# Vendor & Third-Party Security Risk Assessment

> From $38K · Compliance & GRC · https://cisomarketplace.services/services/vendor-third-party-risk-assessment

Comprehensive evaluation of your organization's third-party risk management program and vendor security assessment practices. Our assessment examines your vendor security evaluation processes, contractual security requirements, ongoing monitoring capabilities, and supply chain security controls to identify vulnerabilities in your extended enterprise and provide a roadmap for enhanced third-party risk management.

## In scope

- Vendor security assessment methodology review
- Third-party risk tiering evaluation
- Supply chain attack surface analysis
- Vendor security questionnaire assessment
- Third-party contract security requirements
- Vendor access management review
- Vendor incident response coordination
- Continuous monitoring capabilities
- Fourth-party risk visibility
- Cloud service provider security assessment
- Strategic vendor security oversight
- Third-party risk governance

## Deliverables

- Third-party risk program assessment report
- Vendor security framework recommendations
- Risk-based assessment methodology
- Vendor tiering model
- Contract security requirements template
- Continuous monitoring strategy
- Supply chain risk mitigation plan
- Critical vendor management playbook
- Vendor incident response procedures
- Implementation roadmap and timeline

## Tiers

### Essential Third-Party Risk Assessment: $38K

Program review for a vendor inventory of up to 100. Assesses methodology, risk tiering, questionnaires, contract security terms and vendor access management, sampling up to 5 completed vendor assessments. Program assessment report and roadmap.

Limits: vendors 100

Includes:
- TPRM methodology and governance review
- Risk tiering evaluation
- Questionnaire and contract security requirements review
- Sample review of up to 5 completed vendor assessments
- Program assessment report and roadmap

Excludes:
- Building a new assessment methodology or tiering model
- Continuous monitoring strategy
- Assessing individual vendors on the client's behalf
- Fourth-party and supply chain analysis

### Comprehensive Vendor Security Program: $70K

Vendor inventory of up to 500, sampling up to 15 assessments. We build the risk-based assessment methodology, tiering model, contract security requirements template, continuous monitoring strategy, critical vendor playbook and vendor incident response procedures.

Limits: vendors 500

Includes:
- Everything in the program review tier
- Risk-based assessment methodology written
- Vendor tiering model
- Contract security requirements template
- Continuous monitoring strategy and vendor incident procedures

Excludes:
- Custom assessment tooling
- Supply chain risk quantification
- Rollout support and training
- Performing vendor assessments or onsite vendor audits

### Enterprise Supply Chain Security Framework: $110K

Vendor inventory of up to 2,500, sampling up to 30 assessments. Adds supply chain attack surface and fourth-party analysis, risk quantification for the top 25 critical vendors, custom questionnaires and scoring workbooks, and rollout support with the vendor management team.

Limits: vendors 2500

Includes:
- Everything in the advanced tier
- Supply chain and fourth-party risk analysis
- Risk quantification for up to 25 critical vendors
- Custom questionnaires and scoring workbooks
- Implementation support and team training

Excludes:
- Onsite audits of individual vendors
- Operating the vendor assessment queue as a managed service
- TPRM platform licences
- Inventories above 2,500 vendors (scoped separately)

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=vendor-third-party-risk-assessment
