Third-party risk management (TPRM): assessing your suppliers

Definition, NIS 2 and DORA obligations, a seven-step lifecycle and methods for assessing your suppliers' cybersecurity.

· 10 min read
Illustration: glass nodes linked in a chain, the first one orange

Third-party risk management (TPRM) is the process of identifying, assessing and controlling the risks that your suppliers, service providers and subcontractors pose to your organisation. In cybersecurity, it means listing your third parties, classifying them by criticality, assessing their security, setting requirements by contract and monitoring their level over time. NIS 2 and DORA now make it an obligation for many organisations.

01

What is third-party risk management (TPRM)?

A third party is any external organisation you work with: SaaS software vendor, managed service provider, hosting provider, consultancy, payroll provider, carrier, and even your subcontractor's subcontractor. Each of them may access your data, connect to your information system or determine whether an activity can continue. Their level of security partly becomes yours.

Third-party risk management aims to make this exposure visible and manageable. It covers several families of risk, which the CISO often shares with procurement, legal and the DPO:

  • Cybersecurity: intrusion through the supplier, leak of data hosted by them, compromised software.
  • Continuity: failure of a provider on which a critical activity depends.
  • Compliance: a failing GDPR processor, sector requirements not met.
  • Concentration: too many activities relying on the same supplier, for example a single cloud provider.

TPRM, VRM, supplier risk: what are we talking about?

The terms overlap. TPRM refers to the broadest approach, covering all third parties. VRM (Vendor Risk Management) is limited to suppliers. European texts speak of supply chain security. In every case, third-party risk management is part of governance, risk and compliance (GRC) and follows the same logic as any risk analysis: know what matters, measure, decide, monitor.

02

Why supplier risk has become a priority

For an attacker, compromising a supplier is often more profitable than attacking each of its customers: a single intrusion opens hundreds of doors. In 2021, the EU agency ENISA analysed 24 supply chain attacks: in around 66% of cases, the attackers targeted the supplier's code, and in 66% of cases as well, suppliers did not know or did not report how they had been compromised.

A few public cases illustrate the three ways a third party can expose you:

  • Through a poisoned update: in late 2020, compromised versions of SolarWinds Orion software were distributed to its customers, to the point that the US agency CISA ordered federal agencies to disconnect them.
  • Through exposed software: in 2023, the Cl0p group exploited a flaw in the MOVEit Transfer file transfer tool to steal data from many organisations using it.
  • Through a provider that holds your data: in early 2024 in France, the cyberattack on two third-party payment operators for health insurance, Viamedis and Almerys, affected more than 33 million people according to the CNIL, the French data protection authority. The data was managed on behalf of complementary health insurers.

We look at these scenarios in detail, and at how to protect yourself, in our article on supply chain attacks.

03

Third-party risk management: what NIS 2 and DORA require

Two European texts have turned third-party risk management from good practice into an obligation.

NIS 2: securing the supply chain

Article 21 of the NIS 2 Directive lists supply chain security among the minimum risk management measures, “including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. Entities must take into account the vulnerabilities specific to each supplier, the quality of its products and its cybersecurity practices. In France, at the time of writing (September 2026), the bill on the resilience of critical infrastructure, which transposes NIS 2, is still being debated in Parliament; ANSSI is already supporting the entities concerned.

DORA: register of information and critical ICT providers

The DORA Regulation, which has applied to financial entities since 17 January 2025, goes further. Its Article 28 requires a register of information covering all ICT service arrangements with third-party providers, a risk assessment before contracting and exit strategies. Article 30 lists the mandatory contractual provisions. Finally, in November 2025, the European Supervisory Authorities designated a first list of critical ICT third-party providers, now under EU oversight.

RequirementNIS 2DORA
Who is concernedEssential and important entities in 18 sectorsFinancial entities (banks, insurers, investment firms…)
Assess suppliersYes, supply chain security (Art. 21)Yes, before and during the relationship (Art. 28)
Third-party registerNot required in this formMandatory register of information, submitted to authorities
Contractual provisionsTo be defined according to riskList of mandatory provisions (Art. 30)
Exit strategyNot explicitly requiredMandatory for critical or important functions

The article-by-article detail, deadlines and penalties are covered in our article third-party risk, NIS 2 and DORA. To support these requirements with a tool, see also our compliance campaigns module.

