Evaluate a vendor by first mapping what it does, what information and systems it can reach, and what would happen if it were compromised or unavailable. Then gather evidence proportionate to that risk, examine the supplier and material supply-chain dependencies, weigh likelihood and impact, and document a decision with owners and follow-up conditions. NIST’s cybersecurity supply-chain guidance provides a useful framework, but it is not a complete assessment of financial, legal, privacy, sanctions, safety, or jurisdiction-specific risk.
What a third-party risk assessment should cover
Supplier due diligence is research into pertinent information about a supplier or product to support informed decisions—not simply sending a questionnaire once and filing the response. NIST’s SP 1326 Due Diligence Assessment Quick-Start Guide, finalized July 8, 2026, is specifically scoped to information and communications technology (ICT) suppliers; NIST notes that due-diligence assessment can also be applied to other supplier types.
For an ICT supplier, SP 1326 organizes assessment around five components. Use them as lenses for selecting relevant evidence, not as a universal pass/fail checklist. The evidence examples below are practical prompts, not a mandatory NIST evidence pack.
| Assessment lens | What to understand | Possible evidence to request or review |
|---|---|---|
| Foreign Ownership, Control, or Influence (FOCI) | Relevant ownership, control, and influence considerations for the supplier and the relationship. | Ownership disclosures and explanations of relevant control or influence arrangements, where applicable to your context. |
| Provenance | Where the supplier and relevant products or components originate, and how their origin can be established. | Available product or component origin information and documentation describing how provenance is tracked. |
| Resilience | The supplier’s ability to withstand and recover from disruption affecting the service or product you rely on. | Relevant continuity and recovery information, including how the supplier handles disruptions that could affect your use. |
| Foundational cyber practices | The supplier’s baseline cybersecurity practices and how they relate to the service, data, and access involved. | Security documentation and explanations of practices relevant to the systems and information in scope. |
| Supply-chain tiers | Material dependencies beyond the direct supplier, where information is available. | Information about relevant subcontractors, component dependencies, or other tiers that could affect confidentiality, integrity, or availability. |
These five components come from NIST SP 1326. The examples are ways to make the inquiry concrete; they are not asserted as specific requirements in that guide.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
1. Scope the relationship before asking for evidence
Start by describing the actual product, service, or business process you are considering—or already depend on. A vendor’s general security posture matters, but so does the particular route by which its failure could affect your organization. NIST SP 800-161 Rev. 1 places cybersecurity supply-chain risk management within risk management activities across organizational levels, including strategy, policies, plans, and assessments of products and services. See the current NIST SP 800-161 Rev. 1 publication record.
- Describe the service or product and the business process that relies on it.
- Identify information the supplier handles and the systems, accounts, or interfaces it can access.
- Note important dependencies, including relevant subcontractors or supply-chain tiers if known.
- Consider the consequences if the supplier is breached, provides compromised components, or becomes unavailable.
This scoping list is a practical synthesis of NIST’s organizational and supply-chain framing, not a prescribed NIST form. Capture uncertainties too: for example, if the supplier has not identified a material subprocessor, record that as an evidence gap rather than assuming the dependency does not exist.
2. Set the depth of review by risk and priority
Not every vendor warrants the same investigation. A supplier with sensitive access or a critical operational role generally merits more rigorous review than one whose failure would have limited consequences. NIST’s supplier-assessment template is a toolbox of questions to select for the controls and context, and it advises organizations to consider assessment priority when setting rigor. It does not establish a universal numerical threshold or require one questionnaire for every supplier. See the NIST SP 800-161 Rev. 1 assessment material.
Use a short initial screen to decide whether a deeper review is warranted. Consider:
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
- Access: Does the supplier handle sensitive information or have meaningful system access?
- Criticality: Would interruption materially affect an important service, process, or obligation?
- Exposure: Are there material dependencies, uncertain provenance, or limited visibility into relevant supply-chain tiers?
- Impact: What could a compromise or outage do to your organization, information, and systems?
- Evidence quality: Can the supplier substantiate relevant claims, and are important questions unanswered?
These are prioritization considerations, not a scoring formula. Set the level of inquiry according to your organization’s risk context and policy; the cited NIST sources do not supply a universal score, weight, or pass/fail cutoff.
3. Gather pertinent evidence across the five lenses
Combine information from sources relevant to the relationship. NIST’s assessment approach allows consideration of public and private information and known supply-chain risks; select questions that fit the controls and context rather than treating a long questionnaire as a substitute for judgment.
