Skip to content

Vendor Due Diligence

Definition

The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due diligence includes reviewing the supplier's SBOM, secure development practices, incident response capability, and subcontractor controls.

Field
Supply-chain and third-party cyber risk management
Reviewed items
SBOM, secure development practices, incident response capability
Timing
Pre-procurement and ongoing through the relationship
Extends to
Subcontractor and fourth-party controls

Common questions

Why does due diligence need to continue after a vendor is already onboarded?+

A vendor's security posture can change after signing, through staff turnover, new subprocessors, or an undisclosed breach, so a point-in-time assessment at procurement does not guarantee the same risk level a year later. Ongoing reviews and reassessment triggers catch that drift.

Why is a vendor's SBOM specifically relevant to due diligence rather than just their policies?+

A Software Bill of Materials lists the third-party and open-source components inside a vendor's product, which lets the assessing organisation check those components against known vulnerabilities directly, rather than relying solely on the vendor's self-reported security claims.

Related terms

Dependency Confusion
An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
NIST SP 800-161R1
The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
Software Bill of Materials (SBOM)
A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
Software Composition Analysis (SCA)
A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
Transitive Dependency
A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.