01What supply chain security and TPRM cover
Third-Party-Risk-Management (TPRM) covers the identification, assessment, and ongoing management of risks arising from relationships with suppliers and service providers. This includes an inventory of all third parties, their classification by criticality, the assessment of their security practices, and contractual and organizational controls across the entire lifecycle – from procurement to exit. The goal is transparency about which providers support critical functions and how robust their security posture actually is.
02Regulatory framework: NIS2, DORA, CRA, ISO 27001
The supply chain is now explicitly regulated. NIS2 (Richtlinie (EU) 2022/2555) requires supply chain security measures for relationships with direct suppliers and service providers in Art. 21(2)(d); Art. 21(3) requires taking into account the vulnerabilities of each direct supplier and the quality of its cybersecurity practices (including the coordinated risk assessments under Art. 22). For the financial sector, DORA (Verordnung (EU) 2022/2554, applicable since January 17, 2025) governs ICT third-party risk in Chapter V – including strategy and register of information (Art. 28), concentration risk (Art. 29), and minimum contractual provisions (Art. 30). The Cyber Resilience Act extends these obligations to products with digital elements and their components. In practice, the ISO/IEC 27001 controls A.5.19–A.5.23 operationalize these requirements for supplier relationships and cloud use.
03Assessing cloud providers: CAIQ, CCM, and STAR
The Cloud Security Alliance has created an established procedure for assessing cloud providers. The Cloud Controls Matrix (CCM) is a control framework for cloud computing with 197 control objectives across 17 domains. The accompanying Consensus Assessment Initiative Questionnaire (CAIQ) translates these controls into yes/no questions (v4.0: 261 questions) with which a provider documents its existing security controls; from version 4.1 onward, CCM and CAIQ are merged. Through the STAR Registry (Security, Trust, Assurance and Risk), the completed CAIQ becomes publicly accessible: STAR Level 1 is a free self-assessment (updated annually), Level 2 a paid third-party audit – as STAR Attestation (SOC 2) or STAR Certification (ISO/IEC 27001). This makes it possible to judge whether a service is secure enough for your own intended use.
04Assessing AI providers: CSA AI Controls Matrix v1.1
AI services require their own assessment logic. The CSA AI Controls Matrix (AICM) v1.1 is a vendor-neutral control framework for cloud-based AI systems with 247 control objectives across 18 security domains; it builds on the CCM and is synchronized with CCM v4.1. A dedicated “Model Security” domain addresses AI-specific topics such as Model Poisoning, Prompt Injection, unauthorized model access, and the protection of Model Weights through 13 AI-specific controls. The controls distinguish five roles (including Model Provider, Application Provider, AI Customer) and provide mappings to ISO 42001, ISO/IEC 27001, NIST AI RMF and NIST AI 600-1, BSI AIC4, and the EU AI Act. The accompanying AI-CAIQ (v1.1: 320 questions) serves – like the CAIQ in the cloud domain – as a question catalog for self- and third-party assessments.
05From questionnaire to continuous monitoring
A questionnaire is a snapshot – security, by contrast, is a state over time. A robust assessment begins with the criticality rating of the provider, followed by the evaluation of the CAIQ or AICM responses as well as available certificates and audit reports. Because STAR Level 1 self-disclosures are updated annually, a provider's compliance posture can be tracked continuously; for critical functions, DORA requirements such as concentration analysis (Art. 29) and exit strategies (Art. 28(8)) complete the picture. Point-in-time questionnaires thus become a continuous process with defined triggers for reassessments.
06The VamiSec approach
VamiSec supports the establishment of a TPRM program and the concrete assessment of individual providers. We structure supplier and provider assessments along established catalogs (CAIQ/CCM for cloud, AICM for AI), automate recurring security questionnaires, and map the results to the regulatory requirements from NIS2, DORA, and ISO/IEC 27001. On request, we support the preparation for STAR or ISO 27001 audits and set up continuous monitoring of critical third parties – vendor-neutral and documented in a verifiable manner.