🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
SOC 2ISO 27001NIS2DORACR-SOC-07

Vendor Risk Assessment

Vendor risk assessment: catalogue vendors, assess security posture, risk-rate each one, create policy and register. Covers SOC 2, ISO, NIS2, DORA. €229.

Vendor Risk Assessment by Optimum Web is a fixed-price compliance service covering SOC 2 CC9.2 — Vendor and business partner risk. It costs €229 with 5–7 business days delivery by senior security engineers. Vendor register with risk ratings (all critical third parties). 14-day warranty included.

€229
Fixed price, VAT excluded
5–7 business daysSenior only
Vendor register with risk ratings (all critical third parties)
Vendor security assessment questionnaire and evaluation criteria
Vendor management policy document
Annual vendor review schedule and risk re-assessment process
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-SOC-07

This Service Covers

SOC 2CC9.2 — Risk from vendors and business partners
ISO 27001Annex A 5.19–5.22 — Supplier relationships
NIS2Article 21(2)(d) — Supply chain security
DORAChapter V — ICT third-party risk management

What You Get

Assessment and documentation of vendor/third-party risks for compliance. We catalogue your critical vendors (SaaS, cloud, payment, HR), assess each vendor's security posture (certifications, data handling, breach history), create risk ratings (high/medium/low), develop a vendor management policy, and produce a vendor register with review schedule. Covers SOC 2, ISO 27001, NIS2, and DORA third-party risk requirements.

Optimum Web provides audit preparation, documentation and technical verification. We are not a certification body, we do not employ auditors, and we do not perform internal or certification audits. The Clause 9.2 internal audit is conducted by a person independent of the area audited within your organisation, or by an auditor you appoint; the certification audit is conducted by an accredited certification body. Our role is to make sure you are ready for both.

Who Needs This

  • Companies preparing for SOC 2 needing CC9.2 vendor risk evidence
  • Organizations subject to NIS2 supply chain security requirements
  • Financial entities needing DORA Chapter V third-party risk management
  • Companies that experienced a third-party breach or vendor incident

How It Works

  1. 1
    Catalogue

    Identify all vendors with access to your data or critical systems

  2. 2
    Assess

    Evaluate each vendor: certifications, security controls, data handling

  3. 3
    Rate & Classify

    Risk-rate vendors, classify as critical/standard, document findings

  4. 4
    Policy

    Create vendor management policy + register + annual review schedule

NEXT STEP

Ready to Implement the Findings?

After the assessment, our fixed-price implementation services cover every gap — from GDPR backup (€449) to incident response (€359). No surprises.

Browse Fix Services

Ready to Start?

€229 · 5–7 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Ready to implement? Browse individual fix services

Learn more

Frequently Asked Questions

How many vendors do you typically assess?+
10-30 critical vendors for a mid-size company: cloud infrastructure, SaaS tools with data access, payment processors, HR systems, communication tools. We focus on vendors with access to sensitive data.
What if a vendor doesn't respond to our security questionnaire?+
Common problem. We assess based on public information (SOC 2 reports, ISO certificates, published security pages) and flag non-responsive vendors as higher risk. The policy includes escalation procedures.
Is this required for DORA compliance?+
Yes. DORA Chapter V mandates formal ICT third-party risk management including: pre-contractual assessment, ongoing monitoring, and concentration risk analysis. This service covers the assessment and documentation.
How often should vendor assessments be updated?+
Annual review for all vendors. Critical vendors (cloud infrastructure, payment) should be reviewed if they announce a breach, change terms, or lose certifications. The register includes alert triggers.
Does this include contract review?+
We review security-relevant contract clauses (data processing, breach notification, audit rights) and flag missing clauses. Full legal contract review is not included — consult legal for that.

Service page last reviewed 15 August 2026 by the Optimum Web compliance team.

Secured by PayPal · 256-bit SSL encryption

or order without payment