Penetration Testing / FOCUSED SERVICE

Vendor & Third-Party Software Assessment

Technical security evaluation of software before you buy it, deploy it, or connect it to your environment.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

Vendor and third-party software assessment gives you a risk decision on a product before you buy, deploy, or connect it. We review how the vendor builds and maintains the product securely, measured against the questions a careful buyer should ask. We examine the product’s software components for known-vulnerable and end-of-life parts and, where permitted, run application and interface testing in a sandbox. We review sign-in and access controls, separation between customers, logging, and update integrity, and we examine the connection the product would open into your environment, including the access it requests and the data it reaches. You receive a vendor risk report, a component-risk summary, a security-posture summary, and a go, no-go, or conditional recommendation. Testing vendor-hosted software needs the vendor’s written authorization, confirmed before any hands-on work.

WHEN THIS IS THE RIGHT FIT

For procurement, security, and IT leaders evaluating a product before purchase, renewal, or integration. Common during vendor due diligence, before connecting a SaaS tool to your tenant, or when a customer asks how you vet the software you run.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Frame the decision and access

We agree what the decision hinges on. Then we gather the inputs: a test instance or license, a list of the product’s software components if the vendor provides one, the vendor’s security documentation, any prior third-party report, and integration details. We confirm written authorization before any hands-on testing begins.

Review posture and test

We assess how the vendor builds and maintains the product securely, examine its software components for vulnerable and end-of-life parts, and, where permitted, run application and interface testing in a sandbox. We review sign-in and access controls, separation between customers, logging, and the connection the product would open.

Deliver a go or no-go

You receive a vendor risk report with findings, rated for severity where hands-on testing was done, plus a component-risk summary and a summary of the vendor’s security posture. The recommendation is go, no-go, or conditional, with the conditions spelled out for procurement.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Procurement, security, and IT leaders evaluating a product before purchase or renewal
  • Organizations connecting third-party software to sensitive data or their identity provider
  • Teams that must show customers and auditors how they vet software
  • Buyers who need a risk decision rather than a vendor self-assessment
WHEN IT’S TIME TO ENGAGE
  • A purchase, renewal, or integration decision is pending on a specific product
  • A vendor is about to be granted access to your tenant or data
  • A customer or regulator asks how you assess third-party software risk
  • A vendor supplied an SBOM or attestation that needs independent review
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Review how the vendor builds and maintains the product securely

  • Examine the product’s software components for vulnerable and end-of-life parts

  • Run application and interface testing against the product in a sandbox where permitted

  • Review sign-in, customer separation, logging, and update integrity

  • Assess the connection the product opens: the access it requests and data it reaches

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.

Small
$1,800–$3,000

One product, review of vendor documents and software parts, no hands-on testing

About 12–20 hours
Mid-size
$4,800–$7,200

One product reviewed plus hands-on testing of a trial copy

About 32–48 hours
Large
$8,400–$13,500

A complex platform that connects to your sign-in system and sensitive data, fully tested

About 56–88 hours
WHAT MOVES THE PRICE
  • Document review only, or hands-on testing
  • Size and complexity of the product
  • How deeply the product connects to your systems and data
  • Vendor cooperation and test access
TYPICAL TIMELINE

1–3 weeks

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Vendor risk report with findings and severity ratings where testing was performed
  • Component-risk summary flagging vulnerable and end-of-life parts
  • Summary of the vendor’s security and development practices
  • Go, no-go, or conditional recommendation with the conditions named

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Can you test the product itself or only review documents?

Both, depending on access and authorization. When you can give us a test instance and the right to test it, we run application and interface testing in a sandbox and rate what we find. When only documentation is available, we do a posture and component review and say plainly that it is a document review, not testing. Testing vendor-hosted software always needs the vendor’s written consent.

Is a federal software attestation still required?

The picture changed recently. Federal policy no longer pushes to expand validation of the software attestation form, and the common form is now something agencies may choose to use rather than a blanket mandate. In practice, buyers ask for evidence of secure development, a list of software components, and a clear security posture instead of a specific form. We assess the product against those expectations and tell you plainly where it stands.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security