One supplier record. Every regulation that references it.
Vendor risk is typically assessed once at contract signing and rarely revisited — while NIS2 Art. 21(2)(d) and DORA's ICT third-party chapter both expect continuous oversight. A questionnaire in a drawer is not oversight.
TruSecure maintains one continuous supplier risk register that feeds every regulation referencing supplier or third-party risk simultaneously. One supplier, one record, every regime that cares about that supplier reading from the same page.
How it works
- Register
Every supplier gets one record: the services it provides, the data it touches, the criticality of what depends on it.
- Assess
Inherent risk is scored from what the supplier is to you — not from a generic questionnaire template — and reassessed on a cycle matched to criticality.
- Monitor
Certification status, contract and SLA data, and assessment outcomes stay current through the year, connected where a TPRM system already exists.
- Feed every regime
NIS2’s supply-chain clause, DORA’s third-party register, ISO 27001’s supplier controls — each reads the same record. Assess the supplier once; answer every framework.
What a supplier record looks like
{
"supplier": "cloud hosting provider",
"services": ["iaas", "backup"],
"criticality": "high",
"cites": ["NIS2 21(2)(d)",
"DORA Art. 28", "ISO A.5.19"],
"assessment": {
"status": "current",
"next review": "2026-12-01"
}
}Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Supply-chain security as a risk-management measure | Art. 21(2)(d) |
| DORA | A register of ICT third-party arrangements, maintained | Art. 28 |
| ISO 27001 | Supplier relationship controls, defined and operating | A.5.19–5.22 |
Already running a TPRM or vendor-risk tool? TruSecure's supplier and TPRM connectors pull assessments, contract data and certification status from it — the register enriches what you have rather than replacing it.
