Vendor due diligence, in a security context, is the assessment you run before you sign — establishing what a prospective supplier will be able to reach, how they protect it, and whether the risk that creates is one you are willing to hold. This article is about cyber and supplier assurance due diligence specifically, not the financial-crime or M&A sense of the term, and it covers what to assess, how deep to go, and how due diligence connects to the vendor onboarding process that follows it.
Why the pre-contract moment matters more than any later one
Every assessment you run after signature happens with your leverage already spent. Before signature you can require controls, negotiate notification windows, insist on subcontractor disclosure, or walk away. After signature you can ask.
That asymmetry is the entire argument for taking due diligence seriously, and it is why the most common failure in vendor risk programmes is not a bad assessment — it is an assessment that arrived after procurement had already committed.
Scope the assessment before you run it
The mistake that makes due diligence expensive is assessing everyone at the same depth. Before you send anything, establish inherent risk from what you already know:
- What data will they hold or process? Special-category or regulated data changes the answer entirely.
- What access will they have? Integration, privileged access and remote access into your environment matter far more than contract value.
- How critical are they? How quickly does their failure become your outage?
- Where are they, and where is the data? Jurisdiction affects both regulatory exposure and practical recourse.
- Who do they depend on? Their subcontractors are your fourth parties.
That answers itself from your own records, without asking the vendor anything, and it decides how much effort the rest of the exercise deserves.
What to actually assess
For a supplier with meaningful data or access, cover these:
Governance and accountability. Who owns security, who they report to, and whether there is a policy set that has been reviewed this decade. This is invisible from the outside and is exactly what a questionnaire is for.
Certifications, read properly. ISO 27001, SOC 2 or Cyber Essentials are useful evidence — if you read the scope statement rather than the certificate. Scope is where the interesting detail lives, and the certificate does not state it. See Cyber Essentials Plus for what that particular certificate does and does not prove.
Access and authentication. How their staff reach your environment, whether that access is time-bound, whether MFA is enforced, and who reviews it.
External security posture. What their internet-facing estate actually looks like — patch currency, expired certificates, exposed services, breach history. This requires no cooperation from the vendor, which means you can assess a prospect before anyone agrees to fill anything in.
Incident history and handling. Not disqualifying in itself. How an organisation handled an incident is frequently more informative than whether it had one.
Subcontractors. Who else touches your data. You have no contract with them, so disclosure in your contract is the only leverage you will ever have.
Exit. What happens to your data when the relationship ends, and how destruction is evidenced.
Reconcile the two sources
The valuable output of vendor due diligence is rarely a score. It is the disagreement between what a vendor tells you and what can be independently observed — a questionnaire asserting MFA everywhere alongside an external view showing a legacy portal without it.
That contradiction is worth more than either source alone, and finding it is the part most programmes skip, usually because the questionnaire and the external data live in different systems owned by different people.
Turn findings into contract terms
Due diligence that ends in a report has wasted its timing. The output should land in the agreement:
- Incident notification within a window that lets you meet your own obligations. If you owe a regulator an early warning in 24 hours, a contract giving the supplier 72 is already unmeetable.
- Right to audit, and right to reassess on material change.
- Subcontractor disclosure, with notification before changes.
- Security requirements proportionate to tier, stated rather than implied.
- Data return and destruction at exit, with evidence.
From due diligence into the vendor onboarding process
Due diligence and onboarding are frequently run as one activity, which is why both are often done badly. They answer different questions: due diligence asks should we do this at all, onboarding asks how do we set it up safely.
A workable onboarding sequence after a decision to proceed:
- Record the tier and the accepted residual risk, with a named approver.
- Provision access on least privilege, time-bound where possible, with an owner.
- Register the relationship properly — owner, criticality, data types, systems touched, renewal date. This record is what every later assessment depends on, and it is where most programmes quietly fail.
- Set the monitoring baseline so you can detect change from a known starting point.
- Schedule the first reassessment, and define the events that trigger an off-cycle one.
The limitation worth stating plainly
Vendor due diligence is a decision made at a moment, about a relationship that will last years. Everything you assess pre-contract describes the supplier as they were during procurement — typically their most attentive period.
What follows is the part that determines whether the decision holds: they will change hosting providers, ship new services, be acquired, lose their security lead and inherit vulnerabilities in software they did not write, and none of that generates a notification to you.
Which is to say that due diligence is necessary and not sufficient. The programme it belongs to — tiering, monitoring, reassessment on events rather than dates — is what makes the original decision mean anything twelve months later. That is supplier risk management, and due diligence is its front door rather than its whole house.
