Vendor risk that doesn't stop at the signature.
Procurement signs the contract — and inherits the risk. The vendor assessment happened at onboarding, the certifications were checked once, and nothing watched what changed after: the sub-processor added quietly, the breach disclosed on a Friday, the certificate that lapsed.
TruSecure treats the supplier as continuously governed: one assessment before signature, continuous monitoring after it, and — because supplier obligations repeat across regimes — one register that feeds every framework that asks. NIS2's supply-chain measures, DORA's third-party requirements, ISO's supplier controls: answered once, cited many times.
What changes for sourcing
- Assess before the signature
A structured assessment scores the vendor against your criteria — including sovereignty, where the answers are published rather than promised.
- Feed every regime at once
One assessment satisfies NIS2 supply-chain, DORA third-party risk and ISO supplier controls simultaneously. Answered once, cited everywhere.
- Monitor after go-live
Certificates, sub-processor changes, disclosed incidents and contract flags are watched continuously — the register changes when the vendor changes.
- Turn the table around
When you are the one being assessed, your own answers export from the same register — evidence-backed, not questionnaire-backed.
What you'd actually look at
One assessment — the detail page that opens behind each row of the vendor view:
- Criticality
- important · data access
- Assessment
- 18/20 criteria met
- Flags
- US sub-processor
- Decision
- conditional · compensating
- Monitors
- certs · breaches · changes
- Feeds
- NIS2 21(2)(d) · DORA 28
The obligations behind the register
| What it asks of you | Citation | Where it is answered |
|---|---|---|
| NIS2 · supply-chain security, supplier relationships | Art. 21(2)(d) | Supplier register |
| DORA · ICT third-party risk management | Art. 28 | Register · monitoring |
| ISO 27001 · supplier relationships | A.5.19–5.22 | Assessment · monitoring |
| GDPR · processor guarantees | Art. 28 | DPA · sub-processor watch |
If sovereignty is a scored criterion in your vendor assessment, the answers are published rather than promised: two EU/UK entities, one EEA sub-processor, no US- or Asia-based party in the chain, and full machine-readable export you can exercise today.
How procurement teams usually start
A demo with your assessment criteria loaded, then a Resilience Sprint that stands up the supplier register for your top vendors, then the subscription. No self-serve checkout, no per-seat maths.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.