04

The third-party risk management lifecycle in 7 steps

An effective TPRM approach follows each third party from onboarding to exit. The effort is not the same for all of them: classification by criticality determines how deep the assessment goes.

  1. Inventory List every third party, including purchases outside IT and your suppliers' own subcontractors.
  2. Classification Assign a criticality level based on data, access to systems and business dependency.
  3. Assessment Questionnaire proportionate to criticality, evidence, certifications, audit for the most critical.
  4. Scoring Risk score, gaps found, decision: approve, approve with conditions or reject.
  5. Remediation Action plan agreed with the supplier, with owners and deadlines.
  6. Contract Security clauses, security assurance plan, right to audit, incident notification.
  7. Monitoring and exit Periodic reassessment, incident watch, exit and reversibility plan.
The cycle repeats for each third party: a reassessment, an incident or a change of scope restarts step 2.

1. Inventory your third parties

You cannot protect what you do not know. Cross-check data from procurement, accounts payable and IT, without forgetting SaaS subscriptions taken out directly by business units. For each third party, record the service provided, the data involved, the access granted and the internal owner of the relationship.

2. Classify suppliers by criticality

Assessing every supplier with a 200-question questionnaire would exhaust everyone. Classification sorts third parties into tiers using four simple questions: which data does the third party access, what access does it have to your information system, what happens if it stops, and can it be replaced quickly. Try it with the tool below.

Classify a supplier Pre-filled example: a payroll provider delivered as SaaS. Change the answers.
Which data does it access?
What access to your information system?
What happens if it stops?
Can it be replaced quickly?
SCORE 8 / 11
Criticality High
Assessment
Full questionnaire with evidence and a remediation plan
Reassessment
Every year
Contract
Security clauses, right to audit, security assurance plan
Indicative grid, to be adapted to your context. For a financial entity subject to DORA, any ICT provider supporting a critical or important function is subject to stronger contractual requirements, whatever its score.

3. Assess the supplier's security

The assessment is usually done with a security questionnaire, proportionate to the criticality tier, backed by evidence. Sent through a supplier assessment portal rather than by email, it is much easier to complete, chase and consolidate. How to build it, which questions to ask and how to avoid box-ticking answers is the subject of our article on the supplier security questionnaire.

4. Score and decide

The answers produce a score and a list of gaps. The decision lies with the business, informed by the CISO: approve the supplier, approve it subject to fixes, or reject it. Keep a record of the decision and its reasons.

5. Agree on a remediation plan

Each gap accepted under conditions becomes an action, with an owner at the supplier and a deadline. Without follow-up, these commitments remain a dead letter.

6. Put the requirements into the contract

The contract sets the rules: security clauses, incident notification within a defined time, right to audit, data location, reversibility. For sensitive services, these requirements are grouped in a security assurance plan.

7. Monitor over time, and prepare the exit

A supplier assessed three years ago is no longer the same. Plan reassessments according to criticality, watch for incidents affecting the supplier and keep an exit plan ready for the third parties on which your critical activities depend.

05

Assessing suppliers' cybersecurity: which methods?

No single method is enough. Mature organisations combine several sources of information, depending on the third party's criticality tier.

MethodWhat it providesLimitsFor which third parties
QuestionnaireBroad view of controls, comparable across suppliersSelf-declared, depends on honest answersAll, short or full version
Documentary evidencePolicies, penetration test reports, continuity plansTime to analyseHigh or critical tier
CertificationsISO 27001, SecNumCloud, HDS: checked by an independent third partyCheck the scope actually certifiedDepending on the service
External ratingInternet-facing attack surface, monitored continuouslyCannot see internal organisationAs a complement
AuditOn-site or in-depth documentary verificationCostly, must be provided for in the contractCritical third parties
06

Organising third-party risk management: roles and indicators

Supplier risk management rarely fails for lack of method; it fails because nobody feels responsible for it. Procurement signs, the business uses, and the CISO discovers the provider at the first incident. A clear allocation of roles avoids this scenario.

