Vet a new supplier by matching the review to what it will do, what it can access, how much your business depends on it, and how difficult it would be to replace. Before approval, identify the contracting entity and accountable owners, assess relevant evidence, resolve material gaps, put expectations in writing, and record who accepted any remaining risk. This checklist is a practical baseline—not a substitute for jurisdiction-specific legal, privacy, tax, insurance, sanctions, or regulated-sector review.
How much due diligence does this supplier need?
Set the review depth before sending a questionnaire. A supplier handling a low-impact task with no sensitive data or system access may need a lighter review than a cloud provider hosting a core business process or a managed service provider with privileged access. A long questionnaire sent indiscriminately can burden both sides without making the decision clearer.
Consider these factors together; neither NIST nor CISA provides a universal numerical score or weighting scheme:
- Criticality: Which business process depends on the supplier, and what is the likely impact if the service is unavailable or fails?
- Access and exposure: Will the supplier or its subcontractors enter facilities, connect to systems, handle software, or receive or generate business or personal data?
- Substitutability and resilience: How quickly could you move to another provider, and what would happen during a disruption or transition?
- Ownership, provenance, and dependencies: Are there ownership or control concerns, questions about where products or services originate, or important sub-tier providers to understand?
- Evidence and mitigation: Can the supplier substantiate relevant claims, and can gaps be addressed through controls, contract terms, or a narrower scope?
For ICT suppliers, NIST’s finalized SP 1326, published July 8, 2026, provides a due-diligence structure. Its scope is ICT suppliers, not every type of supplier. CISA’s SMB vendor supply-chain material distinguishes use cases such as physical or logical access, cloud-hosted solutions, and managed service providers; its template is intended to be adapted to the use case rather than treated as a universal questionnaire.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- Desk pad layout: Plan your week at a glance with this 5.5 x 8.5 inches size notepad, designed for daily task management, weekly to-do, and errand tracking right on your desk or bag
- Undated, Monday-Sunday format: 50 tear-off sheets with no date printed, so you can start any week and use the pad anytime - seven-day layout supports appointment tracking and weekly productivity planning
- Versatile planning tool: Use as a weekly schedule, priority list, meal planning pad, grocery list, or task tracker - flexible enough for home, office, and student use
- 70 lb heavyweight paper: Thick sheets provide a clean writing surface - ink does not bleed through, so you can write with any pen, marker, or highlighter without affecting the page below
- Made in USA: designed, printed, and hand assembled in the USA - thank you for supporting small businesses like ours; a compact half letter desk pad built for reliable weekly planning
Vendor onboarding checklist
- Identify the supplier and your accountable owners. Record the legal entity you intend to contract with, the service scope, your business sponsor, and the procurement contact. Note the supplier’s role in the supply chain. For higher-risk ICT suppliers, investigate relevant ownership and control, subsidiaries, and sub-tier providers. NIST SP 1326 includes traceable company information and foreign ownership, control, or influence (FOCI) in ICT due diligence.
- Describe the relationship and exposure. State what the supplier provides, which business process depends on it, how replaceable it is, and whether it or its subcontractors will have physical or logical access to facilities, systems, software, or data. CISA’s SMB materials separate physical/logical access, cloud-hosted solutions, and managed service providers because the relevant questions differ.
- Choose review depth and approval requirements. Use the criticality and exposure factors above to decide what evidence to request, who must review it, and which findings require escalation. Tailor questions to the service and document why a lighter or deeper review is proportionate.
- Verify identity and eligibility where applicable. Confirm that the legal entity in the proposed agreement is the one you assessed. In U.S. government procurement contexts, NIST SP 1326 identifies the ITA Consolidated Screening List and SAM entity exclusions as possible pre-check resources. These are not a universal checklist for private-sector buyers or every transaction; applicability depends on jurisdiction and context, and some sources may restrict access.
- Review evidence relevant to the supplier’s exposure. For ICT suppliers, organize evidence review around NIST SP 1326’s five domains: FOCI, provenance, resilience, foundational cyber practices, and supply-chain tiers. Ask for evidence that addresses your actual use case. Record answers that are partial, unclear, or unsupported, then follow up on material gaps. CISA’s SMB spreadsheet supports yes, no, or partial responses with explanations.
- Understand data handling and privacy. Establish what data the supplier receives or generates; how it may use, share, or sell that data; how long it retains it; and how deletion works when the service ends. The FTC advises addressing vendor data use, sharing, sale, retention, and deletion. Have privacy or legal staff review the terms that apply to your data and jurisdiction.
