Trust RAV
Security RAV
Supply RAV
Final Rating
0 / 52 answered

Assessment

Complete before scoring. Vendor type calibrates the N/A caps below.

N/A caps per vendor type

Mark N/A only when a question genuinely does not apply. N/A is removed from the denominator; it does not count as YES. Exceeding the cap triggers an Incomplete Assessment flag.
Vendor typeTrustSecuritySupply Chain
SaaS / Cloud33 (no physical)0
On-Premises Software340
Professional Services45Not Assessed
Infrastructure Access33Not Assessed

Grade scale

RAVGradeGuidance
95–100ARecommended. Standard contractual monitoring + annual review.
85–94BAcceptable. Verify contracts align with findings; address weak areas contractually.
70–84CConditional. Require contractual safeguards for identified gaps before proceeding.
60–69DHigh risk. Avoid unless no alternative. Legal protections mandatory. Escalate for approval.
Below 60FDo not engage. Documented posture insufficient for the risk involved.

Section 1 — Trust RAV

15 questions • 5 dimensions × Trust Property mapping

Complete this section first. The Trust RAV is the hard ceiling on the Final Rating.

Each question scores one of the 15 OSSTMM 4 Trust Properties (Ch. 3.2) across the 5-dimension lattice. NOs accumulate as limitations against the dimension shown in the tag row. Trust cannot exceed visibility (Trust Rule 7).

Q1
Components
Has the vendor disclosed the full set of subprocessors, partners, and infrastructure dependencies your data will touch?
Visibility Intent
Q2
Symmetry
Does the contract define mutual obligations, or does the vendor accept terms only one-way (you bear the risk, they bear no equivalent)?
Visibility Intent
Q3
Role
Does the vendor occupy a single, scoped role in your operation, rather than bundling hosting + identity + email + backup into one trust relationship?
Visibility Intent
Q4
Property
Is the value you gain from the relationship clearly higher than the cost of trust failure? (NO if the upside is marginal but the blast radius is large.)
Visibility Intent
Q5
Transparency
Can you observe the vendor’s internal operations relevant to your data — through audit reports, real-time dashboards, queryable logs, or right-to-audit clauses?
Visibility Intent
Q6
Friction
Are there few stops, change-orders, or operational handoffs disrupting the relationship? (NO if every change request takes weeks and routes through multiple intermediaries.)
Interactions React
Q7
Certainty
Does the vendor commit contractually to notify you within a defined window when material changes occur (security posture, data handling, ownership, leadership)?
Interactions React
Q8
Oversight
Do you retain real-time intervention rights during active interactions — the ability to revoke, suspend, or audit access while it is happening rather than after?
Interactions React
Q9
Importance
Is your account a meaningful share of the vendor’s revenue or a strategically named customer, such that they have incentive to respond fast?
Interactions React
Q10
Size
Is the relationship structurally simple (you ↔ vendor) rather than chained through multiple intermediaries (you → broker → reseller → vendor → subprocessor)?
Interactions React
Q11
Disparity
Does the vendor’s infrastructure, staff, and process remain stable between interactions, rather than reorganizing every quarter?
Inquest Resolve
Q12
Reflection
After delivery, does the vendor’s actual posture (audit findings, breach disclosures, support quality) match what they represented during sales?
Inquest Resolve
Q13
Offsets
Does the contract specify accountability mechanisms for trust violations — penalties, indemnification, third-party audit rights, breach-notification SLAs with teeth?
Interactions Resolve
Q14
Durability
Does the vendor demonstrate financial, operational, and staffing durability sufficient to survive disruption (recession, key-person loss, security incident at their own infra)?
Intervention Resolve
Q15
Liberty
Has the vendor maintained consistent terms, ownership, and behavior over the past 24 months (low rate of pivots, rebrandings, material contract changes)?
Inquest Resolve

Section 2 — Operational Security

22 questions • 5 dimensions × 3 phases + cross-cutting

Each question maps to one cell of the OSSTMM 4 5×3 control lattice. NO = the control is absent → recorded as a limitation in that dimension. PARTIAL = control exists but incomplete → 0.5 × LT.

Three questions are Red Lines: Q2 (phishing-resistant MFA), Q8 (encryption in transit / at rest), and Supply Chain Q1 (SBOM). A NO on any of these caps the Final Rating at Grade D.

