← Help

Vendor Security Guide

Track your third-party vendors, their criticality, and review status.

Adding a vendor

From the Vendor Security page, record the vendor's name, a criticality tier, and manual review notes. Criticality is your own judgment call (how much would it hurt if this vendor had a security incident?), not something calculated automatically.

Review status

Set a security-review status and a next-review date. A vendor whose next-review date has passed shows an Overdue badge, so you can see at a glance which relationships need a fresh look.

Linking a vendor to a risk

A vendor can link to a single Risk Register entry, useful when a vendor relationship itself is the thing you're tracking as an external risk. See the GRC guide for how the Risk Register's treatment plans work.

Who can do what

Owners, admins, and security managers can add and manage vendors. Any member can view the inventory.

Vendor Security Guide | CyberEnforced