Vendor Due Diligence Checklist: 2026 Complete Vendor DD Framework

Vendor Due Diligence Checklist: The Complete 2026 Framework for Third-Party Risk

Vendor Due Diligence Checklist: The Complete 2026 Framework for Third-Party Risk
Vendor Due Diligence Checklist: 2026 Complete Vendor DD Framework

By CT Acquisitions Editorial Team, reviewed by senior M&A advisors. Last reviewed: June 2026.

A vendor due diligence checklist is a structured evaluation of a third-party supplier across seven domains: financial health, cybersecurity, legal and contractual exposure, regulatory compliance, operational resilience, ESG posture, and concentration risk. In 2026 the exercise carries higher stakes because the U.S. Securities and Exchange Commission cyber incident disclosure rule (effective December 18, 2023) and the EU Digital Operational Resilience Act (DORA, applicable from January 17, 2025) both hold companies accountable for failures inside their vendor stack, not just their own perimeter.

This guide separates two things most articles blur together. Sell-side vendor due diligence (VDD) is the pre-transaction report a seller commissions from a Big Four accounting firm or a boutique so buyers can trust the target’s numbers. Third-party vendor risk management (TPRM) is the ongoing discipline of vetting every supplier a company depends on. Both use the phrase “vendor due diligence.” Neither is the other. This checklist covers TPRM in depth, explains where VDD reports fit, and shows why every M&A buyer inherits the target’s entire vendor risk register at closing.

What vendor due diligence actually means in 2026

Vendor due diligence in 2026 is the process a company uses to verify that a third-party supplier can deliver its service without introducing unacceptable financial, cyber, legal, or regulatory harm. The phrase covers two distinct disciplines that share a name. Buyers evaluating a company for acquisition also inherit its vendor register, which is why M&A dealmakers now embed a vendor risk review inside quality-of-earnings work.

The scope has widened for three reasons. First, cloud and SaaS penetration means the average enterprise now runs on hundreds of external providers; Gartner reported in October 2024 that 60% of organizations work with more than 1,000 third parties. Second, regulators have moved from “know your vendor” guidance to enforceable rules with named penalties. Third, the 2023 MOVEit breach at Progress Software, which exposed data from more than 2,700 organizations according to Emsisoft’s tracker updated through 2024, demonstrated that a single vendor failure can cascade into hundreds of downstream companies.

Sell-side vendor due diligence (VDD) versus third-party vendor risk

Sell-side VDD is a report a seller commissions before running a sale process. Third-party vendor risk management is a continuous program run by a buyer, corporate treasury, or procurement team. The two use identical vocabulary and produce entirely different deliverables.

Dimension Sell-side VDD report Third-party vendor risk management
Who commissions it The company being sold The company using the vendor
Who produces it Big Four or boutique advisor Internal risk team, often on a TPRM platform
Typical output 150 to 300 page report on financials, tax, commercial, IT Risk tier, questionnaire responses, monitoring alerts
Cadence Once per transaction, refreshed if the deal drags Continuous, with annual or triggered re-attestation
Typical fee range $150,000 to $2M+, depending on deal size Platform fees from $30,000 to $500,000 annually
Primary audience Prospective buyers and their lenders Internal risk committee, board, regulators

If a search brought you here looking for the seller’s pre-transaction report, that is a specialized workstream typically commissioned alongside a sell-side advisory engagement. The rest of this checklist covers third-party vendor risk, which is the version most operators and acquirers need day to day.

When to run vendor due diligence

Vendor due diligence runs at four defined trigger points: onboarding a new supplier, annual re-attestation of an existing one, a material change event (new service, ownership change, data breach), and pre-closing on any acquisition where the target relies on that vendor. Each trigger has a different depth of investigation.

Onboarding is the deepest cut and usually blocks contract signature until complete. Annual re-attestation refreshes the highest-risk questions and confirms nothing has drifted. Material change reviews are event-driven and often shortened to the affected domain (a cyber incident triggers a cyber-only re-review). M&A closings sit outside the normal cycle: the acquirer needs to know every vendor the target uses, every contract that survives change of control, and every renewal that falls due inside the first 18 months post-close.

