ESSENTIAL GUIDANCE · PARTNER GUIDANCE · 12 min read

Part of Expose insights →

Vendor security assessments: a practical guide to third-party assurance

A practical guide for MSPs and security teams on supplier tiering, evidence collection, authorised external visibility and proportionate technical assurance.

Organisations depend on an increasingly connected network of technology providers, cloud services, outsourced operations and specialist suppliers. A vendor security assessment is the process of understanding those dependencies, identifying material risks and obtaining proportionate evidence that appropriate security measures are in place.

Need an acronym translated?Open the cyber glossary →

What a vendor security assessment is—and is not

It is not a single questionnaire or penetration test. It is also not a packaged Pentesys service: Pentesys does not currently provide a complete supplier-audit, questionnaire-management or vendor-risk-management service. For MSPs, MSSPs and consultancies, supplier assurance can instead form part of a broader customer relationship, combining the partner's governance context with carefully authorised technical evidence from specialist providers.

Start with the business dependency

Begin with what the supplier does for the organisation—not a standard list of security questions. Establish which systems and processes depend on it, what information it can access, whether disruption would affect customers, whether it has privileged access, what regulatory or contractual consequences could follow, how replaceable it is and whether important subcontractors sit behind it.

Tier suppliers according to risk

Apply three to five proportionate tiers using information sensitivity, system access, operational importance, potential impact, substitutability, concentration risk, regulatory obligations and subcontractor reliance. Critical suppliers may justify detailed evidence review, contractual controls, ongoing monitoring and authorised technical assurance. Important suppliers may need targeted questionnaires and periodic reassessment; standard suppliers may need basic due diligence and change-led review. Tiers must be revisited as access, services and risk change.

Ask for evidence, not just assurances

Questionnaires are a starting point. Depending on risk, evidence may include security policies, recognised certifications, Cyber Essentials status, recent testing summaries, remediation processes, incident and continuity arrangements, privileged-access controls, data flows, hosting and subcontractor information, contractual measures and closure records. The aim is not the largest evidence pack, but confidence that material gaps have an owner, response and timescale. Evidence must also be refreshed throughout the contract.

Use external visibility carefully

Publicly exposed assets can add context: unknown domains, exposed services, certificate changes or unexpected internet-facing infrastructure may justify a supplier discussion. They do not provide a complete security assessment. Where the customer has authorised the activity, Pentesys Expose can provide passive visibility of suppliers' publicly exposed assets so the partner and customer can identify observable change. Activity must remain passive and within scope; visibility from the internet is not permission for Pentesys, a customer or a partner to scan, probe or test a third party.

Technical testing requires the system owner's permission

A commercial relationship does not automatically grant authority to test a supplier's systems. Pentesys Validate may support technical assurance only where the relevant system owner has explicitly authorised testing in writing. Scope, rules of engagement, timing, permitted techniques, contacts and reporting must be agreed first. Without that authority, concerns belong in the supplier-management process—not in active technical testing.

How an MSP or consultancy can coordinate the process

A partner can map suppliers and services, agree risk tiers, define requirements, gather evidence, record actions, coordinate customer and supplier discussions, identify where passive visibility could add context, arrange authorised technical assurance and report material risks. Pentesys can complement that work through Expose and, where appropriately authorised, Validate. The partner retains the customer relationship and governance context. This is a potential partner operating model—not a claim that Pentesys provides an end-to-end vendor-risk platform or managed supplier-assurance service.

Avoid common assurance mistakes

Avoid applying one questionnaire to every supplier, accepting completed forms as proof, collecting evidence without reviewing it, relying indefinitely on old certifications, overlooking subcontractors, leaving exceptions without remediation dates, testing without permission, assessing only at onboarding or recording findings without a governance decision. Effective assurance supports a decision to accept, reduce, transfer or avoid risk.

Make assurance an ongoing conversation

Define what evidence must be refreshed, how frequently each tier is reviewed, which changes trigger reassessment, how incidents and significant findings are reported, who owns remediation and risk acceptance, and when specialist or senior review is required. For MSPs, MSSPs and consultancies, this turns supplier assurance from a periodic compliance exercise into a useful part of the customer's continuing risk-management programme.

Ready for the Pentesys point of view?

This guide covers the essentials. Continue into our technical analysis for a firmer position, practical implications and recommended action.

Read “Vulnerability remediation needs an operating model—not another spreadsheet” →
PARTNER WITH PENTESYS

Complement your supplier-assurance services with defined technical evidence.

If you support customers with supplier risk, security governance or technical assurance, we can explore how Expose and appropriately authorised Validate engagements could complement your existing services.

Discuss becoming a Pentesys partner →Explore Expose

Keep reading

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.