What this tool is for
A new vendor can improve an office’s efficiency while also introducing a new pathway to sensitive information, administrative access, payment data, or business operations. The risk is not limited to technology companies. It can arise with payroll providers, bookkeeping firms, answering services, document platforms, website agencies, copier providers, remote support companies, and cloud applications.
CISA provides small and medium-sized businesses with vendor supply-chain risk management guidance and a template for assessing vendors and suppliers. The questions below are a shorter management tool for a first review. It is not a certification, audit, penetration test, legal review, or guarantee that a vendor is safe.
Use it before signing, before granting access, and again when the service changes materially.
How to use the worksheet
- Ask the vendor to answer in writing.
- Mark each response Complete, Partial, Unclear, or Not Applicable.
- Request evidence for important claims.
- Assign an internal business owner.
- Record unresolved items and who accepted the risk.
- Revisit the review at renewal or after a major change.
Do not award a vendor a favorable rating merely because it has a familiar name or attractive security language. The question is whether the service’s controls and contract terms match the business’s actual risk.
Section 1: Business need and information
1. What business process will the vendor support?
Write the process in operational terms, such as payroll, scheduling, billing, document exchange, remote support, or customer communications. This helps prevent purchasing a broad service when a narrower one would meet the need.
2. What information will the vendor receive, create, or access?
List categories rather than vague labels. Examples include employee records, patient information, financial account details, customer contact information, tax documents, credentials, confidential agreements, or internal procedures.
3. Is the vendor allowed to use the information for its own purposes?
Ask whether data is used for analytics, advertising, product improvement, artificial-intelligence training, resale, or other secondary purposes. If the answer is unclear, have the contract reviewed before proceeding.
4. Where is the information stored and processed?
Request the relevant locations and hosting arrangements. The answer may affect contractual, privacy, customer, or regulatory obligations.
Section 2: Access and authentication
5. What access does the vendor need?
Separate ordinary user access from administrative access. Document the systems, roles, permissions, support channels, and expected duration.
6. Can access be limited by role, time, location, or approval?
A vendor should not receive permanent broad access if a narrower or time-limited method is available.
7. Is multifactor authentication required for vendor personnel?
Ask whether it applies to all accounts, privileged users, support access, and subcontractors. Also ask whether the vendor supports phishing-resistant methods where appropriate.
8. How are vendor employees and subcontractors removed?
The vendor should be able to explain how it disables access after personnel changes, contract termination, or loss of business need.
Section 3: Protection and monitoring
9. How are devices and systems updated?
Ask how the vendor handles security updates, unsupported software, vulnerability prioritization, and emergency fixes. Avoid accepting “we patch regularly” without understanding the process.
10. How is sensitive information protected in transit and at rest?
Request a plain-language explanation of encryption and key management. If the vendor cannot answer, identify the resulting uncertainty before approval.
11. What security events are logged?
Ask whether the vendor records sign-ins, administrative activity, data exports, configuration changes, and support actions. Ask how long logs are retained and whether the customer can obtain relevant records.
12. Does the vendor use subcontractors or additional service providers?
Identify providers that can access the business’s information or systems. Ask how they are evaluated and how changes are communicated.
Section 4: Incidents and continuity
13. What happens if the vendor suspects unauthorized access?
The answer should identify investigation, containment, customer notification, evidence preservation, and communication responsibilities. “We will notify you promptly” may need a defined timeframe in the contract.
14. What support is available during an incident?
Record support hours, emergency contacts, escalation levels, and whether incident assistance costs extra.
15. How is the service backed up?
Ask what is backed up, how often, how backups are protected from unauthorized alteration, and how restoration is tested. A vendor’s statement that it has backups does not prove that the business can recover its data in a usable form.
16. How can the business recover or export its information?
Document export formats, fees, turnaround times, dependencies, and assistance available after termination. Test a small export before the business becomes dependent on the platform.
Section 5: Contract and exit
17. What security commitments are written into the agreement?
Review confidentiality, access control, incident notification, data return or deletion, subcontractors, audit or evidence rights, service availability, support, and responsibility allocation. Security claims on a sales page should not be treated as contract terms unless incorporated into the agreement.
18. What is the exit plan?
Record who owns the data, how access will be revoked, how credentials or tokens will be rotated, how devices will be returned, how data will be deleted, and how the office will continue operating during transition.
Decision record
After completing the questions, record:
- Vendor name and service.
- Internal business owner.
- Systems and information involved.
- Access level requested.
- Responses requiring evidence.
- Open risks and compensating controls.
- Contract provisions still under review.
- Approval authority.
- Review or renewal date.
A “Partial” response is not automatically a rejection. It is a prompt to decide whether the gap is acceptable, whether the vendor can provide an alternative, or whether the business should reduce the data or access provided.
When to stop and escalate
Pause the purchase or seek specialized advice when a vendor:
- Requests unrestricted administrator access without a clear reason.
- Cannot explain who can access the business’s information.
- Refuses to describe incident notification practices.
- Offers no workable data export or termination process.
- Uses vague security claims but will not provide written commitments.
- Will process regulated or highly sensitive information without clear contractual protections.
CISA’s vendor guidance identifies physical or logical access, cloud-hosted solutions, and managed service providers as important small-business use cases. Those categories cover many ordinary office purchases, so vendor review should be part of procurement rather than a one-time compliance exercise.
Final practical test
Before approval, ask: If this vendor were unavailable tomorrow, compromised next month, or terminated next year, could the office explain what happens next?
If the answer is no, the business has not finished the intake. It may still choose the vendor, but it should do so with the uncertainty documented and the recovery path improved.
Human-reviewed draft. This checklist is general information and should be adapted with qualified legal, privacy, insurance, or technical advice when the service involves sensitive or regulated information.

