# Vendor Security Assessment Checklist for Security Teams > A practical vendor security assessment checklist: the areas to review before onboarding a third party, the evidence to ask for, and how to rank vendors by risk instead of treating them all the same. Source: https://playciso.com/blog/vendor-security-assessment-checklist · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- A vendor security assessment exists to answer one question before you sign: can we trust this third party with the data, access or dependency we are about to give them? The mistake most programmes make is treating every vendor the same — burying low-risk suppliers in questionnaires while rushing the ones that actually matter. A good checklist pairs the right questions with the right tiering. ## The checklist — what to review - Data handling: what data they access, where it is stored and processed, encryption in transit and at rest, retention and deletion. - Access & authentication: MFA (ideally phishing-resistant), least privilege, and how your data is segregated from other customers. - Compliance & certifications: SOC 2 Type II, ISO 27001, and any regulatory attestations relevant to your data. - Sub-processors: who they rely on (fourth-party risk) and how they manage it. - Incident response: breach-notification timelines and commitments, in writing. - Business continuity: backup, disaster recovery, and resilience. - Contract terms: security obligations, audit rights, and liability. ## Ask for evidence, not assertions For anything beyond a low-risk vendor, request independent evidence: a current SOC 2 Type II report or ISO 27001 certificate, a pen-test summary, their incident-response policy, and a sub-processor list. Self-attested questionnaire answers are a starting point; evidence is what you can actually rely on. ## Tier by exposure × importance Rank vendors on two axes: **security exposure** (how much sensitive data/access they have and how strong their controls are) and **business importance** (how badly their failure would hurt you). High-exposure, business-critical vendors get deep diligence and ongoing monitoring; low-low vendors get a light review. This focuses effort where risk actually is. Run a structured review with the free [Vendor Risk tool →](/tools/vendor-risk), see the full checklist in [our third-party checklist](/blog/third-party-vendor-risk-assessment-checklist-for-security-teams), and the ranking method in [how to rank vendor security risk](/blog/how-to-rank-vendor-security-risk-a-practical-method). ## Frequently asked questions **What should it cover?** Data handling, access/authentication, compliance/certifications, sub-processors, incident response, business continuity, and contract terms — with evidence. **Same assessment for every vendor?** No — tier by risk; deep diligence for high-exposure, business-critical vendors. **What evidence?** SOC 2 Type II, ISO 27001, pen-test summary, policies, sub-processor list, breach-notification commitments. **How to rank?** Exposure × business importance — prioritise vendors high on both.