Skip to content

Template: Vendor Assessment

Instructions

Assessment of security maturity of service providers and suppliers under §30(2) No. 4 BSIG. To be performed before contract signing, repeated at least annually.

Vendor Master Data

FieldValue
Vendor IDVEN-NIS2-XXXX
Name
Domicile / country
Main contact[Name + email]
Security contact[Name + email + phone]
Contract type[ ] Hosting [ ] Cloud [ ] Software supplier [ ] Support [ ] Other
Criticality[Low / Medium / High / Critical]
Data processed[PII / Business data / Credentials / None]
GDPR DPA in place[ ] Yes [ ] No [ ] Not required

Certificates and Evidence

StandardHeldValid untilScope
ISO/IEC 27001[ ]
SOC 2 Type II[ ]
BSI C5[ ]
TISAX[ ]
Other[ ]

Security Checklist

AreaQuestionStatusEvidence
GovernanceDoes a documented ISMS exist?[Yes/No/N.A.]
GovernanceIs a CISO appointed?
IncidentIs there an incident response plan?
IncidentIs incident notification (24h) contractually guaranteed?
BCMIs a BCM plan in place? Last test?
Supply chainAre sub-suppliers disclosed?
VulnerabilitiesIs there a documented patch management process?
VulnerabilitiesAre CVEs actively monitored?
TrainingDo employees receive regular security training?
CryptographyIs data encrypted at rest and in transit?
AccessIs MFA enforced for administrative access?
AccessIs there a documented onboarding/offboarding process?
AuditAre audit rights contractually guaranteed?

Risk Assessment

AspectRating
Criticality for BAUER GROUP[Low / Medium / High / Critical]
Vendor security maturity[Low / Medium / High]
Resulting risk[Low / Medium / High / Critical]
Risk treatment[ ] Accept [ ] Contractual conditions [ ] Reject

Contractual Requirements

RequirementIn contract
24h incident notification[ ]
Audit right (at least annually)[ ]
Sub-supplier consent obligation[ ]
Data return / deletion at contract end[ ]
Minimum security standards (ISO 27001 etc.)[ ]
Liability for security breaches[ ]

Approval

NameDate
Assessment by
Reviewed by (CISO)
Approved by (Procurement / Management)

Notes

  • Critical vendors are reassessed semi-annually
  • High vendors are reassessed annually
  • Material changes (loss of certification, incident) trigger immediate reassessment

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT