Frequently asked questions
Vendor compliance and third-party risk management, explained.
New here? Start with Why CompliantVendor for the big picture.
What is CompliantVendor?
CompliantVendor is a vendor compliance and third-party risk management platform that helps organizations assess, monitor, and document vendor security, privacy, compliance, and operational risks.
Who should use CompliantVendor?
CompliantVendor is designed for:
- Small businesses
- Mid-sized organizations
- Enterprise organizations
- Healthcare providers
- Government contractors
- Managed service providers
- Software companies
- Compliance and security teams
Why do organizations assess vendors?
Organizations assess vendors to understand risks associated with third-party relationships and to ensure vendors meet security, privacy, and compliance requirements before sensitive information or system access is provided.
Are vendor questionnaires always required?
Not always. The level of assessment typically depends on the risk associated with the vendor relationship. For example:
- Office supply vendors may require little or no review.
- Software providers handling customer information may require a comprehensive assessment.
- Vendors processing regulated data often require detailed security and compliance reviews.
Who sends the questionnaire?
Typically, the customer sends a questionnaire to the vendor. The customer is evaluating the vendor's ability to securely protect information and meet contractual requirements.
What about AWS, Microsoft 365, Azure and Salesforce? They won't answer questionnaires.
They won't, and they never will β and CompliantVendor is built on that assumption rather than pretending otherwise. Providers at that scale publish their assurance instead of answering yours, so they are documented from it.
Add a vendor called Amazon Web Services, or one whose website is aws.amazon.com, and CompliantVendor recognizes it: no questionnaire is sent, no portal invitation goes out, and you're pointed at the trust portal where their reports actually live (AWS Artifact, the Microsoft Service Trust Portal, and so on). The record they get instead is:
- The environment you actually use β GovCloud or us-east-1; GCC High or Commercial.
- Their certifications, with the documents attached β as many as you need.
- The shared-responsibility split β what you inherit and what stays yours.
- Your review β a named person at your organization, on a date. That review is the assessment.
You can mark any vendor this way yourself, and vendors already in your list who match a known provider will offer to switch over in one click.
Why does CompliantVendor ask which cloud environment we use?
Because a certification belongs to a specific environment, not to the brand β and this is where most programs go wrong.
Amazon's FedRAMP High authorization covers GovCloud (US). It does not cover us-east-1. Microsoft's covers Microsoft 365 GCC High. It does not cover Microsoft 365 Commercial. The provider's report will never tell you which region or tenant your data sits in β only a person at your organization can say that.
So CompliantVendor asks you to name the environment and to confirm, in as many words, that the certification on file covers it. Until someone does, nothing is marked satisfied. A green tick built on an authorization that covers somebody else's deployment is worse than no tick at all.
We put CUI in a cloud service. Is a SOC 2 report enough?
No β and this is the most common finding in the defense supply chain.
Where a cloud service stores, processes or transmits CUI, DFARS 252.204-7012 requires its provider to meet security requirements equivalent to the FedRAMP Moderate baseline β or an equivalent assessed against all of those controls by a FedRAMP-recognized 3PAO, with a Customer Responsibility Matrix as part of the evidence. A SOC 2 report, however clean, does not satisfy that clause.
The trap most people fall into: Microsoft 365 Commercial is FedRAMP Moderate authorized but is not built for DFARS 7012 CUI β that generally needs GCC High. CompliantVendor tells you this on the vendor page at the moment you're choosing the environment, refuses to mark the requirement met without the FedRAMP package actually on file, and blocks approval of a High or Critical vendor that falls short.
CompliantVendor surfaces the rule and the gap. It is not legal advice β confirm your specific services and regions against the provider's current FedRAMP Marketplace listing and your contract.
Can I send a vendor an NDA to sign?
Yes β inside CompliantVendor. Upload the NDA (or BAA, DPA, MSA) to the vendor's Agreements, and send it for signature. There is no third-party e-signature account to buy, and nothing for the vendor to sign up for: they get a secure passwordless link, read the document in the browser, and sign by drawing or typing their name.
You watch the status move β sent β viewed β signed β and the signed agreement lands back on the vendor record automatically.
The original document is never altered. CompliantVendor issues a separate Certificate of Electronic Signature recording who signed, when, from what IP address, and a SHA-256 hash of the exact document they saw. That hash is what makes the signature hold up β it binds this signature to that file, so the document cannot quietly be swapped afterwards.
Can assessments be shared with multiple customers?
Yes. CompliantVendor allows vendors to maintain a reusable compliance profile, reducing the need to repeatedly answer the same questions for every customer. The vendor authorizes each organization before any answers are shared, and controls which evidence each customer can see β so one answer set can serve many customers without exposing everything to everyone.
I'm a vendor on CompliantVendor β can I also assess my own vendors?
Yes. A business is often both: a vendor to its customers and an organization with its own vendors to assess. From your vendor portal you can start a subscription ("Start assessing your vendors") to get an organization account β one login then does both. Your existing questionnaire answers and evidence stay linked and keep serving the organizations that assess you; switch to My Profile any time to respond to your customers.
