Skip to main content
Use case · Before signature

The questionnaire review closes the file in eleven weeks. The contract is signed on Friday.

“We need a defensible read on a supplier this week, not a spreadsheet they fill in next quarter.”

A supplier can be assessed from outside in 24 hours, from apex domains alone, with nothing asked of the supplier itself. The categories, the arithmetic and the grade bands are the ones ShadowMap already applies to your own estate, so the read you carry into the contract meeting sits on the same scale as your internal target — and it arrives before the signature rather than at the first annual review.

24 hours
Apex domain in, scored assessment out
Zero
Questions the supplier has to answer first
CERT-In
Empanelled security auditor since 2008
41 days

Average questionnaire turnaround in one mature programme

Median time to close a supplier file in the same programme: eleven weeks. That interval is the whole reason this job exists, and it is deliberately not our number to improve — the supplier writes the answers at whatever pace it writes them, and no monitoring product controls that clock. What changes is whether the contract decision has to wait for it. Anonymised engagement, 2026.

The decision

The signature does not wait for the evidence

Nothing here argues that questionnaires are useless. It argues that the contract meeting happens on a date somebody else set, and the security input either exists by then or it does not.

Procurement runs to a date the business set, and the security review is almost always the long pole in it. Two things tend to happen when the form has not come back. Either the deal proceeds on a conditional sign-off that nobody ever revisits — the condition is discharged by the deal closing — or security holds it up on a general unease it cannot evidence, spending credibility it will need later for something real. Both are failures of timing rather than of judgement. An outside-in read does not fix the parts of the review that genuinely need the form: it cannot see an incident-response plan, a background-check policy, a data-residency commitment or a sub-processor contract, and it never will. What it can do is answer the observable half on the day you ask, which happens to be the half a questionnaire is structurally worst at — because there the supplier is describing itself, from memory, about a moment that has already passed. So the reframe worth having is not that the questionnaire goes away. It is that you already know the observable half before you send it, and the form gets to spend its questions on what only a signature can establish.

Attested against observed

What the form will say, and what is already visible

Every row on the left is a standard questionnaire item. The columns beside it set what the response will say against what can be established from outside before you sign — and then the one that actually matters at this stage, which is what a negotiator does with the difference.

