Review the relationship, not just the questionnaire
Build a useful vendor decision from scope, evidence, exceptions and follow-up.
Content and source check: October 1, 2026 · Operational suggestions
Set the boundary
Identify the service, information handled, business owner and dependencies. Criticality is a reasoned judgment, not a score generated by the tool.
Evaluate evidence
Record the scope and date of each report or other evidence reviewed. Explain unknowns and gaps; a certification logo alone does not resolve a control question.
Make a decision
Explain approval, conditions or rejection. Conditional approval needs an exception review date and a follow-up action. Assign the corrective work separately from the vendor decision.
Keep the review
Download JSON to resume, text or PDF for review, or CSV for a worksheet. Explicitly import the JSON into your pilot firm workspace to assign actions and preserve review history.
Source & applicability
NIST-1305 — CSF 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management
Supports organizing supplier risk management and communicating supplier expectations. Voluntary guidance; review depth, evidence and reassessment timing depend on the service and firm's exposure.
SEC-registered and state-registered firms may have different obligations. Have the appropriate professionals review what applies to your firm. No regulatory determination is made here.