Connect your Supplier and TPRM Systems
Third-party risk is where NIS2, DORA and ISO 27001 all point at the same evidence: supplier assessments, certifications, contract terms. TruSecure's TPRM connector pulls vendor-risk data, so supply-chain controls cite the assessment record.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Vendor assessments | Questionnaire state, scores, risk ratings | Supplier Risk · NIS2 Art. 21(2)(d) supply-chain measures |
| Certifications | ISO 27001 / SOC 2 status, scope, expiry | Supplier Risk · DORA ICT third-party alignment |
| Contract data | Terms, SLAs, audit rights, subprocessor lists | Audit Trail · contractual evidence |
| Criticality ratings | Service dependency, concentration exposure | Risk Management · concentration entries |
Evidence produced from Supplier and TPRM Systems data
One control test pulled from live Supplier and TPRM Systems state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- Critical suppliers hold current certifications
- TPRM source
- OneTrust · 214 vendors, 28 critical
- Test
- re-perform · certificate scope and expiry dates
- Sample
- 28 critical · 24 valid, 4 expired 30-90 days ago
- Result
- fail · 4 suppliers escalated, reassessment initiated
- Evidence
- TPRM API query · timestamped 2026-08-22T06:52:14Z
- Export
- sealed · sha256:8e1d...4c6f
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to vendor records and assessment outcomes. No write permissions, no ability to edit ratings or mark assessments complete.
- Data filtered by entity
Vendors scoped to the entity context — the supplier list that matters for your applicability, not the group-wide register.
- Continuous sync
Expiries and assessment state refresh continuously; a lapsed certificate surfaces the week it lapses.
Commercial packaging
Supplier and TPRM Systems connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual Supplier and TPRM Systems environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.