Questionnaire itemWhat the response will sayWhat is observable before signatureWhat it changes at contractingWhere this is covered
Asset inventory "We maintain an inventory of our internet-facing assets and review it quarterly." Every hostname answering from the public internet across the apex domains you nominate, with the service and software version behind it, and whether an administrative interface is reachable with no second factor in front of it. An inventory obligation with a named refresh interval — and, where an administrative interface is answering unprotected, a disclosure the supplier makes before signature rather than an incident review in year two. Attack Surface Management
Apex domains are the only input. Nothing is sent to the supplier, nothing is installed, and nothing is touched that is not already reachable from the public internet. The estate resolved here is also what every row below is attributed against — nothing enters the assessment that has not first been discovered and attributed to this supplier.
Credential hygiene "Credentials are rotated on a schedule and are never reused across services." Records attributed to the supplier domains in stealer-log and breach material, including how many entered the corpus in the preceding 90 days — which measures when you could have known, not when the supplier got round to saying so. A rotation obligation discharged before any account is issued on your systems, and a notification clause written against a dated fact rather than against the supplier judgement of what counts as material. Dark Web Monitoring
The authorisation boundary sits here, on the row, rather than in a footnote. Records on a candidate estate arrive observed and untested: we hold authorisation over your estate, not over a company you have not signed, and nothing on a supplier system is probed. Where an exposed identity maps to an account you are about to issue — a contractor remote-access portal, a shared tenancy — that account is your estate, and it is testable under your own authorisation once it exists.
Secrets and source control "Secrets are never committed to source control, and our repositories are private." Code, configuration and credential material published under the supplier name or by identifiable staff accounts, correlated back to the estate in the first row so a genuine leak can be told apart from a name collision. A secrets-handling obligation that names the repositories in question, and — where key material was published — a rotation the supplier performs before the integration is built rather than after it. Data Exposure Monitoring
Publication is observable. Whether a published key still opens anything is a separate fact, and on a candidate estate it is one we deliberately do not establish, because establishing it would mean using the key.
Sub-processors "Our sub-processors are disclosed, assessed and listed in the annexe." The hosting, DNS, mail, certificate and authentication providers the supplier actually resolves to — and, once you are monitoring a portfolio, how many of your existing suppliers resolve to the same ones. A disclosure obligation with the known upstream providers already named in it, and notice rights over a change of hosting the annexe would otherwise never mention. Third-Party Risk Management
Concentration is not a vulnerability. It is architecture — and at onboarding it is the cheapest finding in the assessment to act on, because it is the one a supplier will not argue with and the one your continuity plan is most likely to have assumed away.
Ongoing posture "We will notify you of any material change to our security posture." A score on the published A–F bands, computed with the categories and the arithmetic used on your own estate, and benchmarked against comparable suppliers in the same sector so a first grade is interpretable before you have a portfolio to read it against. A threshold written as a number on a scale you already use internally, with a re-score date attached — rather than a notification clause that depends on the supplier deciding what counts as material. Security Ratings
At this stage a grade is a commercial control, not a security one. It decides whether the contract proceeds. It does not decide what gets fixed, and the findings underneath it are what a remediation schedule is written from.
Regulatory expectations "We comply with all applicable regulations in the jurisdictions we operate in." Nothing outside-in establishes compliance, and we will not pretend otherwise. What it establishes is the observable half a supervisor asks about — whether the supplier internet-facing estate is known, whether administrative access is exposed, whether credentials attributed to it are circulating — each carrying the date it was observed. The outsourcing schedule is written against observations with dates on them, and the unobservable half is named as questions for the form rather than assumed away. Banking and financial services
Indian outsourcing expectations place accountability on the regulated entity rather than on the supplier, which is why "the vendor attested to it" is a weak position in an inspection and a dated observation is a strong one. This is the sector where the job comes up first and hardest.

Asset inventory

What the response will say
"We maintain an inventory of our internet-facing assets and review it quarterly."
What is observable before signature
Every hostname answering from the public internet across the apex domains you nominate, with the service and software version behind it, and whether an administrative interface is reachable with no second factor in front of it.
What it changes at contracting
An inventory obligation with a named refresh interval — and, where an administrative interface is answering unprotected, a disclosure the supplier makes before signature rather than an incident review in year two.
Where this is covered
Attack Surface Management

Apex domains are the only input. Nothing is sent to the supplier, nothing is installed, and nothing is touched that is not already reachable from the public internet. The estate resolved here is also what every row below is attributed against — nothing enters the assessment that has not first been discovered and attributed to this supplier.

Credential hygiene

What the response will say
"Credentials are rotated on a schedule and are never reused across services."
What is observable before signature
Records attributed to the supplier domains in stealer-log and breach material, including how many entered the corpus in the preceding 90 days — which measures when you could have known, not when the supplier got round to saying so.
What it changes at contracting
A rotation obligation discharged before any account is issued on your systems, and a notification clause written against a dated fact rather than against the supplier judgement of what counts as material.
Where this is covered
Dark Web Monitoring

The authorisation boundary sits here, on the row, rather than in a footnote. Records on a candidate estate arrive observed and untested: we hold authorisation over your estate, not over a company you have not signed, and nothing on a supplier system is probed. Where an exposed identity maps to an account you are about to issue — a contractor remote-access portal, a shared tenancy — that account is your estate, and it is testable under your own authorisation once it exists.

