Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Vendor Risk Calculator

Rate a third-party vendor's risk from the data they access, the certifications they hold, and how critical they are to your business. The risk tier and recommended due diligence update live as you choose.

Vendor risk tier
Medium
0 / 100 risk points
Recommended due diligence
    How the score works, and its limits. We assign points across four factors: data sensitivity, depth of system access, business criticality, and certification status. Higher points mean higher inherent risk. A recognized, reviewed certification reduces the score because it is independent evidence of controls. This is a triage aid to help you right-size due diligence, not a substitute for a real vendor assessment. It does not account for the vendor's geography, breach history, or fourth-party dependencies, all of which can matter.

    Questions

    What makes a vendor high risk?

    The biggest drivers are how sensitive the data they access is, how deeply they integrate with your systems, and how critical they are to operations. A vendor with broad access to customer data and no recognized certification is the classic high-risk case.

    Do certifications like SOC 2 lower vendor risk?

    Yes. A current SOC 2 Type II or ISO 27001 report is independent evidence that the vendor operates real controls, so it lowers the residual risk. It does not eliminate it, and you should still review the report and any exceptions.

    How should I use the risk tier?

    Use it to right-size due diligence. Low-risk vendors may need only a basic review, while high-risk vendors warrant a security questionnaire, evidence review, contractual security terms, and periodic reassessment.

    How often should vendors be reassessed?

    Reassess high-risk vendors at least annually and whenever their access or your relationship changes materially. Lower-risk vendors can be reviewed on a longer cycle.

    Is this calculator free?

    Yes, it is free with no signup. If you need a full third-party risk program or vendor assessment, our team can help.

    Not ready for a call yet?

    Get the compliance playbook

    A few short notes from Jacob on getting audit-ready without months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    Third-Party Risk Management

    A managed program for vetting and monitoring your vendors.

    Explore Third-Party Risk Management →

    Build a vendor risk program that holds up.

    Auditors and enterprise customers will ask how you vet your vendors. We help you stand up third-party risk management as part of your compliance program, backed by auditor management and advocacy when it's time for the audit.

    See our security services Book a call

    Want the full picture on your vendors?

    This gives you the shape of the problem. The free compliance workspace gives you a proper vendor register: tier every supplier by the data they touch, send them a questionnaire, keep the answers next to the controls that depend on them, and set the review date so it does not lapse. Start free and run your whole vendor list through it.

    Start your free vendor assessment See what is in the platform

    No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the workspace.