Third-Party Security Assessment Checklist
Use this form to assess a third-party vendor’s security posture, document checklist results, and record findings and remediation notes.
Vendor and Assessment Scope
Vendor or Third-Party Organization Name
*
Primary Contact Name
*
First Name
Middle Name
Last Name
Primary Contact Email
*
example@example.com
Service or Product Being Assessed
*
Assessment Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Assessor Name
*
First Name
Middle Name
Last Name
Security Control Checklist
Access control
*
Rows
Present
Partial
Not Present
Access control
1
2
3
Multi-factor authentication
*
Rows
Present
Partial
Not Present
Multi-factor authentication
4
5
6
Encryption
*
Rows
Present
Partial
Not Present
Encryption
7
8
9
Vulnerability management
*
Rows
Present
Partial
Not Present
Vulnerability management
10
11
12
Logging and monitoring
*
Rows
Present
Partial
Not Present
Logging and monitoring
13
14
15
Incident response
*
Rows
Present
Partial
Not Present
Incident response
16
17
18
Backup and recovery
*
Rows
Present
Partial
Not Present
Backup and recovery
19
20
21
Employee security training
*
Rows
Present
Partial
Not Present
Employee security training
22
23
24
Data retention and deletion
*
Rows
Present
Partial
Not Present
Data retention and deletion
25
26
27
Subcontractor management
*
Rows
Present
Partial
Not Present
Subcontractor management
28
29
30
Assessment Ratings and Notes
Overall Security Maturity Rating
*
Very Low
1
2
3
4
5
6
7
8
9
Very High
10
1 is Very Low, 10 is Very High
Key Findings, Gaps, and Recommended Actions
*
Submit
Should be Empty: