One supplier record. Every regulation that references it.
Vendor risk is typically assessed once at contract signing and rarely revisited — while NIS2 Art. 21(2)(d) and DORA's ICT third-party chapter both expect continuous oversight. A questionnaire in a drawer is not oversight.
TruSecure maintains one continuous supplier risk register that feeds every regulation referencing supplier or third-party risk simultaneously. One supplier, one record, every regime that cares about that supplier reading from the same page.
How it works
- Register
Every supplier gets one record: the services it provides, the data it touches, the criticality of what depends on it.
- Assess
Inherent risk is scored from what the supplier is to you — not from a generic questionnaire template — and reassessed on a cycle matched to criticality.
- Monitor
Certification status, contract and SLA data, and assessment outcomes stay current through the year, connected where a TPRM system already exists.
- Feed every regime
NIS2’s supply-chain clause, DORA’s third-party register, ISO 27001’s supplier controls — each reads the same record. Assess the supplier once; answer every framework.
What a supplier record looks like
- Services
- IaaS · backup
- Criticality
- high
- Citations
- NIS2 21(2)(d) · DORA Art. 28 · ISO A.5.19
- Assessment
- current
- Next review
- 2026-12-01
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Supply-chain security as a risk-management measure | Art. 21(2)(d) |
| DORA | A register of ICT third-party arrangements, maintained | Art. 28 |
| ISO 27001 | Supplier relationship controls, defined and operating | A.5.19–5.22 |
Already running a TPRM or vendor-risk tool? TruSecure's supplier and TPRM connectors pull assessments, contract data and certification status from it — the register enriches what you have rather than replacing it.
When a supplier changes — a certificate lapses, a sub-processor is added, a disclosed incident lands — the register changes with it, and every regime reading that supplier sees the new state at once. There is no second register to update, and no quarter in which the answer quietly goes stale.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.