Cybatar Security Hub
Third-Party Cyber Risk / Vendor offboarding
Third-party cyber risk guide

Secure Vendor Offboarding & Exit Readiness

What should cybersecurity teams verify when a vendor relationship ends?

Direct answer

Verify that accounts, API keys, tokens, certificates, remote access and integrations are revoked or transferred; required data is returned, migrated or disposed of under the applicable agreement; assets and dependencies are updated; unresolved findings and incidents are closed or transferred; and evidence of the exit decision is retained.

External reference

National Institute of Standards and Technology (NIST) — SP 800-18 Rev. 2 — Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

Final June 2026. NIST broadens system planning to security, privacy and cybersecurity supply-chain risk management plans and addresses system environments, components, data flows, responsibilities and risk-management decisions.

Primary source →

Practical workflow

Step 1

Inventory what must end or transfer

Identify accounts, privileged access, integrations, keys, certificates, hosted data, support paths and business dependencies.

Step 2

Revoke and verify access

Disable or transfer credentials and integrations and retain evidence that the change actually took effect.

Step 3

Resolve data obligations

Handle return, migration, retention or disposal according to contract, policy and applicable legal/privacy requirements.

Step 4

Close assurance records

Resolve or transfer open findings, incidents, exceptions, evidence requests and remediation commitments.

Step 5

Validate continuity

Confirm the replacement service, internal process or planned shutdown can support the business dependency without creating a new unmanaged risk.

Relevant Cybatar sources

Claim boundary

Offboarding evidence supports process assurance but does not prove that a supplier deleted every copy of data or revoked every internal capability unless independently verified. Contractual and legal requirements remain organisation-specific.

These pages are Cybatar-authored third-party cyber risk and resilience guidance. NIST publications are used as external references. The mappings are not NIST validations, certifications, endorsements, legal opinions or statements that a supplier or deployment is secure.

Evidence