Vendor Security Assessments: What to Ask Suppliers For
Questionnaires only go so far. How to assess supplier security with evidence, and where independent testing fits into third-party assurance.
Read articleVery few standards name penetration testing as a mandatory control, but auditors, customers and insurers ask for it anyway. These articles cover where testing supports ISO 27001, PCI DSS, SOC 2 and UK GDPR, what assessors typically want as evidence, and how to answer supplier assurance questions without handing over exploitable detail.
12 articles
Questionnaires only go so far. How to assess supplier security with evidence, and where independent testing fits into third-party assurance.
Read articleIndependent validation of a supplier's security controls: what it covers, how it differs from an audit, and when it is worth asking for.
Read articleHow to share testing evidence with customers and procurement teams without exposing exploitable detail. Summary letters and attestations.
Read articleSOC 2 does not name penetration testing as a control, but auditors commonly expect it. How testing supports the Trust Services Criteria.
Read articleWhat technical due diligence covers during an acquisition, how much can realistically be done pre-completion, and what changes deal terms.
Read articleArticle 32 requires regular testing of security measures without naming a method. How penetration testing can help evidence that obligation.
Read articleIf you’re still treating your annual audit as a checkbox exercise, you’re likely missing the strategic shift toward continuous security validation….
Read articleISO 27001 does not mandate penetration testing by name. Where it supports Annex A controls, and what auditors typically want as evidence.
Read articleWhat a security assessment covers for a UK health or care provider, from clinical systems and patient data through to the evidence a DSPT submission needs.
Read articleCompany accreditation, individual certification, and the assumptions buyers get wrong about what a CREST logo guarantees.
Read articleThe controls, evidence and testing work that sit behind an ISO 27001 certification, and the order most organisations tackle them in.
Read articleWhere special category data tends to leak — logs, exports, integrations, access control — and what to test when your systems hold it.
Read articleCREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.