| Asset inventory | "We maintain an inventory of our internet-facing assets and review it quarterly." | Every hostname answering from the public internet across the apex domains you nominate, with the service and software version behind it, and whether an administrative interface is reachable with no second factor in front of it. | An inventory obligation with a named refresh interval. An administrative interface answering unprotected becomes a disclosure the supplier makes before signature. | Attack Surface Management |
| Apex domains are the only input. The estate resolved here is what every row below is attributed against. Everything in the assessment was discovered and attributed to this supplier first. |
| Credential hygiene | "Credentials are rotated on a schedule and are never reused across services." | Records attributed to the supplier domains in stealer-log and breach material, including how many entered the corpus in the preceding 90 days. That measures when you could have known, not when the supplier got round to saying so. | A rotation obligation discharged before any account is issued on your systems, and a notification clause written against a dated fact. | Dark Web Monitoring |
| Records on a candidate estate arrive observed and untested: we hold authorisation over your estate, not over a company you have not signed, and nothing on a supplier system is probed. Where an exposed identity maps to an account you are about to issue — a contractor remote-access portal, a shared tenancy — that account is your estate, and it is testable under your own authorisation once it exists. |
| Secrets and source control | "Secrets are never committed to source control, and our repositories are private." | Code, configuration and credential material published under the supplier name or by identifiable staff accounts, correlated back to the estate in the first row so a genuine leak can be told apart from a name collision. | A secrets-handling obligation that names the repositories in question, and, where key material was published, a rotation the supplier performs before the integration is built. | Data Exposure Monitoring |
| Publication is observable. Whether a published key still opens anything is a separate fact, and on a candidate estate it is one we deliberately do not establish, because establishing it would mean using the key. |
| Sub-processors | "Our sub-processors are disclosed, assessed and listed in the annexe." | The hosting, DNS, mail, certificate and authentication providers the supplier actually resolves to, and, once you are monitoring a portfolio, how many of your existing suppliers resolve to the same ones. | A disclosure obligation with the known upstream providers already named in it, and notice rights over a change of hosting the annexe would otherwise never mention. | Third-Party Risk Management |
| Concentration is architecture, not a vulnerability. At onboarding it is the cheapest finding in the assessment to act on, because a supplier will not argue with it and your continuity plan is the thing most likely to have assumed it away. |
| Ongoing posture | "We will notify you of any material change to our security posture." | A score on the published A–F bands, computed with the categories and the arithmetic used on your own estate, and benchmarked against comparable suppliers in the same sector so a first grade is interpretable before you have a portfolio to read it against. | A threshold written as a number on a scale you already use internally, with a re-score date attached. The supplier no longer decides what counts as material. | Security Ratings |
| At this stage a grade is a commercial control, not a security one. It decides whether the contract proceeds. A remediation schedule is written from the findings underneath it. |
| Regulatory expectations | "We comply with all applicable regulations in the jurisdictions we operate in." | The observable half a supervisor asks about: whether the supplier internet-facing estate is known, whether administrative access is exposed, whether credentials attributed to it are circulating, each carrying the date it was observed. Compliance itself needs the form. | The outsourcing schedule is written against observations with dates on them, and the unobservable half is named as questions for the form. | Banking and financial services |
| Indian outsourcing expectations place accountability on the regulated entity, not on the supplier. In an inspection, a dated observation is the strong position. This is the sector where the job comes up first and hardest. |