The M&A trigger deserves its own paragraph

When a buyer acquires a company, it inherits every vendor obligation not carved out of the purchase agreement. That includes payment obligations, data processing agreements, and the target’s exposure to any vendor already under regulatory scrutiny. Buyers who skip vendor DD at closing routinely discover months later that a key supplier terminated on change of control, invoked a price reset clause, or was already under contract dispute. Buy-side deal teams should treat vendor DD as a required workstream inside their broader transaction diligence, not an operational nicety left for post-close integration.

The seven-domain vendor due diligence framework

A defensible vendor due diligence checklist covers seven domains: financial health, cybersecurity and data protection, legal and contractual, compliance and sanctions, operational resilience, ESG and reputational, and concentration and geography. Each domain has a fixed set of evidence artifacts a reviewer requests, a scoring rubric, and a residual risk output that feeds vendor tiering.

Domain 1: Financial health

Financial health due diligence tests whether the vendor will still exist and perform the contract two, three, and five years out. The bar is not “solvent today”; it is “solvent for the useful life of this dependency.” Reviewers pull the vendor’s most recent audited financial statements where available, D&B or Experian commercial credit reports, and any public filings.

Watch for vendors freshly recapitalized under high leverage. The Wall Street Journal reported in April 2024 that U.S. business bankruptcy filings hit their highest quarterly level since 2010, and Fitch Ratings tracked a leveraged loan default rate of 4.5% for the trailing twelve months ended December 2024. Software vendors owned by private equity sponsors and running heavy debt covenants are the population most likely to end up in a distressed sale or a Chapter 11 during a multi-year contract.

Domain 2: Cybersecurity and data protection

Cybersecurity due diligence verifies that a vendor’s security posture will not become the buyer’s breach. This is the highest-stakes domain because a single vendor compromise can trigger disclosure obligations under the SEC’s Form 8-K Item 1.05 (material cybersecurity incident, effective December 18, 2023) and personal-data notice requirements across all 50 U.S. states plus the EU GDPR.

Baseline evidence artifacts:

Sector-specific overlays apply. Healthcare vendors handling PHI need a HIPAA business associate agreement (BAA) and evidence of the HHS Office for Civil Rights Security Rule controls. Payment processors need PCI DSS 4.0.1 attestation (the updated standard published in June 2024, with future-dated requirements effective March 31, 2025). Federal contractors touching controlled unclassified information need NIST SP 800-171 Rev. 3 compliance and, from Q1 2025 forward, CMMC 2.0 certification per the Department of Defense final rule published October 15, 2024.

Cybersecurity DD is where the most expensive vendor failures actually occur. The IBM and Ponemon 2024 Cost of a Data Breach report priced the average breach at $4.88M, with breaches involving a third party running approximately $370,000 higher than the mean.

Domain 3: Legal and contractual

Legal due diligence reads the master services agreement and every subordinate document for terms that shift risk to the buyer or lock the buyer into unfavorable renewals. The review is boring, and skipping it is how companies end up with auto-renewing seven-figure contracts they never intended to keep.

Two terms deserve special attention in 2026. First, change of control clauses trigger during acquisitions and can void a contract or force renegotiation at exactly the moment leverage is lowest, which ties directly to the buyer’s exposure under a material adverse effect analysis. Second, indemnification caps that carve out only “gross negligence and willful misconduct” leave the buyer holding a substantial portion of the loss on ordinary-negligence data breaches. Push for uncapped indemnification for confidentiality and data breach claims, or a supercap set at a multiple of annual fees.

Domain 4: Compliance and sanctions

Compliance due diligence screens the vendor and its beneficial owners against sanctions lists, anti-bribery laws, and sector-specific regulations. This domain has moved from a checkbox to a live enforcement risk since the U.S. Office of Foreign Assets Control (OFAC) intensified enforcement after the February 2022 invasion of Ukraine and expanded the Specially Designated Nationals list repeatedly through 2025.

Screening once at onboarding is not enough. Sanctions lists change weekly, and a vendor that was clean at contract signature may be designated later. Continuous monitoring, either through a TPRM platform or a service like Refinitiv World-Check or LexisNexis Bridger, is the current standard of care.

Domain 5: Operational resilience

Operational resilience due diligence tests whether the vendor can maintain service through disruption. This domain now carries its own regulatory floor in the EU (DORA), in UK financial services (PRA and FCA operational resilience rules effective March 2025), and by supervisory expectation across U.S. banking regulators.

