Skip to content
FortaRisks
The whole platform

Forta Suppliers

Third-party risk (TPRM)

The real posture of your vendors, not their questionnaire

The questionnaire your vendor fills in, continuously cross-checked against a scan of their real attack surface. The gap between what they declare and what their surface shows becomes an explicit signal, and the scan covers a perimeter they validated themselves, so it can be challenged and re-run after remediation.

Forta Suppliers

48 hours

To first alert

0 to 100

Vendor score, A+ to F

500+

Finding types per vendor

The annual questionnaire is already out of date.

A once-a-year form does not tell you when a vendor is actually exposed or breached.

Value you can see

Outcomes your team will feel.

  • The vendor cannot contradict themselves

    Declared and observed side by side, with a flag when the two diverge.

  • A scan they can challenge

    Perimeter validated by the vendor, re-scan on demand after remediation: the opposite of attribution false positives.

  • Questionnaire fatigue, handled

    Answers reused from one client to the next, passwordless portal, versioned evidence.

Key capabilities

  • Declared and observed, reconciled

    On one side the vendor's questionnaire, on the other a native external scan of their surface. Both are cross-checked continuously without being merged, and a divergence between what is declared and what is observed is raised as an explicit flag. That is what ratings lack, having only the observed, and what questionnaires lack, having only the declared.

  • The vendor answers once, for every client

    By our estimate, a vendor receives around 37 assessment requests a month. In their own space they answer once and reuse those answers from one client to the next, question by question or by SCF control. No network or marketplace to build: the SCF link is what makes reuse possible.

  • Passwordless portal and versioned evidence

    The vendor signs in with a code sent by email, with no account to create and no licence to buy. They build a versioned evidence library they can share again. The catalogue is shared: a vendor already known to the platform is not re-scanned for every new client.

  • Three questionnaire levels, including an OT/ICS module

    From a 24-question baseline to a full 139-question assessment across 9 domains and 35 control domains, plus 6 thematic modules you can add. One of them covers OT and ICS, for your industrial suppliers. Every answer maps to an SCF control, which gives NIST, ISO 27001, SOC 2 and GDPR coverage with no extra work.

  • Share reports for remediation

    Export a vendor's report and hand it to them, turning your assessment into their improvement, with no extra licence for them.

  • Questionnaires on demand

    When a posture degrades and you need depth, send a targeted questionnaire for the detail external scanning cannot see, not a yearly blanket survey.

A degradation becomes a dated remediation request.

Twelve configurable alert policies trigger on a score drop, a grade crossing or a new critical finding. The remediation request goes out with a deadline and reminders, and surfaces in the Action Center as well as the risk register. Five registers are exportable, and vendors can be imported in bulk.

Three examples, three situations

  • Example · Manufacturer

    Answer once, for all your customers

    Three customers each send you their security questionnaire. In your own space, you answer once and reuse your answers and your evidence, question by question, from one customer to the next.

  • Example · Multi-site company

    Critical suppliers first

    You depend on hundreds of suppliers. Forta Suppliers ranks the ones that touch your data or your operations, monitors them continuously and keeps the others under simple tracking.

  • Example · Prime contractor

    What a supplier declares, and what is observed

    A supplier declares itself compliant. The scan of its perimeter, which it validated itself, shows an exposed service. The gap is flagged, the supplier fixes it, asks for a new scan, and its grade updates.

What's included

Questionnaires

  • 3 levels: 24, 39 and 139 questions
  • 9 domains and 35 control domains
  • 6 thematic modules you can add
  • OT/ICS module for industrial suppliers
  • Every answer mapped to an SCF control
  • Inherent risk assessment and tiering

Scoring & depth

  • 0 to 100 score, A+ to F grades
  • Native external scan of the vendor's surface
  • Perimeter validated by the vendor, so it can be challenged
  • Re-scan on demand after remediation
  • Divergence flag between declared and observed
  • 500+ finding types applied to every vendor
  • First alert within 48 hours

Vendor portal & operations

  • Passwordless vendor portal, access by email code
  • Versioned, shareable evidence library
  • Answers reused from one client to the next
  • Shared catalogue: a known vendor is not re-scanned
  • 12 configurable alert policies
  • Remediation requests with deadline and reminders
  • 5 registers exportable to XLSX
  • Bulk vendor import

Frameworks

  • NIST CSF 2.0
  • ISO 27001:2022
  • SOC 2
  • GDPR
  • Quebec Law 25
  • IEC 62443

Optional AI enrichment

AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.

In third-party risk, AI targets repetitive work: pre-filling a questionnaire from past answers, flagging an answer inconsistent with the evidence provided, summarizing a vendor file. The assessment and the score stay grounded in validated declarations and the observed scan.

Sovereignty: the platform is built and hosted in Canada, by a Canadian company. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.

Forta Suppliers is not a silo. The other modules feed it.

Continuous TPRM only has value because the other modules exist. That's what distinguishes it from a standalone TPRM product (BitSight, SecurityScorecard) or a TPRM module added to a GRC (OneTrust). Each pillar feeds a different dimension of third-party observation.

  • Forta Exposure → Forta Suppliers

    The 500+ EASM finding types are applied to each third party's perimeter. The native OT/ICS scanner is applied to industrial suppliers. The subdomain takeover detection engine on 83 services is applied to third-party exposed assets. No additional ingestion cost.

  • Forta Radar → Forta Suppliers

    The 100+ aggregated CTI sources and 2,000+ tracked actors are filtered by third-party industry sector. If BlackBasta targets the healthcare sector and one of your healthcare suppliers has an exposed critical CVE, you see it immediately, before the attack.

  • Forta Compliance → Forta Suppliers

    The 1,534+ SCF controls mapped across 40+ frameworks serve as a reference for alignment drift. If a third party declares SOC 2, FortaRisks observes external signs of that alignment (TLS, MTA-STS, security headers) and alerts on drift vs declaration.

  • Forta Cockpit → Forta Suppliers

    The third-party score contributes to your organization's overall risk score. Cross-module prioritization takes your third parties into account: a critical CVE on one of your critical third parties is prioritized over a medium CVE on one of your unexposed direct assets.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.

Frequently asked questions

How is this different from an external score like BitSight or SecurityScorecard?

Those give you a grade from a closed methodology. FortaRisks exposes every finding behind a vendor's score, by dimension, so the vendor can dispute it point by point and you can defend your decision with technical proof.

Does the vendor have to cooperate for the initial assessment?

No. The external scan starts without them and already yields an observed posture. Their cooperation adds the declarative side, the evidence library and perimeter validation, which makes the score challengeable and therefore defensible. Since they can reuse past answers, the cost of entry is low for them.

Does the OT/ICS scanner apply to vendors?

Yes. Categorize a vendor as OT or industrial at onboarding and the native OT/ICS scanner is included in their continuous surface scan, read-only with adapted rate limiting.

What happens when a third party disputes its score?

The scanned perimeter is the one they validated, so the discussion is about recognized assets, not questionable attribution. They fix, request a new scan, and the score updates.