Checklist · 17 items · Updated July 2026

Vendor Due Diligence Checklist

Trust, then verify. In that order.

Your security posture is bounded by your weakest vendor, and your auditor knows it — vendor management is sampled in every SOC 2 and ISO 27001 audit. This is the review process that scales from a two-person startup to a real TPRM program.

01 Tier before you review

  • Classify the vendor by data access: none / internal data / customer data / production access
  • Classify by criticality: would an outage stop your product or your payroll?
  • Match review depth to tier — a full questionnaire for your cloud provider, a lightweight check for the swag vendor
  • Record the tier and rationale; auditors ask how you decided

02 Collect the evidence

  • Request the SOC 2 Type II report (under NDA) or ISO 27001 certificate — and actually read the exceptions
  • Check the report's period and bridge letter if it's stale
  • Review their sub-processor list and where your data will live
  • Request the pen test summary or letter of attestation
  • For AI vendors: ask how your data is used for training and retention

03 Evaluate what you read

  • Scope check: does the report cover the product you're buying, or a different entity?
  • Exception check: repeated access-review or change-management exceptions are a pattern, not noise
  • Breach history: search public disclosures; ask directly
  • Financial viability for critical vendors — a dead vendor is a data incident

04 Contract and monitor

  • Execute a DPA (and BAA if PHI is involved) before data flows
  • Include security requirements, breach notification timelines, and audit rights in the MSA
  • Set the re-review cadence by tier: annually for critical, on renewal for the rest
  • Track everything in a register: tier, documents, dates, owner — this register IS your audit evidence

The register matters more than the reviews. A modest review process, consistently recorded, passes audits and catches real risk. A rigorous process that lives in someone’s inbox does neither. Our vendor management module exists to be that register — reviews tracked, evidence attached, renewals scheduled.

Don't Want to Run This Yourself?

vCISO Services

Virtual CISO services for startups and scaleups: security strategy, compliance roadmap, enterprise deal support, and board reporting — without the $300K hire.

Book a Call
Frequently Asked
What if a vendor won't share their SOC 2 report?

Common for smaller vendors. Fall back to a completed CAIQ or SIG Lite, their public trust page, and contractual security terms. If a vendor handling customer data offers none of these, that's your answer.

How many vendors should we actually review?

All of them get tiered; only the top tiers get deep review. A typical startup has 5–15 vendors touching customer data or production — that's the population that needs real diligence. Tiering everything else takes minutes each.

Do auditors really test vendor management?

Yes — it's a standard SOC 2 sample: 'show me the review for these three vendors.' A register with dates and documents answers in seconds. A Slack archaeology expedition does not.