Security and trust
Supplier Assurance boundaries
What Supplier Assurance records and what it does not authorise.
- Audience
- All users
- Plan availability
- Entitled plans
- Last reviewed
Supplier Assurance helps organisations record suppliers, ownership, criticality, questionnaires, evidence requests and scorecards for third-party risk programmes.
What it does
- Maintain a supplier register with relationship and ownership metadata.
- Track assurance reviews, evidence requests and questionnaire responses.
- Produce scorecards and reporting inputs for entitled workspaces.
What it does not do
- A commercial relationship with a supplier does not authorise Cyber Health Score to actively assess that supplier.
- Supplier Assurance is not internet-wide scanning of supplier estates.
- Supplier Assurance is not penetration testing, credential compromise or exploit verification.
- Supplier scorecards are programme artefacts, not certification of the supplier.
Related documentation
Related documentation
Return to the documentation home to browse all topics.
Back to documentation