ESSENTIAL GUIDANCE · PARTNER GUIDANCE · 12 min read
Part of Expose insights →Vendor security assessments: a practical guide to third-party assurance
A practical guide for MSPs and security teams on supplier tiering, evidence collection, authorised external visibility and proportionate technical assurance.
Organisations depend on an increasingly connected network of technology providers, cloud services, outsourced operations and specialist suppliers. A vendor security assessment is the process of understanding those dependencies, identifying material risks and obtaining proportionate evidence that appropriate security measures are in place.
Need an acronym translated?Open the cyber glossary →What a vendor security assessment is—and is not
It is not a single questionnaire or penetration test. It is also not a packaged Pentesys service: Pentesys does not currently provide a complete supplier-audit, questionnaire-management or vendor-risk-management service. For MSPs, MSSPs and consultancies, supplier assurance can instead form part of a broader customer relationship, combining the partner's governance context with carefully authorised technical evidence from specialist providers.
Start with the business dependency
Begin with what the supplier does for the organisation—not a standard list of security questions. Establish which systems and processes depend on it, what information it can access, whether disruption would affect customers, whether it has privileged access, what regulatory or contractual consequences could follow, how replaceable it is and whether important subcontractors sit behind it.
Tier suppliers according to risk
Apply three to five proportionate tiers using information sensitivity, system access, operational importance, potential impact, substitutability, concentration risk, regulatory obligations and subcontractor reliance. Critical suppliers may justify detailed evidence review, contractual controls, ongoing monitoring and authorised technical assurance. Important suppliers may need targeted questionnaires and periodic reassessment; standard suppliers may need basic due diligence and change-led review. Tiers must be revisited as access, services and risk change.
Ask for evidence, not just assurances
Questionnaires are a starting point. Depending on risk, evidence may include security policies, recognised certifications, Cyber Essentialsi status, recent testing summaries, remediation processes, incident and continuity arrangements, privileged-access controls, data flows, hosting and subcontractor information, contractual measures and closure records. The aim is not the largest evidence pack, but confidence that material gaps have an owner, response and timescale. Evidence must also be refreshed throughout the contract.
Use external visibility carefully
Publicly exposed assets can add context: unknown domains, exposed services, certificate changes or unexpected internet-facing infrastructure may justify a supplier discussion. They do not provide a complete security assessment. Where the customer has authorised the activity, Pentesys Expose can provide passive visibility of suppliers' publicly exposed assets so the partner and customer can identify observable change. Activity must remain passive and within scope; visibility from the internet is not permission for Pentesys, a customer or a partner to scan, probe or test a third party.
Technical testing requires the system owner's permission
A commercial relationship does not automatically grant authority to test a supplier's systems. Pentesys Validate may support technical assurance only where the relevant system owner has explicitly authorised testing in writing. Scope, rules of engagementi, timing, permitted techniques, contacts and reporting must be agreed first. Without that authority, concerns belong in the supplier-management process—not in active technical testing.
How an MSP or consultancy can coordinate the process
A partner can map suppliers and services, agree risk tiers, define requirements, gather evidence, record actions, coordinate customer and supplier discussions, identify where passive visibility could add context, arrange authorised technical assurance and report material risks. Pentesys can complement that work through Expose and, where appropriately authorised, Validate. The partner retains the customer relationship and governance context. This is a potential partner operating model—not a claim that Pentesys provides an end-to-end vendor-risk platform or managed supplier-assurance service.
Avoid common assurance mistakes
Avoid applying one questionnaire to every supplier, accepting completed forms as proof, collecting evidence without reviewing it, relying indefinitely on old certifications, overlooking subcontractors, leaving exceptions without remediation dates, testing without permission, assessing only at onboarding or recording findings without a governance decision. Effective assurance supports a decision to accept, reduce, transfer or avoid risk.
Make assurance an ongoing conversation
Define what evidence must be refreshed, how frequently each tier is reviewed, which changes trigger reassessment, how incidents and significant findings are reported, who owns remediation and risk acceptance, and when specialist or senior review is required. For MSPs, MSSPs and consultancies, this turns supplier assurance from a periodic compliance exercise into a useful part of the customer's continuing risk-management programme.
This guide covers the essentials. Continue into our technical analysis for a firmer position, practical implications and recommended action.
Read “Vulnerability remediation needs an operating model—not another spreadsheet” →