The 2024 CrowdStrike Falcon sensor incident on July 19, 2024, which grounded thousands of flights and disrupted hospitals globally, made concentration risk unmistakable. When one endpoint security vendor pushed a bad configuration file, the outage propagated across every customer running the affected sensor version simultaneously. Delta Air Lines disclosed $500M in losses tied to the outage in its Q3 2024 earnings. Vendor DD in 2026 explicitly asks about single-vendor dependency and the buyer’s ability to failover.

Domain 6: ESG and reputational

Environmental, social, and governance due diligence has moved from “nice to have” to a compliance floor for large enterprises operating in the EU under the Corporate Sustainability Reporting Directive (CSRD), which applied to large listed companies for financial years starting January 1, 2024 and cascades to their vendors through the value-chain reporting requirement.

ESG DD is not universally applicable. Small domestic vendors serving a private company have essentially no ESG reporting obligation. A large European bank buying from a global software vendor has significant obligation to collect CSRD-aligned disclosures. Calibrate the depth to the buyer’s own reporting perimeter.

Domain 7: Concentration and geography

Concentration due diligence maps how much of the buyer’s operation depends on one vendor, and how much of that vendor’s own operation depends on politically or economically fragile jurisdictions. This is the domain most likely to be skipped and most likely to bite during a geopolitical event.

Concentration risk has a M&A angle too. A target company that runs 90% of its production workload on one vendor is worth marginally less to a rational buyer, because the buyer inherits both the dependency and the switching cost. Concentration also shapes the net working capital adjustment when a target has committed spend to a vendor that will not survive change of control.

Tiering vendors by risk

Vendor tiering assigns each supplier a risk level (typically critical, high, medium, low) that determines the depth of due diligence and the frequency of re-review. Tiering is the operational bridge between “we have hundreds of vendors” and “we cannot run the same diligence on all of them.”

Tier Definition DD depth Re-attestation Board reporting
Critical (Tier 1) Loss of service materially impairs revenue or safety within 24 hours Full seven-domain review, on-site or virtual site visit Annual plus continuous monitoring Named on board vendor register
High (Tier 2) Handles regulated data or sensitive IP but not immediately business-halting Full seven-domain review, questionnaire based Annual Aggregated in risk committee reporting
Medium (Tier 3) Operational relevance but replaceable inside 30 days Financial, legal, compliance domains Every 18 to 24 months Sampled in reporting
Low (Tier 4) Commodity vendor, minimal data, low spend Sanctions screen plus basic financial check Every 24 to 36 months Excluded from routine reporting

Tiering criteria commonly combine four inputs: annual spend, business-criticality (measured in maximum tolerable disruption), data sensitivity (regulated, confidential, public), and access privilege (does the vendor sit inside the network). A vendor that scores high on any single input escalates to a higher tier regardless of the other three.

Questionnaires and evidence artifacts

Vendor due diligence questionnaires collect standardized evidence at scale. The industry has consolidated around three widely accepted templates, plus a growing set of platform-native alternatives.

Evidence artifacts to request alongside the questionnaire:

  1. Most recent SOC 2 Type II report
  2. ISO 27001 certificate and Statement of Applicability
  3. Penetration test executive summary
  4. Business continuity plan and last test results
  5. Cyber liability insurance certificate
  6. Financial statements for the last two fiscal years
  7. Anti-bribery and modern slavery policy
  8. Sub-processor list
  9. Data flow diagram
  10. Named privacy and security contacts

Requesting the artifacts and never reading them is common and pointless. A defensible program has a documented reviewer, a scoring rubric, and a residual risk register that carries any unresolved finding into ongoing monitoring.

The 2026 regulatory floor

Vendor due diligence in 2026 has to satisfy a growing set of specific rules with named effective dates. The regulatory floor is no longer voluntary framework alignment; it is a compliance requirement with real penalties for miss.

