PRACTICAL GUIDE · VERSION 1.0.0

Review the relationship, not just the questionnaire

Build a useful vendor decision from scope, evidence, exceptions and follow-up.

Content and source check: October 1, 2026 · Operational suggestions

01

Set the boundary

Identify the service, information handled, business owner and dependencies. Criticality is a reasoned judgment, not a score generated by the tool.

02

Evaluate evidence

Record the scope and date of each report or other evidence reviewed. Explain unknowns and gaps; a certification logo alone does not resolve a control question.

03

Make a decision

Explain approval, conditions or rejection. Conditional approval needs an exception review date and a follow-up action. Assign the corrective work separately from the vendor decision.

04

Keep the review

Download JSON to resume, text or PDF for review, or CSV for a worksheet. Explicitly import the JSON into your pilot firm workspace to assign actions and preserve review history.

Source & applicability

NIST-1305 — CSF 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management

Supports organizing supplier risk management and communicating supplier expectations. Voluntary guidance; review depth, evidence and reassessment timing depend on the service and firm's exposure.

SEC-registered and state-registered firms may have different obligations. Have the appropriate professionals review what applies to your firm. No regulatory determination is made here.

Review a vendor →