Vendor Risk Assessment: The 50-Point Checklist Before You Sign

Your vendors have access to your data, your customers, and your systems. Here's how to vet them before it's too late.

By The StackMatch Research Team

A meaningful share of small-business data incidents trace back to a third-party vendor, not an internal system

50Checkpoint due-diligence checklist
$4M+Illustrative avg. breach cost, larger incidents
3Categories to vet: security, continuity, financial health

Directionally illustrative figures — actual breach costs vary enormously by incident scope and industry.

Signing a contract is the same decision as handing over a login

A SaaS vendor's sign-up flow takes five minutes and asks for a credit card. What it actually grants, on the other side, is standing access to customer records, employee PII, and often a live connection into your financial systems — with none of the scrutiny you'd apply before handing a stranger your bank login. The 50-point checklist below is the scrutiny that sign-up flow skips.

Vendor risk assessment is due diligence you do once, before signing — not paranoia after something goes wrong.

Security checklist (20 points)

Security requirements

  • SOC 2 Type II certification (not Type I)
  • ISO 27001 certification (bonus)
  • Encryption at rest (AES-256)
  • Encryption in transit (TLS 1.3+)
  • Two-factor authentication (required, not optional)
  • SSO/SAML support (Okta, Azure AD, Google)
  • Role-based access controls
  • Audit logs (who accessed what, when)
  • Data residency options (US, EU, etc.)
  • GDPR compliance (if EU customers)
  • HIPAA compliance (if healthcare data)
  • Penetration testing (annual, third-party)
  • Vulnerability disclosure program
  • Incident response plan (documented)
  • Breach notification SLA (24-72 hours)
  • Backup frequency (daily minimum)
  • Disaster recovery plan (tested)
  • RTO/RPO defined (under 4 hours ideal)
  • Employee background checks
  • Security training (annual, documented)
20
security checkpoints minimum

Business continuity (15 points)

Continuity requirements

  • Uptime SLA (99.9% minimum)
  • SLA credits (automatic, not requested)
  • Support response times (documented)
  • 24/7 support availability
  • Dedicated CSM (for enterprise)
  • Escalation path (documented)
  • Contract term (1-3 years max)
  • Termination clause (30-60 days)
  • Data export format (CSV, JSON, API)
  • Data export timeline (under 30 days)
  • Transition assistance (included)
  • Price increase cap (5-10%/year)
  • Auto-renewal opt-out (90 days)
  • Liability cap (reasonable, not unlimited)
  • Insurance coverage ($1M+ cyber liability)

The data export trap: vendors make it easy to get data in, impossible to get it out. Require export in standard formats (CSV, JSON) before signing.

Financial health (15 points)

Financial due diligence

  • Years in business (3+ minimum)
  • Funding stage (Series B+ stable)
  • Revenue growth (positive trend)
  • Customer count (100+ minimum)
  • Customer retention rate (90%+)
  • Churn rate (under 10%/year)
  • Profitability (break-even or better)
  • Customer references (3+ provided)
  • Case studies (relevant to your size)
  • G2/Capterra reviews (4+ stars)
  • Employee count (growing, not shrinking)
  • LinkedIn activity (active, professional)
  • News mentions (positive, recent)
  • Leadership stability (low exec turnover)
  • Acquisition risk (low, or plan disclosed)

Illustrative failure risk by vendor age (directional, not a guarantee)

The three due-diligence categories, at a glance

CategoryWhat it protects againstSingle biggest red flag
Security (20 pts)A breach that exposes customer or employee dataNo SOC 2 / ISO certification, or a Type I instead of Type II report
Business continuity (15 pts)Being stuck with a tool that fails you or traps your dataNo documented data-export path or timeline
Financial health (15 pts)The vendor disappearing or getting acquired mid-contractCan't produce customer references or shows shrinking headcount

The bottom line

A vendor that fails the security checklist is a breach risk. One that fails business continuity is a migration project waiting to happen. One that fails financial health might not exist in two years. Any one category failing is enough to walk away or negotiate remediation before signing — not after.

Run the free StackMatch audit to see vendor risk scores for your current software stack.

Run your own audit
More from the blog