Q1
Identification
Does the vendor maintain a current list of authorized contacts on your staff for administrative, billing, and support requests, rather than acting on any caller who claims to represent your org?
Visibility Intent
Q2
Authentication RED LINE
Does the vendor require phishing-resistant MFA (FIDO2/WebAuthn or equivalent) for all interactive administrative and customer-data access (web consoles, cloud portals, admin UIs, jump hosts), with long-lived SSH keys and API tokens for privileged access issued only through the same MFA-gated flow?
Visibility React
Q3
Non-Repudiation
Does the vendor maintain immutable, queryable records of every interaction with your data and services, including who, when, what, and the channel of access?
Visibility Resolve
Q4
Restriction
Does the vendor segment customer environments such that a compromise of one tenant cannot reach another? (For SaaS, also: does network/identity isolation extend to backups and analytics?)
Induction Intent
Q5
Alarm
Does the vendor commit to notifying you of incidents (digital or physical) affecting your data within a defined window, via an out-of-band channel from how requests are normally made?
Induction React
Q6
Remediation
Does the vendor have a documented process for restoring environments to known-good after an incident, with the ability to provide post-incident artifacts (root cause, scope, remediation steps)?
Induction Resolve
Q7
Authorization
Does the vendor enforce least-privilege access, with documented role definitions and segregation of duties for staff who can reach customer data?
Interactions Intent
Q8
Subjugation RED LINE
Are protection mechanisms (encryption, access controls, audit logging) configured such that the vendor cannot remove or weaken them, including under support or maintenance pretexts? Encryption applies in transit AND at rest.
Interactions React
Q9
Indemnification
Does the contract specify the vendor’s accountability — financial, contractual, and operational — for breaches caused by the vendor or its subprocessors?
Interactions Resolve
Q10
Availability
Does the vendor commit to defined SLAs for uptime and recovery, with documented infrastructure redundancy (no single points of failure) and tested business-continuity plans?
Intervention Intent
Q11
Containment
Does the vendor maintain technical and organizational controls to isolate and limit the blast radius of an in-progress incident (network segmentation, automated kill-switches, account lockouts)?
Intervention React
Q12
Stabilization
Does the vendor maintain timely, regularly-tested backups of all customer data and configurations, with a documented restoration process and recovery-time / recovery-point objectives?
Intervention Resolve
Q13
Confidentiality
Does the vendor maintain confidentiality of operational details (locations, personnel, customer lists, security processes) — and require NDAs of employees, contractors, and partners?
Inquest Intent
Q14
Resilience
Does the vendor maintain an alternative or fallback mechanism so that data and service can be recovered if the vendor’s primary channel fails (e.g., independent export channel, escrowed credentials)?
Inquest React
Q15
Integrity
Does the vendor run regular authenticity / integrity checks on stored customer data, with detection of accidental or malicious modification, and a documented recovery process?
Inquest Resolve
Q16
Cross-cutting
Does the vendor hold the certifications required by your sector (HIPAA / PCI DSS / SOC 2 Type II / ISO 27001 / OSSTMM STAR / sector-specific)?
Inquest
Q17
Cross-cutting
Does the contract specify support for legal-defense and eDiscovery — connection logs, communication logs, evidentiary holds, forensic readiness — in defense of third-party legal claims?
Inquest
Q18
Cross-cutting
Does the vendor commit to data residency aligned with your regulatory environment (data stays within named jurisdictions; transfers governed by SCCs / DPF / equivalent)?
Visibility
Q19
Cross-cutting
Does the vendor restrict physical access to server rooms and operational sites to vetted, contracted personnel — with logged access and visitor controls?
Interactions
Q20
Cross-cutting
Does the vendor disclose all subcontracting and third-party operational dependencies, AND require security commitments downstream that match the commitments you require of them?
Interactions
Q21
Cross-cutting
Does the vendor commit to verifiable destruction of customer data on contract termination, with documented exceptions only for billing / regulatory / legal retention?
Inquest
Q22
Cross-cutting
Does the vendor provide schedules in advance of maintenance and operational changes, with named personnel responsible?
Inquest

Section 3 — Supply Chain RAV

15 questions • SaaS / Software / Cloud

Required for vendors providing software or hosted services. Mark Not Assessed (N/A on all questions) for pure professional-services or physical-infrastructure vendors and document the reason in the Assessment tab.

Q1 (SBOM) is a Red Line for SaaS / software / cloud vendors.

