Your compliance is only as strong as your weakest vendor
Regulators and auditors have long stopped looking only at your own organisation: ISO 27001, the GDPR and DORA all require demonstrable control of risk across the entire chain. That means knowing, per vendor, what data sits where, what's been agreed, and whether it's being followed.
What you get
- Risk scan per vendor — continuity, privacy and security risks mapped and prioritised by impact.
- Compliance check — compliance with ISO 27001, GDPR, DORA and NIS2 across the vendor chain assessed, with concrete improvement points.
- Audit-ready file — a file per vendor or contract that convinces management, customers and regulators alike.
Workable, not a paper tiger
Compliance that only exists on paper won't survive an audit. We set requirements up so they land in your existing contract and vendor processes: measurable in SLAs, assigned to owners, and repeatable at every renewal. Ongoing monitoring is available through VendorManager.nl.
How we approach it
Compliance in the sourcing chain does not start with a standard, but with an overview of who manages which data and processes for you. Only then do we test against ISO 27001, GDPR, DORA and NIS2.
- Vendor register and classification — We map all ICT vendors and classify them by business criticality: which services are essential to operations, which process personal data, which have access to your network or production environment. This register is the basis for every further assessment and is exactly what DORA and NIS2 require of you.
- Contractual review — For each critical vendor we review the contract for the mandatory elements: data processing agreement, security requirements, audit rights, incident notification duty, exit and continuity arrangements, sub-processors and data location. Missing or weak provisions are ranked by risk.
- Evidence — Per vendor we collect the evidence that agreements are actually being met: ISO 27001 or SOC 2 reports, penetration test results, statements on sub-processors and the follow-up of earlier findings. Where evidence is missing, we draft the request.
- Remediation plan and embedding — You receive a prioritised list of concrete actions per vendor, tied to the next renewal date, plus a repeatable process so new vendors are contracted correctly from the start. See our knowledge centre, including EU AI Act requirements for vendors.
A familiar situation
An organisation in a regulated sector requires ISO 27001 from its ICT vendors: as a suitability requirement in tenders, and as a contractual obligation to maintain the certificate. On paper, the chain is covered. An audit by a major customer shows otherwise: of the twelve vendors with access to personal data, three can no longer produce a valid certificate, for two the scope covers only the head office and not the SaaS service actually used, and one vendor hosts data outside the EU through a sub-processor that appears nowhere in the contract. Nobody had noticed, because the certificate was checked once at contracting and never requested again. After a chain assessment the requirements are tightened: annual delivery of certificate and Statement of Applicability, scope explicitly tied to the service purchased, a duty to report changes in sub-processors and an audit right if the certificate lapses. The findings are tied to the next renewal dates and resolved within two quarters.
When is this relevant?
- You fall under DORA or NIS2, or supply organisations that do and pass the obligations on to you contractually.
- A customer, auditor or regulator asks for demonstrable control of your vendor chain.
- You require ISO 27001 or a comparable standard from vendors, but do not structurally verify after contracting whether they still comply.
- Many SaaS services have been added in recent years without central review of data processing agreements.
- A vendor has had an incident and you did not know which notification and recovery arrangements applied.
Frequently asked questions
Who does DORA apply to?
DORA applies to financial institutions and their critical ICT service providers. As a supplier to a bank or insurer, you're also drawn in through contracts.
Does this replace ISO 27001 certification?
No — it focuses on the vendor side of your information security: the controls, contracts and files that a certifying body or regulator wants to see about your chain.
What if a vendor doesn't cooperate with the assessment?
That's a finding in itself: the contract determines which audit rights and information duties you have. Where those are missing, we flag them as an improvement point for the next renewal.
What is the difference between DORA and NIS2 for my vendors?
DORA targets the financial sector and sets detailed requirements for contracts with ICT service providers, including a mandatory register and exit strategies. NIS2 applies more broadly to essential and important sectors and requires supply-chain risk management at a higher level. In practice the contractual requirements overlap strongly, so one chain assessment covers both.
How often should a vendor assessment be repeated?
At least annually for critical vendors, and at every contract renewal or material change in the service. We set up the assessment so that repetition mostly consists of requesting and reviewing current evidence rather than a new investigation.
Can you also conduct the vendor conversations?
Yes. That is often more effective than a questionnaire: vendors respond faster to a concrete contractual question than to a generic assessment. We prepare the request, hold the conversations and record the outcomes in the file.
What does a vendor's ISO 27001 certificate actually tell you?
Less than is often assumed. A certificate proves the vendor has a working information security management system within a defined scope. Check three things: whether the scope covers the service you buy (a certificate for the head office says nothing about the SaaS platform), the Statement of Applicability listing which controls are implemented and which are excluded, and whether sub-processors and hosting parties fall within the scope or are certified separately. Also ask for the latest audit report or findings list; a certificate with open major findings is a different story from a clean audit.
Test your sourcing model
Schedule a no-obligation call with Bob Goosen, or start with the free Sourcing Quickscan.
Schedule a call