Regulation Effective date Scope Vendor DD implication
SEC Cybersecurity Disclosure Rule December 18, 2023 U.S. public companies Material cyber incidents at vendors that flow through to the registrant require 8-K Item 1.05 disclosure within four business days
NIS2 Directive Transposition deadline October 17, 2024 EU essential and important entities Article 21 requires supply chain security including third-party risk assessment
DORA (Digital Operational Resilience Act) Applicable January 17, 2025 EU financial entities and their ICT third-party providers Mandatory register of ICT third-party arrangements, exit strategies, and pre-contractual assessment
PCI DSS 4.0.1 Published June 2024, future-dated requirements effective March 31, 2025 Any entity processing payment card data Third-party service providers must comply with applicable requirements
CMMC 2.0 Final Rule Published October 15, 2024, phased 2025 onward Department of Defense contractors handling CUI Vendors must be certified at required level; primes verify subcontractors
UK Operational Resilience (PRA SS1/21, FCA PS21/3) Full compliance from March 31, 2025 UK banks, insurers, investment firms Impact tolerances must include third-party dependencies
EU AI Act Entered force August 1, 2024, phased application through 2027 Providers and deployers of AI systems High-risk AI vendors must supply conformity assessments; deployers must monitor
HIPAA Security Rule proposed update Notice of Proposed Rulemaking published January 6, 2025 Covered entities and business associates Business associate agreements would need stronger verification and encryption obligations if finalized

Two of these deserve highlighting. DORA is the first EU regulation to impose supervisory oversight on critical ICT third-party providers directly, meaning a large cloud vendor serving EU banks now faces European supervisory scrutiny even if headquartered in the U.S. The SEC rule created the first named-form disclosure obligation for vendor-originated cyber incidents at U.S. public companies, which turned vendor cyber DD from a private matter into a securities compliance issue.

Vendor due diligence inside M&A transactions

Vendor due diligence in an M&A transaction is a distinct workstream that runs alongside financial, tax, and legal DD. The buyer needs to know every vendor obligation that survives closing, every contract that terminates on change of control, and every renewal that falls due before integration completes.

What the buyer’s DD list should include

Contract clauses that need special attention

Change of control clauses are the most consequential term the acquirer inherits. Some contracts terminate automatically on change of control; some require consent; some contain a price reset or a most-favored-nation clause that resets the terms. The buyer’s counsel should produce a change-of-control schedule that flags every affected contract, quantifies the exposure, and identifies whether consent must be obtained before signing or before closing.

Assignment provisions matter equally. In an asset deal (as opposed to a stock deal or reverse triangular merger), vendor contracts do not automatically transfer to the buyer; they must be assigned. Vendors sometimes withhold assignment consent as leverage to renegotiate terms. Deal teams working with an experienced M&A advisor raise assignment mechanics during structure selection, not after signing.

Post-close vendor integration

The first 100 days after closing are when vendor DD failures surface. Common post-close problems include duplicate vendors across acquirer and target that create leverage for consolidation and price reduction, contracts that trigger price escalation on change of control, and shadow IT vendors nobody at the target disclosed during DD because the CFO did not know they existed. A named vendor consolidation workstream inside the integration management office catches most of this inside 90 days.

Vendor DD platforms and pricing

Vendor risk management platforms automate questionnaire distribution, evidence collection, scoring, and continuous monitoring. The market has consolidated around a small group of enterprise vendors and a longer tail of specialists. Pricing is a mix of platform license and per-vendor consumption; expect noticeable variation depending on module coverage, integrations, and negotiated minimums.

Platform Owner Positioning Indicative annual price range
OneTrust Third-Party Management OneTrust, LLC Enterprise breadth; ties into privacy and GRC $50,000 to $500,000+
ProcessUnity ProcessUnity, Inc. Enterprise TPRM plus policy management $60,000 to $400,000+
Prevalent (a Mitratech company since June 2024) Mitratech Holdings, Inc. Assessment plus continuous monitoring $40,000 to $300,000+
ServiceNow Vendor Risk Management ServiceNow, Inc. Native ServiceNow integration for existing customers Priced inside ServiceNow subscription
Archer (RSA) Cinven / Archer Technologies Long-established GRC platform $60,000 to $400,000+
SecurityScorecard SecurityScorecard, Inc. Outside-in security ratings for continuous monitoring $25,000 to $200,000+
Bitsight Moody’s Corporation (acquisition announced August 2024, closed 2025) Outside-in security ratings; strong in financial services $30,000 to $250,000+
UpGuard UpGuard, Inc. Attack surface and vendor risk hybrid $20,000 to $150,000+

Prices above are indicative ranges observed across public case studies and negotiated proposals in the U.S. market during 2024 and early 2025; actual pricing depends on vendor count, module selection, integration scope, and multi-year commitments. Buyers routinely reduce total spend 20% to 35% by consolidating GRC and TPRM onto a single platform, according to Gartner Peer Insights user reviews aggregated through 2024.