Secrets and source control

What the response will say
"Secrets are never committed to source control, and our repositories are private."
What is observable before signature
Code, configuration and credential material published under the supplier name or by identifiable staff accounts, correlated back to the estate in the first row so a genuine leak can be told apart from a name collision.
What it changes at contracting
A secrets-handling obligation that names the repositories in question, and — where key material was published — a rotation the supplier performs before the integration is built rather than after it.
Where this is covered
Data Exposure Monitoring

Publication is observable. Whether a published key still opens anything is a separate fact, and on a candidate estate it is one we deliberately do not establish, because establishing it would mean using the key.

Sub-processors

What the response will say
"Our sub-processors are disclosed, assessed and listed in the annexe."
What is observable before signature
The hosting, DNS, mail, certificate and authentication providers the supplier actually resolves to — and, once you are monitoring a portfolio, how many of your existing suppliers resolve to the same ones.
What it changes at contracting
A disclosure obligation with the known upstream providers already named in it, and notice rights over a change of hosting the annexe would otherwise never mention.
Where this is covered
Third-Party Risk Management

Concentration is not a vulnerability. It is architecture — and at onboarding it is the cheapest finding in the assessment to act on, because it is the one a supplier will not argue with and the one your continuity plan is most likely to have assumed away.

Ongoing posture

What the response will say
"We will notify you of any material change to our security posture."
What is observable before signature
A score on the published A–F bands, computed with the categories and the arithmetic used on your own estate, and benchmarked against comparable suppliers in the same sector so a first grade is interpretable before you have a portfolio to read it against.
What it changes at contracting
A threshold written as a number on a scale you already use internally, with a re-score date attached — rather than a notification clause that depends on the supplier deciding what counts as material.
Where this is covered
Security Ratings

At this stage a grade is a commercial control, not a security one. It decides whether the contract proceeds. It does not decide what gets fixed, and the findings underneath it are what a remediation schedule is written from.

Regulatory expectations

What the response will say
"We comply with all applicable regulations in the jurisdictions we operate in."
What is observable before signature
Nothing outside-in establishes compliance, and we will not pretend otherwise. What it establishes is the observable half a supervisor asks about — whether the supplier internet-facing estate is known, whether administrative access is exposed, whether credentials attributed to it are circulating — each carrying the date it was observed.
What it changes at contracting
The outsourcing schedule is written against observations with dates on them, and the unobservable half is named as questions for the form rather than assumed away.
Where this is covered
Banking and financial services

Indian outsourcing expectations place accountability on the regulated entity rather than on the supplier, which is why "the vendor attested to it" is a weak position in an inspection and a dated observation is a strong one. This is the sector where the job comes up first and hardest.

The first day

What happens between the apex domain and the assessment

The order is load-bearing rather than decorative. Nothing is correlated that has not been discovered, and nothing is scored that has not been attributed — a finding that skips a step is a finding about somebody else.

Sourcing the read

What a 24-hour assessment is, and what it structurally cannot be

A procurement team is right to distrust a number that arrives in a day with no derivation behind it. Here is the derivation — and, more useful at this stage, the list of things the method is not able to tell you, which is exactly what the form is for.

From apex domain to a defensible read As of Assessment method, August 2026
  • The 24 hours is the assessment interval, not a claim about the supplier. A larger estate produces a larger finding set in the same window rather than a slower one; what varies is how much of it you get through before the meeting.
  • The categories, the sub-score arithmetic and the A–F bands are the ones applied to your own estate, unchanged. Nothing is substituted because the estate belongs to somebody else — that substitution is precisely what makes most vendor scores impossible to set beside an internal target.
  • A first assessment has no history behind it, so the grade is positioned against comparable suppliers in the same sector rather than against a trend that does not yet exist. A first grade is a position, not a direction, and reading it as a direction is the common mistake.
  • The assessment is produced by the same recurring scan cycle that would run afterwards. If the contract proceeds, it is simply the first cycle — which is why there is no onboarding result to reconcile against the monitoring that follows.
  • Every finding carries the date it was observed. That matters more at onboarding than anywhere else, because the question in a contract meeting is what was true on the day you asked, not what has been true for a year nobody was watching.

