Vendors

Every vendor,
reviewed on time.

Keep a third-party register where each vendor has an owner, a status and a next-review date. Attach its certs and evidence as files, a SOC 2 or ISO 27001 report, a DPA, alongside the security questionnaires you run, and let each completed review set the next review date so nothing quietly slips past due.

Start for freeBook a conversation
++++
app.devguard.ch / vendors
7 vendors
Reviewed
Vendors reviewed
5/7
up to date
Reviewed05
Due01
Scheduled01
VendorComplianceNext reviewStatus
AWAWSISOSOC 2Mar 2027Reviewed
CFCloudflareISOSOC 2Jan 2027Reviewed
DiDivioISOFADPFeb 2027Reviewed
StStripeISOSOC 2this weekDue
PhPostHogISOGDPRApr 2027Scheduled
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Register, assess, review on cadence.

One register for every third party, with each vendor’s attached certs and evidence, the questionnaires you run, and its next review date in the same place.

01

Register each vendor

Add a vendor with an owner and a status, then attach its certs and evidence as files, a SOC 2 or ISO 27001 report, a DPA, a pentest AoC. The register shows at a glance who’s reviewed, who’s due and who’s scheduled.

02

Attach the assessment

Send and store the security questionnaire, VSAQ or CAIQ, and keep the evidence files the vendor returns attached to the vendor. The assessment and its proof sit on the vendor record, not in an inbox.

03

Review so it never slips

Periodic reviews run on a cadence, and completing a review sets the vendor’s next review date. The next date is set on completion, so the review schedule maintains itself.

The review never slips

Completing a vendor review sets the next review date in the same step, so a vendor moves from reviewed to due to scheduled on its own rather than being chased by memory.

Why it’s built this way

Built so reviews don’t lapse.

Four choices behind how the vendor register works here, each one something you can check, not an adjective.

01

Certs and evidence live on the vendor

You attach the vendor’s certs and evidence to the record, a SOC 2 or ISO 27001 report, a DPA, a pentest AoC, so what a third party holds is on file, not in an email thread.

02

The next review date sets itself

Completing a periodic review sets the vendor’s next review date, so the review schedule maintains itself instead of relying on a reminder.

03

Questionnaires and evidence stay attached

Security questionnaires, VSAQ or CAIQ, and the evidence files sit on the vendor, so the assessment and its proof are in one place.

04

One status, reviewed to due to scheduled

Each vendor is reviewed, due or scheduled, so you can see which third parties need attention this week without opening a single file.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where vendors connect.

Vendors are one module; each vendor reaches into the rest of the workspace, from the risks a third party introduces to the reports you hand an auditor.

2.0SCORE

Risks

Raise a risk against a vendor and tie it to the controls that treat it.

342
artifacts captured
linked to controls

Evidence

Keep questionnaires and evidence files attached to the vendor they cover.

86%
Shared with
JDAKMR+3

Reports

Export a vendor’s review history and evidence for an auditor or the board.

JUN
ISO review
in 3 days

Deadlines

See each vendor’s next review date alongside every other due item.

FAQ

The questions evaluators ask.

What does each vendor record hold?

A vendor has an owner, a status and a next-review date. You attach its certs and evidence as files, a SOC 2 or ISO 27001 report, a DPA, a pentest AoC, alongside the security questionnaires you run, so the proof stays on that record.

How do you keep vendor reviews from slipping?

Reviews run on a cadence, and completing one sets the vendor’s next review date in the same step. Because the next date is set on completion, a vendor moves through reviewed, due and scheduled on its own rather than being chased by memory.

Which security questionnaires can I use?

You can store the questionnaires you run, including VSAQ and CAIQ, and keep the evidence files a vendor returns attached to the vendor. The assessment and its proof live on the vendor record.

How is this different from a vendor spreadsheet or another GRC tool?

In a spreadsheet, a vendor is a row with a review date nobody updates and certs nobody can find. Here, each vendor is a living record with its certs and evidence files attached alongside the questionnaires you run, a clear status, and a next review date the system sets on completion, so reviews stay current.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. You can export your vendor records and questionnaires to CSV; your data is yours, so there’s no lock-in.

Keep every vendor reviewed on time.

Hold one register where you attach each vendor’s certs and evidence files alongside the questionnaires you run, and let completed reviews set the next date. See who’s due this week instead of finding out at the audit.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free