Ongoing monitoring and remediation

Vendor due diligence at onboarding is a snapshot. Ongoing monitoring converts that snapshot into a moving picture that catches vendor drift before it becomes an incident. Modern programs combine four monitoring streams.

Remediation turns monitoring alerts into action. A defensible workflow has a named risk owner, a documented root cause analysis for each finding, a remediation plan with a target date, and an exception process for accepted residual risk that survives past the plan date. Findings that sit open for more than 90 days should escalate automatically.

How often to re-attest each tier

Re-attestation cadence should match the risk tier, not calendar convenience. Tier 1 critical vendors get annual full re-attestation supplemented by continuous outside-in monitoring and quarterly financial-signal review. Tier 2 high-risk vendors get annual questionnaire refresh, focused on cyber, compliance, and any newly-identified sub-processors. Tier 3 medium-risk vendors run on an 18 to 24 month cadence, with material change events (new service scope, ownership change, incident) collapsing the timeline. Tier 4 low-risk vendors get a lightweight sanctions and credit refresh every 24 to 36 months. Any vendor that misses a re-attestation window past 60 days should escalate to the risk committee, and any vendor whose risk score materially worsens between windows should be re-tiered immediately rather than waiting for the next scheduled cycle.

The offboarding workflow that most programs skip

Vendor offboarding is the domain that closes the loop and where documented gaps most often surface during audit. A clean offboarding workflow revokes system access within 24 hours of termination, retrieves or destroys any regulated data with a signed destruction certificate, closes open change tickets, terminates payment authorizations, and archives the vendor file for the applicable record retention period (commonly seven years for financial records, longer for healthcare BAAs). Programs that skip offboarding accumulate a long tail of dormant vendor accounts with residual access, which is exactly the population that later shows up in an audit finding or a post-breach forensic report.

Red flags that should stop the engagement

Some findings are severe enough to stop the vendor onboarding rather than remediate around. Every mature program maintains a list of “do not proceed” triggers reviewed by the risk committee.

None of these mean the vendor is unusable in every context. A small vendor without SOC 2 might be acceptable for a low-tier commodity purchase. The point is that a “yes” from procurement does not automatically override the risk committee, and a documented exception process is essential when the answer is nuanced.

Common vendor DD mistakes and how to avoid them

Programs fail in predictable ways. The most common mistake is questionnaire theater: the vendor completes 850 SIG questions, the buyer’s team files the response, and nobody scores or challenges the answers. A defensible program samples responses, requests supporting evidence, and reconciles the questionnaire against the SOC 2 report line by line where the two overlap. Where the questionnaire and the SOC 2 disagree, the SOC 2 wins because it carries auditor attestation.

The second common mistake is one-time onboarding with no ongoing monitoring. The vendor was clean in March, and by December it has been acquired, the CFO has left, and the SOC 2 opinion has been qualified. Continuous monitoring is not optional for Tier 1 or Tier 2 populations. Even for Tier 3, event-triggered re-review (breach notification, change in ownership, service scope expansion) catches drift the annual cycle misses.

The third mistake is treating vendor DD as a procurement gate rather than a risk decision. Procurement enforces process; the risk committee owns the accept-or-reject decision. Programs that let procurement close out findings without risk sign-off routinely end up with a stack of accepted exceptions that would have been rejected on independent review. A named committee, quarterly meetings, and a documented delegation of authority to accept residual risk (with dollar and severity limits) close this gap.

Where CT Acquisitions fits

Vendor due diligence sits inside the broader diligence exercise that runs during any acquisition or exit. Buyers under-invest in vendor DD because it looks operational; sellers under-prepare vendor DD because the population is scattered across procurement, IT, and legal. That gap becomes a valuation discount when a buyer’s counsel finds a change-of-control landmine two weeks before signing.

CT Acquisitions works with owners of $5M to $50M enterprise value businesses on sell-side and buy-side engagements. Our diligence workstream includes a vendor register review before we hit the market, so the change-of-control schedule, renewal cliffs, and IP-dependency map are ready when a buyer’s counsel starts pulling threads. That preparation preserves value that would otherwise vanish inside a working capital or indemnification negotiation. For sellers running a process, we co-ordinate the vendor DD pack alongside quality-of-earnings, so the deal room is complete before buyers arrive.

Schedule a 30-minute exit-readiness call at ctacquisitions.com/contact-us/ if you want a candid read on how your vendor exposure will look to a private equity buyer.