Can I share my profile before a customer invites me?
Yes. From your portal you can invite a customer by email to receive your security questionnaire and evidence. They start a free trial and add you as a vendor; you authorize them, and your single profile keeps them in sync along with everyone else.
How do vendors complete the questionnaire?
Vendors work through a guided questionnaire one question at a time, organized by section. Each question shows a status β Not Started, Incomplete, Complete, or Marked for Review β so vendors can see what's left and flag anything they want to revisit.
- Only the questions that apply to how the vendor was classified are shown.
- Where evidence is requested, the vendor sees exactly what to provide and can attach one or more files, each with a document title and description.
- Answers and evidence save as the vendor goes, and update the live profile shared with authorized customers.
Does the vendor control what evidence is shared?
Yes. Evidence is private by default. For each document or questionnaire file, the vendor chooses which authorized organizations may see it β so a vendor can provide a System Security Plan to one customer without exposing it to others. Items a vendor hasn't shared appear to the organization as βevidence withheld,β which the organization can request directly.
What types of questionnaires can be managed?
Organizations can create and manage assessments covering:
- Cybersecurity
- Privacy
- HIPAA
- SOC 2
- NIST
- CMMC
- Artificial Intelligence
- Business Continuity
- Incident Response
- Vendor-specific requirements
Can supporting evidence be collected?
Yes. Organizations can request, collect, review, and securely store supporting evidence such as policies, audit reports, certifications, training records, and security documentation.
Does CompliantVendor support AI governance assessments?
Yes. Organizations can evaluate vendor use of Artificial Intelligence, data handling practices, governance controls, security protections, and compliance requirements through configurable AI-focused questionnaires.
How does CompliantVendor help with audits?
CompliantVendor maintains centralized records of assessments, evidence, findings, remediation activities, and approvals, making it easier to demonstrate compliance during internal reviews, customer audits, and regulatory assessments.
Can CompliantVendor be used for regulatory compliance programs?
Yes. CompliantVendor can support vendor management activities associated with:
- HIPAA
- SOC 2
- NIST Cybersecurity Framework
- NIST SP 800-171
- CMMC
- ISO 27001
- Other industry and customer-specific compliance requirements
What is continuous monitoring?
A vendor's posture changes over time β certifications lapse, controls change, evidence is replaced. CompliantVendor treats each vendor's questionnaire as a living profile rather than a point-in-time form. When a vendor updates an answer or evidence you've already reviewed, CompliantVendor notifies your organization to assess the change and determine whether the vendor still meets your requirements β so compliance stays current between formal reviews.
How will I know when a vendor changes their answers or evidence?
You're notified three ways, without having to watch the vendor manually:
- Re-review flags β any answer you previously reviewed that the vendor later changes is marked βchanged β re-reviewβ on the questionnaire.
- In-app alerts β a notice appears on your dashboard and on the vendor's record listing vendors with updates.
- Weekly email digest β a once-weekly summary emails your team the names of vendors that made updates, with a link to log in and review.
Each notice prompts you to reassess the change and decide whether the vendor still meets your organization's requirements. Re-reviewing an item clears its flag automatically.
How does CompliantVendor reduce risk?
CompliantVendor helps organizations identify vendor risks before onboarding, document security and compliance controls, track remediation efforts, and continuously monitor third-party relationships β alerting you to changes so risk is managed throughout the vendor lifecycle, not just at onboarding.
Is multi-factor authentication required?
Strongly recommended, but not forced. Your account can reach every vendor's security questionnaire, their evidence, and your signed agreements β MFA means a stolen or reused password isn't enough to open any of it, and setup takes about a minute with Google or Microsoft Authenticator.
You can skip it at first sign-in and switch it on later; a quiet reminder sits on your dashboard until you decide. Turn it on or off any time from My Account. Turning it off asks for your password first β a hijacked session must not be able to remove the very control that would have stopped it.
What happens when I reach my plan's vendor limit?
On plans that offer it, you can buy extra vendor slots one at a time instead of jumping to the next tier β so a customer on a 25-vendor plan who needs 28 doesn't have to move to unlimited. The extras are added to your existing subscription, so they arrive on the same invoice rather than as a second bill.
Billing shows the new monthly total before you commit, and afterwards the plan card tells you exactly what will be charged next and when β the plan price plus the add-ons, itemized.
Can I see my invoices and payment history?
Yes. Billing lists every payment with its outcome β succeeded or failed β and each invoice links to its receipt. The whole history exports to CSV for your finance team.
Failed payments are recorded permanently, even after a later retry succeeds, so the history reflects what actually happened rather than only the happy ending.
How do I get help?
Raise a support request from Support in the app β describe the problem, tell us which page it happened on, and say how you'd prefer to be reached. You'll see the status move (new β in progress β waiting on you β resolved) and the whole conversation stays in one thread instead of scattering across email.
Every role can raise a request β you don't need to track down an Admin first.
Still have questions?
Create an account to explore the platform, or learn more about how it works.