Free Tool

Vendor Security Risk Assessment Template
twenty sections for tiering, controls, evidence, residual scoring, and a defensible sign-off

A free, copy-ready vendor security risk assessment template for internal security, AppSec, vulnerability management, GRC, cloud security, and security operations teams running a third-party supplier review. Twenty structured sections covering cover and document control, engagement scope and context, vendor tiering decision, governance and security organisation, data handling and data protection, network and infrastructure security, application and product security, identity and access management, vulnerability and patch management, logging and security operations, incident response and breach notification, business continuity and operational resilience, product-level controls the buyer can configure, supply chain and fourth-party risk, privacy and data protection, compliance and certifications, contractual security clauses and exit, evidence pack and verification, findings ledger with residual risk scoring, and decision, sign-off, and reassessment trigger. Aligned with ISO/IEC 27001 Annex A 5.19 to A 5.22, NIST SP 800-53 SA-12 and SR controls, NIST SP 800-161, SOC 2 CC9.2, PCI DSS Requirement 12.8, HIPAA 164.308(b), NIS2 Article 21, and DORA Articles 28 to 30.

No credit card required. Free plan available forever.

Loading tool...

Score the vendor against the live record, not against a side spreadsheet

SecPortal carries vendor assessments on a workspace engagement record so the completed template, the evidence, the scored findings, the residual ratings, and the sign-off live on one record the audit can read. Free plan available.

No credit card required. Free plan available forever.