Frequently Asked Questions

What are the 4 Cs of vendor due diligence?

The 4 Cs of vendor due diligence are commonly rendered as capacity, capability, character, and controls. Capacity tests financial and operational scale, capability tests service delivery, character tests reputation and ethical posture (sanctions, adverse media, litigation), and controls tests the vendor’s internal control environment (SOC 2, ISO 27001, policy maturity). Some frameworks substitute compliance or cost for character.

What should a vendor due diligence checklist include?

A vendor due diligence checklist should include seven evidence domains: financial statements and credit reports, cybersecurity attestations (SOC 2 Type II, ISO 27001, penetration test), legal contract review, compliance and sanctions screening, business continuity and insurance evidence, ESG and reputational search, and concentration analysis. Each domain gets a scoring rubric, an evidence artifact list, and a documented reviewer with sign-off authority.

How long does vendor due diligence take?

Onboarding due diligence for a Tier 1 critical vendor typically takes four to eight weeks from questionnaire distribution to signed exception register, assuming the vendor responds inside standard SLAs. Tier 3 medium-risk vendors close in two to four weeks. Rush timelines shorter than two weeks force reviewers to accept documentation gaps and typically produce weaker residual risk conclusions.

How much does vendor due diligence cost?

Vendor due diligence platform costs typically range from about $25,000 per year for a lean SMB deployment on outside-in monitoring to more than $500,000 per year for a full enterprise TPRM suite. Sell-side vendor due diligence reports commissioned by a seller from a Big Four accounting firm generally run $150,000 to more than $2M depending on transaction size and scope. Standalone third-party assessments by consultants sit in a lower $5,000 to $25,000 per vendor band.

What is the difference between vendor due diligence and vendor risk management?

Vendor due diligence is the pre-engagement or pre-transaction assessment that produces a decision (proceed, proceed with conditions, do not proceed). Vendor risk management is the ongoing program that manages the population of accepted vendors across their lifecycle, including monitoring, re-attestation, incident response, and offboarding. Due diligence is an event; risk management is a discipline.

Do small businesses need to run vendor due diligence?

Small businesses need vendor due diligence sized to their risk exposure, not enterprise-scale programs. A five-employee company selling regulated services still owes its clients diligence on any subcontractor handling client data, and its own customers may impose flow-down obligations through contract. A useful minimum is sanctions screening, cyber insurance verification, and a one-page questionnaire covering data handling and business continuity for any vendor with system access.

What is a SIG questionnaire?

The Standardized Information Gathering questionnaire, maintained by Shared Assessments, is the most widely used third-party risk questionnaire in North America. SIG Core has approximately 850 questions across 21 risk domains including cybersecurity, privacy, business continuity, and compliance. SIG Lite is a shorter version with roughly 130 questions used for lower-tier vendors or initial screening.

What is the SEC cybersecurity disclosure rule and how does it affect vendor due diligence?

The SEC Cybersecurity Disclosure Rule, effective December 18, 2023, requires U.S. public companies to disclose material cybersecurity incidents on Form 8-K Item 1.05 within four business days of determining materiality. Because vendor breaches can constitute material incidents at the registrant, public company vendor DD now requires named incident notification clauses, defined materiality thresholds, and documented processes for capturing vendor-originated incidents inside the corporate disclosure workflow.

