Forta Suppliers
Third-party risk (TPRM)
The real posture of your vendors, not their questionnaire
The questionnaire your vendor fills in, continuously cross-checked against a scan of their real attack surface. The gap between what they declare and what their surface shows becomes an explicit signal, and the scan covers a perimeter they validated themselves, so it can be challenged and re-run after remediation.

48 hours
To first alert
0 to 100
Vendor score, A+ to F
500+
Finding types per vendor
The annual questionnaire is already out of date.
A once-a-year form does not tell you when a vendor is actually exposed or breached.
Outcomes your team will feel.
The vendor cannot contradict themselves
Declared and observed side by side, with a flag when the two diverge.
A scan they can challenge
Perimeter validated by the vendor, re-scan on demand after remediation: the opposite of attribution false positives.
Questionnaire fatigue, handled
Answers reused from one client to the next, passwordless portal, versioned evidence.
Key capabilities
Declared and observed, reconciled
On one side the vendor's questionnaire, on the other a native external scan of their surface. Both are cross-checked continuously without being merged, and a divergence between what is declared and what is observed is raised as an explicit flag. That is what ratings lack, having only the observed, and what questionnaires lack, having only the declared.
The vendor answers once, for every client
By our estimate, a vendor receives around 37 assessment requests a month. In their own space they answer once and reuse those answers from one client to the next, question by question or by SCF control. No network or marketplace to build: the SCF link is what makes reuse possible.
Passwordless portal and versioned evidence
The vendor signs in with a code sent by email, with no account to create and no licence to buy. They build a versioned evidence library they can share again. The catalogue is shared: a vendor already known to the platform is not re-scanned for every new client.
Three questionnaire levels, including an OT/ICS module
From a 24-question baseline to a full 139-question assessment across 9 domains and 35 control domains, plus 6 thematic modules you can add. One of them covers OT and ICS, for your industrial suppliers. Every answer maps to an SCF control, which gives NIST, ISO 27001, SOC 2 and GDPR coverage with no extra work.
Share reports for remediation
Export a vendor's report and hand it to them, turning your assessment into their improvement, with no extra licence for them.
Questionnaires on demand
When a posture degrades and you need depth, send a targeted questionnaire for the detail external scanning cannot see, not a yearly blanket survey.
A degradation becomes a dated remediation request.
Twelve configurable alert policies trigger on a score drop, a grade crossing or a new critical finding. The remediation request goes out with a deadline and reminders, and surfaces in the Action Center as well as the risk register. Five registers are exportable, and vendors can be imported in bulk.
Three examples, three situations
- Example · Manufacturer
Answer once, for all your customers
Three customers each send you their security questionnaire. In your own space, you answer once and reuse your answers and your evidence, question by question, from one customer to the next.
- Example · Multi-site company
Critical suppliers first
You depend on hundreds of suppliers. Forta Suppliers ranks the ones that touch your data or your operations, monitors them continuously and keeps the others under simple tracking.
- Example · Prime contractor
What a supplier declares, and what is observed
A supplier declares itself compliant. The scan of its perimeter, which it validated itself, shows an exposed service. The gap is flagged, the supplier fixes it, asks for a new scan, and its grade updates.
What's included
Questionnaires
- 3 levels: 24, 39 and 139 questions
- 9 domains and 35 control domains
- 6 thematic modules you can add
- OT/ICS module for industrial suppliers
- Every answer mapped to an SCF control
- Inherent risk assessment and tiering
Scoring & depth
- 0 to 100 score, A+ to F grades
- Native external scan of the vendor's surface
- Perimeter validated by the vendor, so it can be challenged
- Re-scan on demand after remediation
- Divergence flag between declared and observed
- 500+ finding types applied to every vendor
- First alert within 48 hours
Vendor portal & operations
- Passwordless vendor portal, access by email code
- Versioned, shareable evidence library
- Answers reused from one client to the next
- Shared catalogue: a known vendor is not re-scanned
- 12 configurable alert policies
- Remediation requests with deadline and reminders
- 5 registers exportable to XLSX
- Bulk vendor import
Frameworks
- NIST CSF 2.0
- ISO 27001:2022
- SOC 2
- GDPR
- Quebec Law 25
- IEC 62443
Optional AI enrichment
AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.
In third-party risk, AI targets repetitive work: pre-filling a questionnaire from past answers, flagging an answer inconsistent with the evidence provided, summarizing a vendor file. The assessment and the score stay grounded in validated declarations and the observed scan.
Sovereignty: the platform is built and hosted in Canada, by a Canadian company. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.
Forta Suppliers is not a silo. The other modules feed it.
Continuous TPRM only has value because the other modules exist. That's what distinguishes it from a standalone TPRM product (BitSight, SecurityScorecard) or a TPRM module added to a GRC (OneTrust). Each pillar feeds a different dimension of third-party observation.
Forta Exposure → Forta Suppliers
The 500+ EASM finding types are applied to each third party's perimeter. The native OT/ICS scanner is applied to industrial suppliers. The subdomain takeover detection engine on 83 services is applied to third-party exposed assets. No additional ingestion cost.
Forta Radar → Forta Suppliers
The 100+ aggregated CTI sources and 2,000+ tracked actors are filtered by third-party industry sector. If BlackBasta targets the healthcare sector and one of your healthcare suppliers has an exposed critical CVE, you see it immediately, before the attack.
Forta Compliance → Forta Suppliers
The 1,534+ SCF controls mapped across 40+ frameworks serve as a reference for alignment drift. If a third party declares SOC 2, FortaRisks observes external signs of that alignment (TLS, MTA-STS, security headers) and alerts on drift vs declaration.
Forta Cockpit → Forta Suppliers
The third-party score contributes to your organization's overall risk score. Cross-module prioritization takes your third parties into account: a critical CVE on one of your critical third parties is prioritized over a medium CVE on one of your unexposed direct assets.
Explore the other modules.
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.
Frequently asked questions
How is this different from an external score like BitSight or SecurityScorecard?
Those give you a grade from a closed methodology. FortaRisks exposes every finding behind a vendor's score, by dimension, so the vendor can dispute it point by point and you can defend your decision with technical proof.
Does the vendor have to cooperate for the initial assessment?
No. The external scan starts without them and already yields an observed posture. Their cooperation adds the declarative side, the evidence library and perimeter validation, which makes the score challengeable and therefore defensible. Since they can reuse past answers, the cost of entry is low for them.
Does the OT/ICS scanner apply to vendors?
Yes. Categorize a vendor as OT or industrial at onboarding and the native OT/ICS scanner is included in their continuous surface scan, read-only with adapted rate limiting.
What happens when a third party disputes its score?
The scanned perimeter is the one they validated, so the discussion is about recognized assets, not questionable attribution. They fix, request a new scan, and the score updates.