Recommended Free Tools
Assess a vendor by what your organization depends on it to do, what it can access, and the consequences if it fails or is compromised—not by how many people it employs. Headcount can describe a company, but it does not establish whether its controls, continuity plans, or subcontractor oversight are adequate for your particular relationship.
Start with the service and its consequences
Before judging the vendor, define the relationship. Record what the provider will do, which business service relies on it, what information it will handle, what systems or accounts it can access, and what could happen if its service stopped or produced incorrect results. This context determines which risks matter and how much evidence is reasonable to request.
NIST describes due diligence as research used to make informed decisions about a supplier or product, including for new acquisitions and existing systems. Its SP 1326 guide, published July 8, 2026, applies its detailed assessment to information and communications technology (ICT) suppliers, while noting that due diligence can apply to any supplier. For non-technology providers, adapt the activity-specific approach rather than treating ICT controls as universal requirements.
Match the depth of review to the risk
Use a basic review of public information as an initial screen, then spend more time on relationships with greater potential consequences, sensitive data, substantial system access, or significant uncertainty. NIST SP 1326 distinguishes basic public-information research from enhanced diligence and frames due diligence as minimum reasonable research—not an identical checklist for every supplier. The appropriate depth depends on what the service does and what is at stake if it goes wrong.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Evaluate evidence that is relevant to the service
For an ICT vendor, NIST SP 1326 organizes due diligence around five components. For each, identify what evidence is available, its date and scope, what remains unknown, and whether it applies to the product or service being considered.
Ownership, control, or influence
Consider foreign ownership, control, or influence (FOCI) where it is relevant to the service, data, or applicable obligations. The point is to understand whether ownership or influence could affect the relationship—not to treat a company’s location or size as a stand-in for that analysis.
Rank #2
Provenance
Look at the origin and relevant history of the product or service. Ask whether the available information gives you enough visibility into what you are acquiring and whether its provenance raises concerns for this use.
Resilience
Assess whether the provider can continue or restore the activity after disruption. Consider continuity and disaster-recovery arrangements alongside the recovery expectations your organization needs from this specific service.
Rank #3
Foundational cybersecurity practices
Review evidence of security practices that bear on the vendor’s role and access. Check what the evidence covers and when it was produced; a general statement about security is not automatically evidence about the service or environment you will rely on.
Supply-chain tiers
Identify whether important functions depend on subcontractors or deeper supply-chain tiers, and what visibility the vendor can provide into those dependencies. A provider’s own assurances may not answer questions about a service component delivered by another party.
NIST SP 1326 is based on the broader approach in NIST SP 800-161 Rev. 1, which addresses cybersecurity supply-chain risk management and assessment for products and services.
Check continuity, dependencies, and accountability
Consider whether the vendor can keep the activity running or restore it after disruption, and whether critical functions rely on subcontractors. The U.S. Interagency Guidance on Third-Party Relationships discusses operational resilience, cybersecurity, disaster recovery, and business continuity; NIST SP 1326 includes resilience and supply-chain tiers. The interagency guidance is directed to banking organizations, so its regulatory requirements should not be assumed to apply universally. Its activity-specific due-diligence principle is useful more broadly: familiarity with a provider does not replace an assessment.
Best Value
Before proceeding, clarify contractual responsibilities, available remedies, and who in your organization owns unresolved gaps or accepted risk. Contract terms do not erase operational risk, but they help make responsibilities and responses explicit.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Compare alternatives using the same criteria
If there are genuine vendor alternatives, assess each against the same relationship-specific axes. This makes trade-offs visible without turning headcount into a score.
- Fit for the activity and the consequences of service failure.
- Data sensitivity, system access, and exposure created by the service.
- Evidence of relevant security practices, including the evidence’s scope and date.
- Resilience, continuity, disaster recovery, and recovery expectations.
- Ownership, control, influence, and provenance concerns where applicable.
- Subcontractors, supply-chain tiers, and visibility into dependencies.
- Contractual responsibilities, available remedies, and unresolved gaps.
Record the decision and keep it current
Keep a supplier assessment record that allows someone else to understand the decision later. NIST SP 800-161 Rev. 1 includes supplier profile information and calls out assessment dates and findings over time.
- Describe the service, its business purpose, relevant data, system access, and consequences of interruption or error.
- Record the sources reviewed, dates, scope of evidence, and material unknowns.
- Document identified risks, mitigations, accountable owners, and any accepted residual risk.
- Set a review cadence appropriate to the relationship and revisit the assessment when material facts change.
Requirements vary by sector, jurisdiction, and the organization’s status; these sources do not establish a universal legal checklist. Banking organizations should consult the applicable interagency guidance. Other organizations should identify the obligations that govern their own activities.
Free tools Windows power users keep installed
One-click scans. No signup required.
Use headcount as context, not as the verdict
NIST’s sample supplier assessment record includes company size among profile details such as legal name, domicile, company-family structure, years in business, and market segment. That placement makes size descriptive context, not a demonstrated measure of security quality or relationship risk. A vendor’s size may help identify the organization, but the decision should turn on the actual exposure, consequence, relevant practices, resilience, and dependencies. Neither smallness nor scale, by itself, proves that a vendor is safer or riskier.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