Sources and further reading

  1. U.S. Securities and Exchange Commission, “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure,” Final Rule, July 26, 2023 (effective December 18, 2023). https://www.sec.gov/rules/final/2023/33-11216.pdf
  2. European Parliament and Council, Regulation (EU) 2022/2554 (DORA), applicable January 17, 2025. https://eur-lex.europa.eu/eli/reg/2022/2554/oj
  3. European Parliament and Council, Directive (EU) 2022/2555 (NIS2), transposition deadline October 17, 2024. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
  4. PCI Security Standards Council, PCI DSS v4.0.1, published June 2024. https://www.pcisecuritystandards.org/
  5. U.S. Department of Defense, CMMC 2.0 Final Rule, published October 15, 2024, 32 CFR Part 170. https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program
  6. Bank of England Prudential Regulation Authority, SS1/21 Operational Resilience, full compliance by March 31, 2025. https://www.bankofengland.co.uk/prudential-regulation/publication/2021/march/operational-resilience-impact-tolerances-for-important-business-services-ss
  7. Financial Conduct Authority, PS21/3 Building Operational Resilience. https://www.fca.org.uk/publications/policy-statements/ps21-3-building-operational-resilience
  8. Regulation (EU) 2024/1689 on artificial intelligence (EU AI Act), Official Journal July 12, 2024. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  9. U.S. Department of Health and Human Services, HIPAA Security Rule NPRM, Federal Register January 6, 2025. https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
  10. Corporate Sustainability Reporting Directive (Directive (EU) 2022/2464). https://eur-lex.europa.eu/eli/dir/2022/2464/oj
  11. NIST SP 800-171 Rev. 3, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” May 2024. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.pdf
  12. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Information Systems and Organizations.” https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
  13. Shared Assessments, “Standardized Information Gathering (SIG) Questionnaire.” https://sharedassessments.org/sig/
  14. Cloud Security Alliance, “Consensus Assessments Initiative Questionnaire (CAIQ) v4.” https://cloudsecurityalliance.org/research/cloud-controls-matrix/
  15. Cloud Security Alliance STAR Registry. https://cloudsecurityalliance.org/star/
  16. AICPA, “SOC 2 Reporting on an Examination of Controls at a Service Organization.” https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/aicpasoc2report.html
  17. ISO/IEC 27001:2022, “Information security, cybersecurity and privacy protection Information security management systems Requirements.” https://www.iso.org/standard/27001
  18. IBM and Ponemon Institute, “Cost of a Data Breach Report 2024,” July 30, 2024. https://www.ibm.com/reports/data-breach
  19. U.S. Office of Foreign Assets Control, Specially Designated Nationals and Blocked Persons List. https://ofac.treasury.gov/specially-designated-nationals-and-blocked-persons-list-sdn-human-readable-lists
  20. U.S. Office of Foreign Assets Control, Consolidated Screening List. https://www.trade.gov/consolidated-screening-list
  21. UK Office of Financial Sanctions Implementation, Consolidated List. https://www.gov.uk/government/publications/financial-sanctions-consolidated-list-of-targets
  22. United Nations Security Council Consolidated Sanctions List. https://main.un.org/securitycouncil/en/content/un-sc-consolidated-list
  23. U.S. Department of Justice, “A Resource Guide to the U.S. Foreign Corrupt Practices Act,” Second Edition, July 2020. https://www.justice.gov/criminal/criminal-fraud/file/1292051/download
  24. UK Bribery Act 2010. https://www.legislation.gov.uk/ukpga/2010/23/contents
  25. UK Modern Slavery Act 2015. https://www.legislation.gov.uk/ukpga/2015/30/contents
  26. Delta Air Lines, Third Quarter 2024 Earnings Release, October 10, 2024. https://ir.delta.com/
  27. Emsisoft, MOVEit tracker, updated through 2024. https://www.emsisoft.com/en/blog/44123/moveit-a-massive-blow-to-trust-in-the-file-transfer-ecosystem/
  28. Gartner, “Manage Third-Party Cybersecurity Risk,” 2024 research note.
  29. Fitch Ratings, “U.S. Leveraged Loan Default Rate,” December 2024 update. https://www.fitchratings.com/
  30. Shared Assessments Program Third-Party Risk Management. https://sharedassessments.org/
  31. ISACA, “IT Audit and Assurance Guideline on Third-Party Risk.” https://www.isaca.org/
  32. Federal Financial Institutions Examination Council, “Outsourcing Technology Services Booklet.” https://ithandbook.ffiec.gov/it-booklets/outsourcing-technology-services/
  33. Office of the Comptroller of the Currency, Bulletin 2023-17 “Third-Party Relationships: Interagency Guidance on Risk Management,” June 6, 2023. https://www.occ.gov/news-issuances/bulletins/2023/bulletin-2023-17.html
  34. Financial Stability Board, “Enhancing Third-Party Risk Management and Oversight,” December 2023. https://www.fsb.org/2023/12/
  35. Basel Committee on Banking Supervision, “Principles for the sound management of third-party risk,” July 2024. https://www.bis.org/bcbs/publ/d573.htm
  36. CrowdStrike Falcon sensor incident review, July 2024. https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
  37. U.S. Treasury Financial Crimes Enforcement Network, Corporate Transparency Act Beneficial Ownership Information. https://www.fincen.gov/boi

Leave a Reply

Your email address will not be published. Required fields are marked *