| Asset inventory | "We maintain an inventory of our internet-facing assets and review it quarterly." | Every hostname answering from the public internet across the apex domains you nominate, with the service and software version behind it, and whether an administrative interface is reachable with no second factor in front of it. | An inventory obligation with a named refresh interval — and, where an administrative interface is answering unprotected, a disclosure the supplier makes before signature rather than an incident review in year two. | Attack Surface Management |
| Apex domains are the only input. Nothing is sent to the supplier, nothing is installed, and nothing is touched that is not already reachable from the public internet. The estate resolved here is also what every row below is attributed against — nothing enters the assessment that has not first been discovered and attributed to this supplier. |
| Credential hygiene | "Credentials are rotated on a schedule and are never reused across services." | Records attributed to the supplier domains in stealer-log and breach material, including how many entered the corpus in the preceding 90 days — which measures when you could have known, not when the supplier got round to saying so. | A rotation obligation discharged before any account is issued on your systems, and a notification clause written against a dated fact rather than against the supplier judgement of what counts as material. | Dark Web Monitoring |
| The authorisation boundary sits here, on the row, rather than in a footnote. Records on a candidate estate arrive observed and untested: we hold authorisation over your estate, not over a company you have not signed, and nothing on a supplier system is probed. Where an exposed identity maps to an account you are about to issue — a contractor remote-access portal, a shared tenancy — that account is your estate, and it is testable under your own authorisation once it exists. |
| Secrets and source control | "Secrets are never committed to source control, and our repositories are private." | Code, configuration and credential material published under the supplier name or by identifiable staff accounts, correlated back to the estate in the first row so a genuine leak can be told apart from a name collision. | A secrets-handling obligation that names the repositories in question, and — where key material was published — a rotation the supplier performs before the integration is built rather than after it. | Data Exposure Monitoring |
| Publication is observable. Whether a published key still opens anything is a separate fact, and on a candidate estate it is one we deliberately do not establish, because establishing it would mean using the key. |
| Sub-processors | "Our sub-processors are disclosed, assessed and listed in the annexe." | The hosting, DNS, mail, certificate and authentication providers the supplier actually resolves to — and, once you are monitoring a portfolio, how many of your existing suppliers resolve to the same ones. | A disclosure obligation with the known upstream providers already named in it, and notice rights over a change of hosting the annexe would otherwise never mention. | Third-Party Risk Management |
| Concentration is not a vulnerability. It is architecture — and at onboarding it is the cheapest finding in the assessment to act on, because it is the one a supplier will not argue with and the one your continuity plan is most likely to have assumed away. |
| Ongoing posture | "We will notify you of any material change to our security posture." | A score on the published A–F bands, computed with the categories and the arithmetic used on your own estate, and benchmarked against comparable suppliers in the same sector so a first grade is interpretable before you have a portfolio to read it against. | A threshold written as a number on a scale you already use internally, with a re-score date attached — rather than a notification clause that depends on the supplier deciding what counts as material. | Security Ratings |
| At this stage a grade is a commercial control, not a security one. It decides whether the contract proceeds. It does not decide what gets fixed, and the findings underneath it are what a remediation schedule is written from. |
| Regulatory expectations | "We comply with all applicable regulations in the jurisdictions we operate in." | Nothing outside-in establishes compliance, and we will not pretend otherwise. What it establishes is the observable half a supervisor asks about — whether the supplier internet-facing estate is known, whether administrative access is exposed, whether credentials attributed to it are circulating — each carrying the date it was observed. | The outsourcing schedule is written against observations with dates on them, and the unobservable half is named as questions for the form rather than assumed away. | Banking and financial services |
| Indian outsourcing expectations place accountability on the regulated entity rather than on the supplier, which is why "the vendor attested to it" is a weak position in an inspection and a dated observation is a strong one. This is the sector where the job comes up first and hardest. |