Q1
Identification RED LINE
Does the vendor publish a current Software Bill of Materials (SBOM, CycloneDX or SPDX) for each released version, listing all third-party and open-source components with versions?
Visibility Intent
Q2
Authentication
Does the vendor sign all release artifacts (binaries, packages, containers) with verifiable signatures (Sigstore / cosign / notarization), enabling integrity and origin verification?
Visibility React
Q3
Non-Repudiation
Does the vendor publish provenance attestations (SLSA L2+ or equivalent) for build artifacts, allowing customers to verify what was built, by whom, from what source?
Visibility Resolve
Q4
Restriction
Is the vendor’s CI/CD build environment isolated from production and from external internet access, with enforced access controls and full audit logging of pipeline activity?
Induction Intent
Q5
Alarm
Does the vendor monitor SBOM-listed dependencies for newly-disclosed vulnerabilities and notify customers within a defined window?
Induction React
Q6
Remediation
Does the vendor commit to patch-cycle SLAs by severity (Critical / High / Medium) and provide hotfixes for critical supply-chain advisories?
Induction Resolve
Q7
Authorization
Does the vendor have a documented dependency-vetting process — license review, known-vulnerability check, maintainer-credibility assessment — applied before adoption?
Interactions Intent
Q8
Subjugation
Does the vendor enforce a documented AI-generated-code policy requiring human security review and testing before merge to production (enforceable, not advisory)?
Interactions React
Q9
Indemnification
Does the contract assign liability for supply-chain compromises (including upstream component CVEs that were known and unpatched at release)?
Interactions Resolve
Q10
Availability
Does the vendor maintain backup release channels and signed mirrors so that a compromise of the primary distribution channel does not block customer recovery?
Intervention Intent
Q11
Containment
Does the vendor commit to a coordinated-disclosure timeline (CERT or sector ISAC) so that supply-chain advisories do not surprise customers via public disclosure first?
Intervention React
Q12
Stabilization
Does the vendor maintain rollback paths to prior known-good releases, including for hosted services where the customer doesn’t control the deployment?
Intervention Resolve
Q13
Confidentiality (AI)
Does the vendor contractually commit to NOT using customer data, prompts, or operational logs to train, fine-tune, benchmark, or evaluate any AI model without explicit written consent per use?
Inquest Intent
Q14
Resilience (AI)
If the vendor uses AI in their delivery (LLM features, agentic workflows, AI-assisted support), do they document the model provenance — base model, training data sources, alignment process?
Inquest React
Q15
Integrity (AI)
Does the vendor maintain documented input-validation and output-monitoring for AI features, with logging sufficient to detect prompt-injection, data-exfiltration, or model-drift events?
Inquest Resolve

Results

Final Vendor Rating = min(Trust RAV, Security RAV, Supply Chain RAV) with Red Line caps applied

Final Vendor Rating

Complete all sections to compute.

RAV breakdown

SectionRAVAnsweredNO countPARTIAL countUNK count

Red Line status

Red Line Controls

N/A discipline

Per-dimension breakdown (Security)

DimensionQuestionsLT_n (NO + 0.5·PARTIAL)

Compliance Coverage

Framework crosswalks • select a framework in the scorecard to see per-control coverage
First-pass mappings, SME review required before ship. OSSTMM v4 does not have official published crosswalks to NIST 800-53, PCI DSS, or HIPAA. The mappings loaded here are best-fit first-pass suggestions maintained in mappings.py. Currently populated: NIST 17/52 questions, PCI 17/52, HIPAA 14/52. Extend or edit before using with clients.
Pick a framework in the scorecard filter (top-right) to see per-control coverage. Coverage shows every control any question maps to, which questions cover it, and whether those questions are marked YES (control covered), PARTIAL (partially covered), NO (control gap), or unanswered.

About this checklist

OSSTMM 4 Vendor Security Checklist v10.2 — the only vendor checklist grounded in published security science with a mathematically defined score. Applies OSSTMM 4 RAV math (Appendix C) to three independent channels: Trust Properties (Ch. 3), Operational Security (Ch. 10), and Supply Chain / AI governance.

Who fills this out: a security assessor or procurement officer with security oversight responsibility. Not the vendor.

Evidence sources: contracts and SLAs, independent audit reports (SOC 2 Type II, ISO 27001, PCI DSS, OSSTMM STAR), direct technical testing of the vendor's services, public records, court filings. NOT vendor whitepapers or sales-conversation statements.

Three scores, one rating: Trust RAV (Section 1), Security RAV (Section 2), Supply Chain RAV (Section 3). Final Rating = min(all three). Trust acts as a hard ceiling per Trust Rule 7 (trust cannot exceed visibility).

Red Lines: Security Q2 (phishing-resistant MFA), Security Q8 (encryption in transit / at rest), Supply Chain Q1 (SBOM, for SaaS / software / cloud). NO on any Red Line caps the Final Rating at Grade D regardless of other scores.

Compliance mapping (v10.1): First-pass crosswalks to NIST 800-53 rev5, PCI DSS 4.0, and HIPAA Security Rule. Currently a partial stub for demonstration. Extend the mappings.py data file to add SME-reviewed mappings before client use.

Reassess annually or after: confirmed security incident, vendor acquisition or change of ownership, material product / service change, change in your own risk profile.

Methodology: OSSTMM 4 (isecom.org) • ISECOM, Institute for Security and Open Methodologies