Supplier due diligence should establish what the supplier or product does, which business process and data it can affect, how critical the dependency is, what is known about ownership and provenance, which foundational cyber practices are evidenced, how resilient the service appears, what sub-tier dependencies matter, and which unresolved risks require treatment before onboarding or renewal.
External reference
Final July 2026. NIST identifies due-diligence assessment components including foreign ownership/control/influence, provenance, resilience, foundational cyber practices and supply-chain tiers for ICT suppliers.
Primary source →Practical workflow
Define the dependency
Record the service, product, business owner, systems, data, integrations and operational dependency that create the third-party risk context.
Research the supplier
Collect available information on ownership, provenance, service history, security practices, resilience and material supply-chain dependencies.
Request evidence
Use questionnaires and evidence requests proportionate to criticality rather than treating an unanswered checklist as equivalent to assurance.
Record gaps and decisions
Separate confirmed evidence from representations, unknowns and exceptions; assign owners and treatment decisions to material gaps.
Set review conditions
Define renewal, incident, material-change and periodic review triggers so due diligence does not become a one-time onboarding artefact.
Relevant Cybatar sources
Claim boundary
A completed questionnaire or due-diligence review does not prove a supplier is secure. Cybatar can structure vendor, questionnaire, evidence and finding records, but the organisation must determine scope, evidence quality, acceptance criteria and required specialist or legal review.
These pages are Cybatar-authored third-party cyber risk and resilience guidance. NIST publications are used as external references. The mappings are not NIST validations, certifications, endorsements, legal opinions or statements that a supplier or deployment is secure.