The challenge behind the engagement.
Vendor and third-party software assessment gives you a risk decision on a product before you buy, deploy, or connect it. We review how the vendor builds and maintains the product securely, measured against the questions a careful buyer should ask. We examine the product’s software components for known-vulnerable and end-of-life parts and, where permitted, run application and interface testing in a sandbox. We review sign-in and access controls, separation between customers, logging, and update integrity, and we examine the connection the product would open into your environment, including the access it requests and the data it reaches. You receive a vendor risk report, a component-risk summary, a security-posture summary, and a go, no-go, or conditional recommendation. Testing vendor-hosted software needs the vendor’s written authorization, confirmed before any hands-on work.
For procurement, security, and IT leaders evaluating a product before purchase, renewal, or integration. Common during vendor due diligence, before connecting a SaaS tool to your tenant, or when a customer asks how you vet the software you run.
What we do.
What you can use.
Frame the decision and access
We agree what the decision hinges on. Then we gather the inputs: a test instance or license, a list of the product’s software components if the vendor provides one, the vendor’s security documentation, any prior third-party report, and integration details. We confirm written authorization before any hands-on testing begins.
Review posture and test
We assess how the vendor builds and maintains the product securely, examine its software components for vulnerable and end-of-life parts, and, where permitted, run application and interface testing in a sandbox. We review sign-in and access controls, separation between customers, logging, and the connection the product would open.
Deliver a go or no-go
You receive a vendor risk report with findings, rated for severity where hands-on testing was done, plus a component-risk summary and a summary of the vendor’s security posture. The recommendation is go, no-go, or conditional, with the conditions spelled out for procurement.
Who it’s for.
When you need it.
- Procurement, security, and IT leaders evaluating a product before purchase or renewal
- Organizations connecting third-party software to sensitive data or their identity provider
- Teams that must show customers and auditors how they vet software
- Buyers who need a risk decision rather than a vendor self-assessment
- A purchase, renewal, or integration decision is pending on a specific product
- A vendor is about to be granted access to your tenant or data
- A customer or regulator asks how you assess third-party software risk
- A vendor supplied an SBOM or attestation that needs independent review
What the scope can include.
- 01
Review how the vendor builds and maintains the product securely
- 02
Examine the product’s software components for vulnerable and end-of-life parts
- 03
Run application and interface testing against the product in a sandbox where permitted
- 04
Review sign-in, customer separation, logging, and update integrity
- 05
Assess the connection the product opens: the access it requests and data it reaches
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
One product, review of vendor documents and software parts, no hands-on testing
About 12–20 hoursOne product reviewed plus hands-on testing of a trial copy
About 32–48 hoursA complex platform that connects to your sign-in system and sensitive data, fully tested
About 56–88 hours- Document review only, or hands-on testing
- Size and complexity of the product
- How deeply the product connects to your systems and data
- Vendor cooperation and test access
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Vendor risk report with findings and severity ratings where testing was performed
- Component-risk summary flagging vulnerable and end-of-life parts
- Summary of the vendor’s security and development practices
- Go, no-go, or conditional recommendation with the conditions named
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Can you test the product itself or only review documents?
Both, depending on access and authorization. When you can give us a test instance and the right to test it, we run application and interface testing in a sandbox and rate what we find. When only documentation is available, we do a posture and component review and say plainly that it is a document review, not testing. Testing vendor-hosted software always needs the vendor’s written consent.
Is a federal software attestation still required?
The picture changed recently. Federal policy no longer pushes to expand validation of the software attestation form, and the common form is now something agencies may choose to use rather than a blanket mandate. In practice, buyers ask for evidence of secure development, a list of software components, and a clear security posture instead of a specific form. We assess the product against those expectations and tell you plainly where it stands.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
