Learn

Third-party risk, explained.

Plain-language guides to the field we work in — third-party risk, security questionnaires, and regulatory incident response. Open, on the page, no form. Written for practitioners, not for search engines, but useful to both.

Third-party risk
Pillar · Foundations
What is third-party risk management? A 2026 guide
The complete primer: what TPRM is, the vendor lifecycle, tiering by exposure, frameworks, and where ratings fall short.
Read →
Assessment
Vendor risk assessment, step by step
The steps, the evidence to gather, and how to scope depth to a vendor's exposure.
Read →
Foundations
Vendor risk management
What VRM is, how it differs from TPRM, and how to scope depth to a vendor's exposure.
Read →
Foundations
Fourth-party risk
Your vendors' vendors — subprocessors and nth parties you never contracted but still depend on.
Read →
Foundations
Building a TPRM framework
The building blocks of a third-party risk management framework, and the standards that shape it.
Read →
Assessment
Vendor tiering
How to classify vendors by criticality and exposure so assessment depth follows real risk.
Read →
Foundations
Supply chain risk management
C-SCRM, the software and hardware supply chain, and how it differs from TPRM.
Read →
Foundations
NIST CSF supply chain
How CSF 2.0 handles supply-chain risk — the Govern function, the GV.SC category, and NIST SP 800-161r1.
Read →
Assessment & assurance
Pillar · Assessment
The security questionnaire: a practical guide for both sides
SIG, CAIQ, and bespoke questionnaires; questionnaire fatigue; how to answer once and reuse.
Read →
Assessment
The SIG questionnaire, Core and Lite
What Shared Assessments' SIG covers, how Core and Lite differ, and when each is the right depth.
Read →
Assessment
CAIQ, for cloud providers
What the CAIQ is, how it maps to the Cloud Controls Matrix, and when cloud buyers ask for it.
Read →
Assessment
What a trust center is
The page where a vendor publishes security evidence so buyers self-serve — and send fewer questionnaires.
Read →
Assessment
SOC 2 vs ISO 27001, for buyers
What each credential proves, how an attestation differs from a certification, and when each applies.
Read →
Incident & resilience
Pillar · Resilience
Cyber incident management: the lifecycle and the clocks
The phases of incident management, how it differs from response, and the DORA, NIS2, and GDPR clocks.
Read →
Pillar · Resilience
Cyber risk response: acting when a vendor is the incident
Responding to third-party cyber risk — from early signal to containment, notification, and reassessment.
Read →
Resilience
DORA incident reporting, on the clock
How a major ICT-related incident is classified and the initial, intermediate, and final report clock that follows.
Read →
Resilience
NIS2 incident reporting: 24h, 72h, one month
The significant-incident test and the 24h/72h/one-month reporting sequence to the CSIRT.
Read →
Resilience
GDPR breach notification and the 72-hour rule
The 72-hour rule, when it applies, and notifying the supervisory authority and data subjects.
Read →
Resilience
The incident response plan, built to work
What an IR plan contains, the NIST/ISO phases, and how to keep it alive with testing.
Read →
Resilience
DORA vs NIS2: differences and overlap
Scope, sectors, incident clocks, and lex specialis — how the two EU regimes differ and overlap.
Read →
Regulation
Regulation
What is DORA?
A plain guide to the EU Digital Operational Resilience Act — who it binds, the five pillars, and the timeline.
Read →
Regulation
What is NIS2?
A plain guide to the NIS2 Directive — essential vs important entities, sectors in scope, and supply-chain and reporting duties.
Read →
Also
Inside-out vs outside-in
Why the scanner misses your riskiest vendor.
The incident clocks
DORA, NIS2, and GDPR deadlines side by side.
All resources
Guides, release notes, and references.