Structured vendor security assessment across 8 domains with 42 questions mapped to NIST CSF 2.0, SOC 2, and ISO 27001. Real-time risk scoring, evidence tracking, and exportable results. No signup, no install, no data leaves your browser.
This is a free, browser-based vendor assessment. Looking for full TPRM program management? Our Premium Toolkits include vendor inventory dashboards, framework toggle filtering, tiered questionnaires, and executive reporting.
What's Included
42 questions covering governance, data protection, access control, technical security, incident response, business continuity, compliance, and contractual protections.
Four-tier maturity scoring with automatic domain averages, overall risk rating, and findings counter updated as you assess.
Every question mapped to NIST CSF 2.0 subcategories, SOC 2 Trust Services Criteria, and ISO 27001:2022 Annex A controls.
Toggle evaluation criteria for each question, showing what evidence to request and how to assess vendor responses.
Save progress as JSON to continue later. Export full results with scoring summary to CSV for stakeholder reporting.
Runs entirely in your browser. No server connection, no data collection. Your vendor assessment stays on your device.
Coverage
Each domain contains targeted questions with evaluation guidance and framework mappings, organized into logical categories for efficient assessment.
Methodology
Each question is scored on a four-tier maturity scale. Scores roll up to domain averages and an overall vendor risk rating.
| Score | Level | Description |
|---|---|---|
| 1 | Not Implemented | Control does not exist or is not operational in the vendor environment |
| 2 | Partially Implemented | Control exists but is incomplete, inconsistent, or not fully deployed |
| 3 | Largely Implemented | Control is implemented with minor gaps or areas for improvement |
| 4 | Fully Implemented | Control is fully operational, documented, monitored, and regularly reviewed |
Vendor risk rating is calculated from the overall average: 75%+ = Low, 50-74% = Moderate, 25-49% = High, below 25% = Critical.
Getting Started
Fill in vendor name, assessor, criticality tier, and data access level in the sidebar.
Use the sidebar navigation or dashboard cards to pick an assessment domain.
Rate the vendor's maturity (1-4) for each of the 42 questions. Toggle guidance for evaluation criteria.
Add notes and evidence references in the text field beside each question.
Click Summary to see the overall risk rating, domain scores, and category breakdown.
Save as JSON to continue later, or export to CSV for stakeholder reporting.
Free Assessment Tools