What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assess vendor risk by examining the service you will depend on, the data and systems it can reach, and the consequences if it fails or is compromised—not by treating employee count as a security score. For technology vendors, NIST’s July 2026 due-diligence guide offers a practical set of areas to investigate; for other suppliers, adapt the same activity-specific, proportionate approach.

Start with the relationship, not the company profile

Before reviewing a vendor’s controls, define what the relationship exposes your organization to. NIST describes due diligence as research into pertinent information about a supplier or product to inform acquisition decisions. Its detailed guide focuses on information and communications technology (ICT) suppliers, so its specific dimensions are most directly applicable to technology services and products. NIST SP 1326

  • What service, product, or business activity will the vendor provide?
  • Which internal service or process depends on it?
  • What data will it handle, store, or transmit, and how sensitive is that data?
  • What systems, accounts, or permissions will it be able to access?
  • What would happen if the service became unavailable, produced incorrect results, or exposed information?

These answers establish the scope and consequences of the relationship. They also help distinguish a vendor that needs a basic screen from one that warrants deeper review.

Scale the review to the potential impact

NIST SP 1326 describes due diligence as a minimum reasonable level of research and distinguishes basic public-information research from enhanced diligence. Treat an initial public-source review as a screen, not as proof that a vendor is safe. Spend more effort where the service is critical, handles sensitive information, has privileged access, or leaves important uncertainties unresolved. NIST SP 1326

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The U.S. Interagency Guidance on Third-Party Relationships similarly frames due diligence as tailored to the activity and says familiarity with a provider is not a substitute for diligence. That guidance applies to banking organizations; its tailoring principle is useful more broadly, but it is not a universal legal requirement. Interagency Guidance on Third-Party Relationships

Evaluate evidence tied to the service

For ICT vendors, NIST SP 1326 organizes due diligence around five areas. For each one, record what evidence you found, its date and scope, whether it applies to the specific service or product, and what remains unknown. A document or assertion is useful only to the extent that it addresses the exposure in your relationship.

Foundational cybersecurity practices

Look for evidence about security practices relevant to the service, its data, and the access it receives. Identify what the evidence covers and when it was prepared; do not treat a general company statement as proof about every product, environment, or operation.

Resilience

Assess whether the vendor can continue or restore the activity after disruption. Consider the service’s continuity and recovery expectations in light of the business process that depends on it. A recovery claim matters only if its scope and assumptions fit the service you plan to use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Supply-chain tiers and subcontractors

Find out whether important functions rely on subcontractors or deeper supply-chain tiers, and how much visibility the vendor can provide into those dependencies. A direct contract does not by itself show where the service’s critical components or operations come from.

Ownership, control, influence, and provenance

Where relevant to the product, service, or your obligations, consider foreign ownership, control, or influence (FOCI) and provenance: the origin and history of the product or its components. These concerns are context-dependent; they are not a reason to apply the same assumptions to every supplier.

NIST’s broader supply-chain guidance describes a multilevel approach to cybersecurity supply-chain risk management and risk assessment for products and services. NIST SP 800-161 Rev. 1

Check continuity, responsibilities, and unresolved gaps

For a service whose interruption could materially affect your operations, review how continuity, disaster recovery, and restoration are addressed. Also identify which party is responsible for key security and operational tasks, what remedies or other contractual options are available, and which gaps remain. The U.S. interagency guidance discusses operational resilience, cybersecurity, disaster recovery, and business continuity in third-party relationships. Interagency Guidance on Third-Party Relationships

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the resulting picture to decide whether to proceed, request more evidence, add mitigations or contractual protections, choose another option, or accept a clearly documented residual risk. A missing document is not automatically proof of a control failure; it is an uncertainty to evaluate against the relationship’s importance and the evidence available.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Compare alternatives using the same criteria

When you have genuine alternatives, assess each one against the same relationship-specific criteria rather than using company size as a shortcut.

Assessment area What to compare
Activity and consequence Fit for the activity and the effect of service failure or incorrect output.
Exposure Data sensitivity, system access, and the exposure created by the service.
Security evidence Relevant practices, and the evidence’s date, scope, and applicability.
Resilience Continuity, disaster recovery, and recovery expectations.
Ownership and provenance Ownership, control, influence, and origin concerns where applicable.
Dependencies Subcontractors, supply-chain tiers, and visibility into important dependencies.
Responsibilities and gaps Contractual responsibilities, available remedies, and unresolved issues.

These criteria draw on NIST’s ICT due-diligence dimensions and the interagency guidance’s activity-specific and resilience considerations. They are a comparison framework, not a universal legal checklist. Requirements vary with sector, jurisdiction, and the buyer’s status; organizations should identify the obligations that govern their own relationships. NIST SP 1326 Interagency Guidance on Third-Party Relationships

Record the decision and keep it current

Keep a supplier assessment record that lets another reviewer understand the basis for the decision. NIST SP 800-161 Rev. 1 includes a supplier assessment record and calls for assessment dates and temporal findings, alongside supplier profile information. NIST SP 800-161 Rev. 1

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The service, product, business dependency, data, and access in scope.
  • Evidence reviewed, the source and date, its scope, and how it relates to the service.
  • Unknowns, limitations, and dependencies that could affect the assessment.
  • Mitigations, accountable owners, the decision, and any accepted residual risk.
  • The assessment date and when or under what material changes it should be revisited.

Revisit the assessment when material facts change or on a schedule proportionate to the relationship’s importance. Company size may appear in a supplier profile, but it is descriptive context—not evidence that security controls are effective or that a service is low risk. NIST’s sample record lists size among profile attributes such as legal name, domicile, company-family structure, years in business, and market segment. NIST SP 800-161 Rev. 1

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.