Track supplier security assessments and review dates: what each supplier touches, what agreements are in place, and when the next review is due.
Criticality ratings, DPA tracking, automatic review dates · Excel (.xlsx) · Free, no email required
A supplier security register covering what each supplier does, what data it touches, its criticality, contracts and DPAs, certifications, and a review schedule with automatically calculated next-review dates. Two worked examples show the expected detail.
Annex A controls 5.19 to 5.22 require you to manage information security in supplier relationships. A register is how businesses evidence knowing their suppliers, what data they touch, what agreements exist and that reviews happen.
Any supplier that accesses, processes or stores your information, and any whose failure would disrupt your service: hosting, SaaS tools, IT support, payroll.
Risk-based: critical and high-criticality suppliers at least annually, others on a two-year cycle. The template calculates next review dates automatically.
In ISOvault, open a supplier and see every asset, control and risk that depends on it, with review reminders built in. 14 days free, no card required.