Deliberately excluded

  • Nothing on the candidate estate is probed or tested. We hold authorisation over your estate, not over a company you have not signed, and Continuous Automated Red-Teaming runs only where it is safe and authorised. Pre-signature findings arrive observed, dated and evidenced.
  • It establishes nothing about compliance, and it cannot see an incident-response plan, a background-check policy, a data-residency commitment or a sub-processor contract. Those need the form, and the form needs a signature behind it.
  • It is not a prediction. A clean assessment says what was observable on the day it was taken. It does not say the supplier will not be breached, and no external assessment from anyone can say that.
  • No accuracy figure and no false-positive figure appears here or anywhere else on this site. That is policy rather than omission — we have not established one we would defend in front of a contract.

The contract meeting

One assessment, three people who want different things from it

The same document lands in front of procurement, security and whoever writes the schedule. It is worth being explicit about what each of them will actually do with it, because a report that satisfies only one of the three does not change the outcome.

What each reader takes from it

Friday, with the assessment on the table

Procurement
A defensible reason to proceed, to proceed with conditions, or to pause — arriving on the timetable the deal already runs to. Walking away is rare and everyone in the room knows it, so the useful output is a short list of conditions that can be attached to a signature this week, rather than a review that lands after it.
Security
Findings with owners, dates and evidence, on the same scale as everything else in the register. A supplier sitting at C is not a different kind of object from an internal business unit sitting at C; it is argued about with the same vocabulary. That is the practical benefit of a methodology that does not change when the estate stops being yours.
Whoever writes the schedule
The security annexe stops being boilerplate. An observed exposure becomes a named remediation obligation with a date. An undisclosed exception becomes a disclosure clause. A concentration finding becomes notice rights over a change of hosting. None of that is available to a negotiator who is still waiting for a form.

Questions buyers actually ask

Before you evaluate this

Do you contact the supplier, or do they have to agree to this?

Neither. The assessment runs from apex domains you already hold in the procurement file, and everything it uses is already reachable from the public internet. That is also its limit, and the limit is stated on the table above rather than here: nothing on the candidate estate is probed or tested, so pre-signature findings are observations with dates on them, not test results. Whether you put the findings to the supplier is your decision and there is a good case for it — an observed exposure with evidence attached is a considerably easier conversation than a questionnaire answer somebody has to defend.

Does this replace our questionnaire?

No, and the opening section of this page argues against trying. An attestation carries a signature and an observation cannot sign anything, which is why a regulator asking whether a supplier has a documented incident-response plan is not asking a question anything outside-in can answer. What changes is the order of work. You know the observable half before the form goes out, so the form spends its questions on the unobservable half — and "we follow industry best practice" stops being a passing answer to something you can already see for yourself.

What if the supplier is small, or barely has an internet-facing estate?

Then the assessment is short and says so, and a capability that found nothing attributable is recorded as zero rather than quietly left out of the report. A four-hostname supplier with a marketing site and a mail domain produces a short assessment, and that is the correct result rather than a failure. The mistake worth naming is reading a small estate as a low-risk supplier: the question that decides the tier is what access this supplier is about to be granted on your estate, and that is a finding about you, not about them.

How is this different from just buying a security rating for the candidate?

A rating is an output and it is genuinely good at what it is for — clearing a threshold, drawing a trend, travelling into a board pack. At onboarding it has no trend behind it, because nobody has been watching this supplier. What you need on Friday is the findings underneath the grade: the hostname nobody knew was answering, the credential record dated to last month, the administrative interface with nothing in front of it. Those are the things a clause can be written against. The grade is what you carry into the meeting; the findings are what you negotiate with.

Assess a supplier you are deciding on this quarter

Send the apex domains of one supplier currently in your pipeline. You get back what we would otherwise have handed you on day one of the contract — dated, evidenced, and with the questions the form still has to ask named explicitly.