 · High 8–9 · Critical 12–16).

Tier

Tier 1 Critical, Tier 2 Important, Tier 3 Standard, Tier 4 Minimal. The tier must be the highest any criterion reaches, and never below an override's minimum.

TP-nn, TPM-nn

Rule and measure numbers in the Third-Party Security Policy.