Cybatar Security Hub
Third-Party Cyber Risk / Supplier due diligence
Third-party cyber risk guide

Cybersecurity Supplier Due Diligence

What should cybersecurity supplier due diligence establish before a vendor is approved?

Direct answer

Supplier due diligence should establish what the supplier or product does, which business process and data it can affect, how critical the dependency is, what is known about ownership and provenance, which foundational cyber practices are evidenced, how resilient the service appears, what sub-tier dependencies matter, and which unresolved risks require treatment before onboarding or renewal.

External reference

National Institute of Standards and Technology (NIST) — SP 1326 — Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide

Final July 2026. NIST identifies due-diligence assessment components including foreign ownership/control/influence, provenance, resilience, foundational cyber practices and supply-chain tiers for ICT suppliers.

Primary source →

Practical workflow

Step 1

Define the dependency

Record the service, product, business owner, systems, data, integrations and operational dependency that create the third-party risk context.

Step 2

Research the supplier

Collect available information on ownership, provenance, service history, security practices, resilience and material supply-chain dependencies.

Step 3

Request evidence

Use questionnaires and evidence requests proportionate to criticality rather than treating an unanswered checklist as equivalent to assurance.

Step 4

Record gaps and decisions

Separate confirmed evidence from representations, unknowns and exceptions; assign owners and treatment decisions to material gaps.

Step 5

Set review conditions

Define renewal, incident, material-change and periodic review triggers so due diligence does not become a one-time onboarding artefact.

Relevant Cybatar sources

Claim boundary

A completed questionnaire or due-diligence review does not prove a supplier is secure. Cybatar can structure vendor, questionnaire, evidence and finding records, but the organisation must determine scope, evidence quality, acceptance criteria and required specialist or legal review.

These pages are Cybatar-authored third-party cyber risk and resilience guidance. NIST publications are used as external references. The mappings are not NIST validations, certifications, endorsements, legal opinions or statements that a supplier or deployment is secure.

Evidence