Free Tool

Vendor Onboarding Security Checklist
twelve sections that turn vendor go-lives from informal sign-offs into a defensible onboarding artefact

A free, copy-ready vendor onboarding security checklist for GRC, vendor risk, AppSec, internal security, vulnerability management, and security operations teams who own the security side of bringing a new third-party SaaS, cloud, or embedded vendor into production. Twelve structured sections covering header and scope, pre-onboarding security review, contract and data processing terms verification, tenant and environment configuration, identity, access, and credential provisioning, integration and API security, data flow, classification, and residency verification, logging, monitoring, and detection enablement, vulnerability and patch posture confirmation, incident response and notification readiness, the four-signature go-live security gate, and the post-go-live verification and reassessment cadence. Aligned with ISO/IEC 27001 Annex A 5.19 through 5.23 and 8.30 supplier and cloud-services controls, ISO/IEC 27036 supplier relationships standard, SOC 2 CC9.2 vendor and business partner management, PCI DSS Requirement 12.8 service providers and 12.9 service provider acknowledgement, HIPAA 164.308(b) and 164.314(a) business associate provisions, NIST SP 800-53 SR family supply-chain risk management and SA-12, NIST SP 800-161 cybersecurity supply chain risk management, NIST CSF 2.0 GV.SC supply chain risk management category, CSA Cloud Controls Matrix STA domain, NIS2 Article 21 supply-chain risk, DORA Articles 28 to 30 ICT third-party risk management, GDPR Article 28 processor obligations, UK PRA SS2/21 outsourcing and third-party risk management, FFIEC outsourcing booklet, and APRA CPS 230 service provider management where in scope.

No credit card required. Free plan available forever.

Loading tool...

Run vendor onboarding on the live workspace, not on a side spreadsheet

SecPortal pairs each new vendor onboarding to a versioned engagement record so the in-scope vendor, the named integration endpoints, the named identity provisioning steps, the named monitoring sources, the named four-signature go-live gate, and the named post-go-live verification cadence live on one workspace with a named-actor activity log. Free plan available.

No credit card required. Free plan available forever.