  • Procurement triggers the process for each new relationship and includes security clauses in contracts.
  • The business owner of the relationship qualifies the need, owns the decision to approve the supplier and follows up its remediation plan.
  • The CISO defines the classification, questionnaires and thresholds, analyses answers and advises on the decision.
  • Legal and the DPO check the clauses, in particular those required by Article 28 of the GDPR for processors of personal data.
  • Senior management sets the acceptable level of risk and arbitrates cases where a critical supplier cannot be replaced.

Indicators to track

A few indicators are enough to steer the process and report on it to management, or to a supervisory authority:

  • the share of inventoried third parties that have been classified by criticality;
  • the share of critical third parties assessed in the last twelve months;
  • the number of open gaps and their average age;
  • the share of critical contracts that contain the expected security clauses;
  • the number of security incidents involving a third party over the period.

These figures show whether effort is going to the right place. A high assessment rate is worthless if the gaps found are never fixed.

07

Third-party risk management tools: spreadsheet or platform?

Many organisations start with a spreadsheet and questionnaires sent by email. This works for a dozen suppliers. Beyond that, the limits quickly show: multiple versions, manual reminders, no history, and no way to consolidate indicators for management or for a NIS 2 or DORA inspection.

Phinasoft's third-party risk management module addresses these needs: you create your questionnaires from your requirements, your providers answer them on a dedicated portal, you give them feedback (accepted or rejected non-conformities, requests for additional information) and you track progress and compliance indicators. Each provider has a profile with the history of its assessments: you start from the previous one rather than from scratch, and you export the requirements to include in your security assurance plans. To see the full journey, from creating the questionnaire to the report, you can request a demo.

Summary

01

A risk that comes from outside

Your suppliers access your data and systems: their security level becomes yours. Third-party risk management aims to understand, measure and control this exposure.

02

A regulatory obligation

NIS 2 requires supply chain security; DORA requires financial entities to keep a register of information and to include specific contractual provisions for their ICT providers.

03

A proportionate cycle

Inventory, classify by criticality, assess, score, remediate, contract, monitor: effort focuses on critical third parties, and each assessment builds on the previous one.

Frequently asked questions

What is third-party risk management?

Third-party risk management is the process of identifying, assessing and controlling the risks associated with an organisation's suppliers, service providers, subcontractors and partners. In cybersecurity, it means listing third parties, classifying them by criticality, assessing their security, framing the relationship by contract and monitoring their level over time.

What does TPRM stand for?

TPRM stands for Third-Party Risk Management. The term covers all third parties: suppliers, IT service providers, SaaS vendors, subcontractors, partners. VRM (Vendor Risk Management) is used when the scope is limited to suppliers, and regulatory texts such as NIS 2 speak of supply chain security.

Does NIS 2 require supplier assessments?

Yes. Article 21 of the NIS 2 Directive lists supply chain security among the minimum risk management measures. Essential and important entities must take into account the vulnerabilities specific to each direct supplier, the quality of its products and its cybersecurity practices, including secure development procedures.

What is the DORA register of information?

It is a register that every financial entity subject to DORA must keep of all its contractual arrangements for ICT services with third-party providers, distinguishing those that support critical or important functions. Required by Article 28 of the regulation, it is submitted to the competent authorities, which use it in particular to identify critical ICT providers.

How do you assess a supplier's cybersecurity?

Combine several sources, in proportion to its criticality: a tailored security questionnaire, evidence (policies, test reports, continuity plans), its certifications such as ISO 27001, possibly an external rating of its exposed attack surface, and an audit for the most critical third parties. Gaps lead to a remediation plan.

Which tools for third-party risk management?

A spreadsheet is enough for a handful of suppliers but quickly becomes unmanageable: email reminders, multiple versions, no history. A third-party risk management platform centralises supplier profiles, sends questionnaires through a portal, calculates indicators, tracks action plans and keeps the history of assessments.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.