Vendor Due Diligence
Definition
The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due diligence includes reviewing the supplier's SBOM, secure development practices, incident response capability, and subcontractor controls.
- Field
- Supply-chain and third-party cyber risk management
- Reviewed items
- SBOM, secure development practices, incident response capability
- Timing
- Pre-procurement and ongoing through the relationship
- Extends to
- Subcontractor and fourth-party controls
Common questions
Why does due diligence need to continue after a vendor is already onboarded?+
A vendor's security posture can change after signing, through staff turnover, new subprocessors, or an undisclosed breach, so a point-in-time assessment at procurement does not guarantee the same risk level a year later. Ongoing reviews and reassessment triggers catch that drift.
Why is a vendor's SBOM specifically relevant to due diligence rather than just their policies?+
A Software Bill of Materials lists the third-party and open-source components inside a vendor's product, which lets the assessing organisation check those components against known vulnerabilities directly, rather than relying solely on the vendor's self-reported security claims.
Related terms
- Dependency Confusion
- An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
- NIST SP 800-161R1
- The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
- Software Bill of Materials (SBOM)
- A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
- Software Composition Analysis (SCA)
- A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
- Transitive Dependency
- A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...