Skip to main content
INTEGRATION

Connect your Supplier and TPRM Systems

Third-party risk is where NIS2, DORA and ISO 27001 all point at the same evidence: supplier assessments, certifications, contract terms. TruSecure's TPRM connector pulls vendor-risk data, so supply-chain controls cite the assessment record.

What the connector pulls

Supplier and TPRM Systems data pulled into TruSecure
Source systemWhat TruSecure pullsFeeds governance
Vendor assessmentsQuestionnaire state, scores, risk ratingsSupplier Risk · NIS2 Art. 21(2)(d) supply-chain measures
CertificationsISO 27001 / SOC 2 status, scope, expirySupplier Risk · DORA ICT third-party alignment
Contract dataTerms, SLAs, audit rights, subprocessor listsAudit Trail · contractual evidence
Criticality ratingsService dependency, concentration exposureRisk Management · concentration entries

Evidence produced from Supplier and TPRM Systems data

One control test pulled from live Supplier and TPRM Systems state — not a manual export, not a screenshot, but a verified query result with provenance:

Control test · TPRM-2026-017 certificate expirySample data
Control tested
Critical suppliers hold current certifications
TPRM source
OneTrust · 214 vendors, 28 critical
Test
re-perform · certificate scope and expiry dates
Sample
28 critical · 24 valid, 4 expired 30-90 days ago
Result
fail · 4 suppliers escalated, reassessment initiated
Evidence
TPRM API query · timestamped 2026-08-22T06:52:14Z
Export
sealed · sha256:8e1d...4c6f

Setup and scope model

  1. Read-only, scoped permission

    Connector requires read-only access to vendor records and assessment outcomes. No write permissions, no ability to edit ratings or mark assessments complete.

  2. Data filtered by entity

    Vendors scoped to the entity context — the supplier list that matters for your applicability, not the group-wide register.

  3. Continuous sync

    Expiries and assessment state refresh continuously; a lapsed certificate surfaces the week it lapses.

Commercial packaging

Supplier and TPRM Systems connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.

How integration works

A demo with your actual Supplier and TPRM Systems environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.