Skip to content
Cyber Horizon
Back to Blog
Vendor RiskThird-Party RiskTPRM

Vendor Tiering: Stop Assessing Every Supplier the Same Way

11 September 2026·7 min read·Cyber Horizon Team

The fastest way to ruin a third-party risk programme is to treat all vendors equally. Send the 200-question assessment to everyone and two things happen: your critical vendors’ answers get skimmed, and your team burns out chasing the office plant supplier for their encryption policy. Tiering fixes the economics.

Tier on two axes, not gut feel

A workable model scores every vendor on data access (what could they lose or leak?) and operational criticality (what breaks if they go down?). Take the higher of the two — a payroll processor with modest data but payday-critical operations is still Tier 1.

TierTypical profileDue diligence
Tier 1 — CriticalProduction data access, customer PII at scale, or you stop trading if they fail (cloud, payments, auth, payroll).Full assessment + evidence review, DPA, annual reassessment, exit plan, continuous monitoring where possible.
Tier 2 — ImportantLimited or internal data, painful-but-survivable outage (analytics, support tooling, marketing platforms).Focused questionnaire (20–40 questions), certificate/report check, reassess every 1–2 years.
Tier 3 — StandardNo meaningful data access, easy substitution (office services, one-off consultancies, content tools).Contract clauses + a short intake check. Reassess only on change of scope.

Scoring that survives contact with reality

  • Tier at intake, not after onboarding — the moment procurement raises a vendor, five questions decide the tier and the assessment depth.
  • Score the relationship, not the brand. A hyperscaler running your production is Tier 1; the same company’s free webinar tool is Tier 3.
  • Let evidence downgrade effort, not the tier. A current ISO 27001 certificate or SOC 2 report can shorten a Tier 1 assessment — it doesn’t make the vendor Tier 2.
  • Concentration counts: many Tier 2 vendors on one platform can be a Tier 1 risk in aggregate.
  • Fourth parties matter for Tier 1 — ask who THEY depend on; your sub-processor list obligations flow downhill.

What the frameworks expect

ISO 27001 (A.5.19–5.23), SOC 2’s vendor-management criteria, DORA’s ICT third-party regime, NIS2 and the GLBA Safeguards Rule all demand risk-based supplier oversight — none of them demand identical treatment of every supplier. A documented tiering model is precisely what “risk-based” means: it shows the auditor why the depth differs, vendor by vendor, on criteria you wrote down before anyone argued.

The payoff

Teams that tier typically cut questionnaire volume by more than half while increasing scrutiny where it matters. Reviews stop being a queue and become a calendar: Tier 1 annually, Tier 2 on a rolling two-year cycle, Tier 3 on change. And when a vendor breach hits the news, you can answer the only question that matters — “do they touch our data?” — from a register, in minutes.

Tier, score and track every vendor in one place

Cyber Horizon’s vendor-risk module bakes tiering into intake, matches assessment depth to tier, and keeps reassessments on schedule — with AI to triage the questionnaire answers.

Book a Demo