Third-Party Risk Management

Your compliance obligations do not stop at your network edge.

Who this is for

Organizations that share CUI with subcontractors or suppliers, rely on MSPs or cloud providers within their assessment boundary, or carry DFARS flow-down obligations they have not passed down.

Problems we address

  • No inventory of which third parties access controlled information
  • Flow-down requirements accepted but never passed to subcontractors
  • MSP and cloud provider responsibilities undefined, with real gaps between them
  • Vendor security assessed once at onboarding and never revisited
  • No record of third-party risk decisions when a prime asks

Scope and approach

We identify every third party with access to your systems or controlled information, then establish what each is contractually and practically responsible for. Shared-responsibility gaps get documented and closed — the space between what your MSP assumes you handle and what you assume they handle is where most findings live.

From there we build an assessment process proportionate to risk. A supplier handling CUI warrants scrutiny a janitorial vendor does not.

Typical deliverables

  • Third-party inventory classified by access and data sensitivity
  • Shared responsibility matrix for MSPs and cloud providers
  • Vendor security assessment process and questionnaires
  • Contract and flow-down language review
  • Ongoing monitoring cadence and reassessment triggers
  • Documented risk decisions and acceptances

Framework and technology context

DFARS 252.204-7012 flow-down, NIST SP 800-171 requirements for external service providers, CMMC ESP and CSP considerations, and FedRAMP equivalency.

If you cannot name every third party that touches your controlled information, that is where we start.

Talk to a senior practitioner

Tell us about your contracts, your environment, and your timeline. We will tell you plainly what we would do first.