Skip to main content
FOR PROCUREMENT

Vendor risk that doesn't stop at the signature.

Procurement signs the contract — and inherits the risk. The vendor assessment happened at onboarding, the certifications were checked once, and nothing watched what changed after: the sub-processor added quietly, the breach disclosed on a Friday, the certificate that lapsed.

TruSecure treats the supplier as continuously governed: one assessment before signature, continuous monitoring after it, and — because supplier obligations repeat across regimes — one register that feeds every framework that asks. NIS2's supply-chain measures, DORA's third-party requirements, ISO's supplier controls: answered once, cited many times.

What changes for sourcing

  1. Assess before the signature

    A structured assessment scores the vendor against your criteria — including sovereignty, where the answers are published rather than promised.

  2. Feed every regime at once

    One assessment satisfies NIS2 supply-chain, DORA third-party risk and ISO supplier controls simultaneously. Answered once, cited everywhere.

  3. Monitor after go-live

    Certificates, sub-processor changes, disclosed incidents and contract flags are watched continuously — the register changes when the vendor changes.

  4. Turn the table around

    When you are the one being assessed, your own answers export from the same register — evidence-backed, not questionnaire-backed.

What you'd actually look at

One assessment — the detail page that opens behind each row of the vendor view:

Vendor assessment · V-208 cloud analyticsSample data
Criticality
important · data access
Assessment
18/20 criteria met
Flags
US sub-processor
Decision
conditional · compensating
Monitors
certs · breaches · changes
Feeds
NIS2 21(2)(d) · DORA 28

The obligations behind the register

Third-party obligations · illustrative
What it asks of youCitationWhere it is answered
NIS2 · supply-chain security, supplier relationshipsArt. 21(2)(d)Supplier register
DORA · ICT third-party risk managementArt. 28Register · monitoring
ISO 27001 · supplier relationshipsA.5.19–5.22Assessment · monitoring
GDPR · processor guaranteesArt. 28DPA · sub-processor watch
Sovereignty

If sovereignty is a scored criterion in your vendor assessment, the answers are published rather than promised: two EU/UK entities, one EEA sub-processor, no US- or Asia-based party in the chain, and full machine-readable export you can exercise today.

See the whole chain

How procurement teams usually start

A demo with your assessment criteria loaded, then a Resilience Sprint that stands up the supplier register for your top vendors, then the subscription. No self-serve checkout, no per-seat maths.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.