- Put the requirements in the agreement. Specify relevant security expectations and how you will confirm compliance. Depending on the relationship, address incident notification and cooperation, remediation, subcontractor flow-downs, and data return or deletion at exit. FTC guidance supports written security provisions and verification; NIST software supply-chain guidance discusses attestation and flow-down obligations for sub-tier suppliers. Exact clauses depend on the service, data, jurisdiction, and applicable obligations.
- Record the approval decision and any conditions. Keep the risk tier, questionnaire, supporting documents, open findings, mitigations, decision owner, approval date, and conditions together in an accessible record. A supplier with unresolved high-impact gaps may require mitigation, a restricted scope, an exception, or a decision not to proceed; the appropriate outcome depends on business risk and applicable obligations.
- Set monitoring expectations before onboarding is complete. Choose a review interval and event triggers proportionate to risk. Potential triggers include a material service change, breach, ownership change, significant subcontractor change, or deterioration in evidence. FTC guidance advises verifying compliance and updating vendor requirements as threats change.
What to request from an ICT supplier
Use NIST SP 1326’s five domains to keep an ICT review organized, then tailor each request to the service and your exposure. A document or questionnaire response is evidence to assess, not proof by itself that a supplier is safe.
| Domain | Review focus | Practical follow-up |
|---|---|---|
| Foreign ownership, control, or influence (FOCI) | Ownership and control information relevant to the supplier and the service. | Clarify relevant entities and relationships where the service’s risk or applicable obligations warrant it. |
| Provenance | Where the product, service, or important components originate and how their source is established. | Ask for evidence relevant to the components and dependencies your use case relies on. |
| Resilience | How the supplier and service can withstand or recover from disruption. | Explore dependencies, continuity arrangements, and the practical consequences of an outage or transition. |
| Foundational cyber practices | Cybersecurity practices relevant to the systems, access, and data involved. | Match evidence requests to the supplier’s access and the impact of compromise; follow up on material gaps. |
| Supply-chain tiers | Sub-tier providers and dependencies that may affect delivery, security, or continuity. | Identify important subcontractors and determine whether relevant obligations and evidence extend to them. |
This framework is specific to ICT supplier due diligence. It does not replace other reviews that may apply, such as privacy, tax, insurance, sanctions, or sector-specific legal checks.
Rank #2
Make the approval decision traceable
Keep the decision record with the evidence so another reviewer can understand what was assessed and why the supplier was approved, restricted, or declined. CISA’s SMB vendor supply-chain material includes an Excel spreadsheet that can be adapted for questionnaire tracking. The page is dated October 26, 2021; confirm that its downloadable file remains available and suitable for your use before relying on it.
- Supplier identity, service scope, and relationship owner
- Risk tier and rationale for the review depth
- Questionnaire responses and supporting material
- Unresolved findings, impact, and planned mitigation
- Approver, decision date, and any restrictions or conditions
- Review interval and event triggers
If a material gap remains, make the decision explicit: address it before onboarding, reduce access or scope, document an authorized exception, or do not proceed. The response should reflect business impact and applicable obligations rather than a generic score.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Common review mistakes to avoid
- Using one exhaustive questionnaire for every supplier: tailor the questions and evidence burden to criticality, access, data, and dependency.
- Treating a certification or questionnaire as a guarantee: assess evidence in context, note partial answers, and verify material claims where appropriate.
- Checking only the direct supplier: consider relevant subsidiaries, subcontractors, and other sub-tier dependencies for higher-risk relationships.
- Leaving privacy and exit terms until later: establish data use, sharing, retention, deletion, and return expectations before approval.
- Approving without a monitoring plan: a review can become stale after a breach, material service change, ownership change, or significant subcontractor change.
- Applying U.S. government screening checks indiscriminately: NIST’s named screening resources are cited for government procurement contexts; determine what applies to your buyer, transaction, and jurisdiction.
Or skip the browser setup
If part of your ICT supplier review is to keep a visual record of public-facing supplier pages, you can capture them with ScreenshotNeo. A screenshot documents what appeared on a page at capture time; it does not verify a supplier’s security controls or replace evidence review.
One GET request returns an image or PDF. For example, this cURL request saves a WebP screenshot of the supplier’s public site; replace the example URL with the page you need. See the ScreenshotNeo API documentation for request options.
Rank #4
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Quick Recap
Best Value
- Cookie or consent banners are accepted and removed before capture; supported cleanup also removes known consent platforms, newsletter popups, and chat widgets, and each cleanup step can be turned off.
- Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing; response headers identify the page verdict and whether the request was billed.
- An MCP server provides
take_screenshot,get_page_info, andcapture_pdftools for AI agents and MCP clients. - The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free plan.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →

