Skip to main content
PLATFORM · SUPPLIER RISK

One supplier record. Every regulation that references it.

Vendor risk is typically assessed once at contract signing and rarely revisited — while NIS2 Art. 21(2)(d) and DORA's ICT third-party chapter both expect continuous oversight. A questionnaire in a drawer is not oversight.

TruSecure maintains one continuous supplier risk register that feeds every regulation referencing supplier or third-party risk simultaneously. One supplier, one record, every regime that cares about that supplier reading from the same page.

How it works

  1. Register

    Every supplier gets one record: the services it provides, the data it touches, the criticality of what depends on it.

  2. Assess

    Inherent risk is scored from what the supplier is to you — not from a generic questionnaire template — and reassessed on a cycle matched to criticality.

  3. Monitor

    Certification status, contract and SLA data, and assessment outcomes stay current through the year, connected where a TPRM system already exists.

  4. Feed every regime

    NIS2’s supply-chain clause, DORA’s third-party register, ISO 27001’s supplier controls — each reads the same record. Assess the supplier once; answer every framework.

What a supplier record looks like

Supplier record · cloud hosting providerSample data
Services
IaaS · backup
Criticality
high
Citations
NIS2 21(2)(d) · DORA Art. 28 · ISO A.5.19
Assessment
current
Next review
2026-12-01

Which regulations it maps to

Third-party obligations · by framework
FrameworkWhat it expectsCitation
NIS2Supply-chain security as a risk-management measureArt. 21(2)(d)
DORAA register of ICT third-party arrangements, maintainedArt. 28
ISO 27001Supplier relationship controls, defined and operatingA.5.19–5.22

Already running a TPRM or vendor-risk tool? TruSecure's supplier and TPRM connectors pull assessments, contract data and certification status from it — the register enriches what you have rather than replacing it.