Verify that accounts, API keys, tokens, certificates, remote access and integrations are revoked or transferred; required data is returned, migrated or disposed of under the applicable agreement; assets and dependencies are updated; unresolved findings and incidents are closed or transferred; and evidence of the exit decision is retained.
External reference
Final June 2026. NIST broadens system planning to security, privacy and cybersecurity supply-chain risk management plans and addresses system environments, components, data flows, responsibilities and risk-management decisions.
Primary source →Practical workflow
Inventory what must end or transfer
Identify accounts, privileged access, integrations, keys, certificates, hosted data, support paths and business dependencies.
Revoke and verify access
Disable or transfer credentials and integrations and retain evidence that the change actually took effect.
Resolve data obligations
Handle return, migration, retention or disposal according to contract, policy and applicable legal/privacy requirements.
Close assurance records
Resolve or transfer open findings, incidents, exceptions, evidence requests and remediation commitments.
Validate continuity
Confirm the replacement service, internal process or planned shutdown can support the business dependency without creating a new unmanaged risk.
Relevant Cybatar sources
Claim boundary
Offboarding evidence supports process assurance but does not prove that a supplier deleted every copy of data or revoked every internal capability unless independently verified. Contractual and legal requirements remain organisation-specific.
These pages are Cybatar-authored third-party cyber risk and resilience guidance. NIST publications are used as external references. The mappings are not NIST validations, certifications, endorsements, legal opinions or statements that a supplier or deployment is secure.