Ownership, control, and influence
Determine whether ownership, control, or influence factors are relevant to this supplier and the service in scope. Ask for clarification where publicly available information is incomplete. The significance of a particular factor depends on your organization and applicable requirements; the NIST guide names FOCI as an assessment component but does not make every ownership circumstance a universal disqualifier.
Provenance and supply-chain tiers
Understand what is known about the origin of the supplier and material products or components, and how that origin is established. Ask which downstream suppliers or subcontractors matter to the service and whether the supplier can provide meaningful visibility into those tiers. Distinguish a documented dependency from one that is simply unknown.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Resilience and foundational cyber practices
Seek information that bears on the supplier’s ability to withstand and recover from relevant disruption, alongside evidence of baseline cybersecurity practices pertinent to the service. Focus on whether the evidence addresses your exposure, not merely whether a document exists. Record claims that cannot be verified or that cover a different service or environment as limitations.
4. Assess likelihood and impact, not just questionnaire answers
Bring the evidence together with known supply-chain risks and ask two decision questions: how plausible is it that a risk will affect this relationship, and how serious would the effect be for your enterprise, information, and systems? NIST’s assessment materials emphasize likelihood and potential impact; they do not prescribe one scoring model for all organizations.
Consider both direct access and indirect pathways. A supplier does not need to be a software company to create cybersecurity supply-chain exposure: NIST has described a retailer’s data breach through an air-conditioning contractor’s access to a data-sharing portal. The example illustrates why the assessment should follow actual access and dependencies rather than vendor category alone. See NIST’s May 2022 explanation of its supply-chain guidance.
If you compare multiple vendors, use the same decision-relevant lenses for each. A side-by-side record can include:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
| Comparison area | Record for each candidate |
|---|---|
| Access and information sensitivity | What information and systems the supplier would reach, and how sensitive they are. |
| Criticality and resilience | How much the business depends on the supplier and what is known about its ability to withstand and recover from disruption. |
| FOCI and provenance | Relevant ownership, control, influence, origin, and traceability information. |
| Foundational cyber practices | Evidence relevant to the service and any material unanswered questions. |
| Supply-chain visibility | What is known about material dependencies beyond the direct supplier. |
| Evidence gaps and expected impact | Where evidence is weak or missing, and the likely consequences if the supplier is compromised or unavailable. |
This comparison is a synthesis of NIST SP 1326’s components and SP 800-161’s emphasis on risk assessment. The sources do not prescribe weights, a numeric ranking method, or universal acceptance criteria.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Make a decision and preserve the reasoning
Use the assessment to inform acquisition or continued-use decisions. Record the material findings, what remains uncertain, the risk judgment, and any mitigations or conditions needed to proceed. Assign owners and follow-up dates or triggers according to your organization’s approval process; the exact decision workflow is organization-specific.
A useful decision record states:
- the supplier, service, and scope assessed;
- the evidence considered and any material gaps;
- the significant risks and their expected likelihood and impact;
- the decision, its rationale, and any agreed mitigation or limitation;
- who owns each action and what event will prompt reconsideration.
This record is a practical governance aid, not a NIST-mandated template. It helps connect supplier research to organizational risk management, rather than leaving findings isolated in a procurement file.
6. Reassess when the relationship or risk changes
Supplier due diligence should inform decisions about new acquisitions and existing systems. Revisit the assessment when a material change affects the basis of the decision—for example, a change in the service, access, supplier, or relevant supply-chain conditions. Set the review cadence through organizational policy and risk context: the cited NIST publications do not establish a universal reassessment interval.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Use public web pages as evidence carefully
A supplier’s public security or trust page can be one source of information, but a screenshot only records what was visible at capture time. It does not verify the accuracy of the supplier’s claims, establish its internal controls, or replace direct evidence and judgment. Preserve relevant context and date in your own assessment record, and do not treat a clean-looking page as proof of low risk.
Or skip the browser setup
If you need a capture of a public supplier page for your evidence file, ScreenshotNeo can return a screenshot or PDF through a single API request. Replace the example URL with the supplier’s public page. The API accepts a URL and can return PNG, JPEG, WebP, or PDF; see the ScreenshotNeo documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots per month with no card, and paid plans start at $5 for 3,000 screenshots.
Sign up free for 1,000 screenshots a month—no card required.
Recommended Free Tools
Keep the scope of the assessment clear
NIST SP 800-161 Rev. 1 and SP 1326 are cybersecurity supply-chain resources. They help structure questions about ICT suppliers and can inform due diligence for other supplier types, but they do not by themselves settle every legal, financial, privacy, sanctions, safety, or sector-specific issue. Add the other reviews your organization and jurisdiction require, using appropriate sources for those domains.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

