Complies

VENDOR REGISTER · TIERING · REVIEWS

Vendor risk management software: third party risk management software and a TPRM platform for teams of 5 to 200

Every third party in one register, tiered by the data it can reach, with the SOC 2 report, the questionnaire, the insurance certificate and the DPA tracked against a renewal date somebody owns.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
TPRM

What vendor risk management software actually does

Vendor risk management software keeps one register of every third party your company depends on, tiers each vendor by the data and the access it holds, stores the due diligence you collected, and reminds a named owner to re-review before that evidence goes stale. Third party risk management software is the same product under a different label, and TPRM is the abbreviation most buyers pick up somewhere around their first audit. The reason it becomes urgent is external: your auditor holds you responsible for your suppliers. SOC 2 criterion CC9.2 asks how you assess and manage vendor risk, ISO 27001 spends four controls on it in A.5.19 through A.5.22, PCI DSS v4.0.1 Requirement 12.8 governs third party service provider relationships, HIPAA requires a business associate agreement before a vendor touches PHI, and GDPR Article 28 sets what has to be in a processor contract. A critical vendor with no security review on file is a finding in every one of those. Complies is vendor risk management software built for companies of 5 to 200 people, where the vendor list is somewhere between forty and three hundred SaaS tools and nobody is employed full time to chase them. The register starts from the integrations you already connect, then you tier each vendor by what it can reach: a payroll processor holding employee data and an analytics widget on the marketing site are not the same risk and should not eat the same effort. Each tier gets a review cadence, and each vendor carries the artifacts that actually matter, a current SOC 2 report or ISO 27001 certificate, a completed security questionnaire, a certificate of insurance, and a signed data processing agreement, each with an owner and an expiry date so nothing lapses in silence. The category splits three ways and the split matters more than any feature list. Security ratings platforms like UpGuard, Bitsight and SecurityScorecard scan a vendor from the outside and score it continuously. Enterprise TPRM suites like ProcessUnity, Prevalent, Venminder and OneTrust run heavy assessment workflows for organizations with a dedicated third party risk team. Compliance platforms including Vanta, Drata and Complies fold vendor risk into the same system as your controls and evidence, because for most companies the reason vendor risk exists at all is the audit. Complies publishes its prices, $79, $199 and $499 a month, with vendor risk included from Growth and monthly billing available. Two honest limits: Complies does not scan your vendors from the outside, so there is no security rating or continuous breach feed, and a human still has to read the SOC 2 report and decide whether the vendor is acceptable. What changes is that the decision, the date, the owner and the proof all live in one place your auditor can open.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated August 2026

THE THREE JOBS

The three jobs a vendor risk program has to do

1

Know who your vendors actually are

Most small companies discover their real vendor list during their first audit, and it is longer than the finance export suggests. The register pulls from the identity provider and the integrations you already connect, then you add the ones nobody expensed. Every entry carries an owner, what data it can reach, and whether it is in scope for the frameworks you are chasing.

vendor due diligence software
2

Tier the list so the work is survivable

Reviewing three hundred vendors to the same depth is how a program dies in month two. Tiering by data sensitivity and access sets the depth: a critical processor gets a full questionnaire and an annual review, a marketing tool that sees no customer data gets a light check and a longer cycle. Auditors accept a risk-based approach. They do not accept a flat one you clearly abandoned.

compliance risk register
3

Make the review happen on schedule, with proof

The failure mode is never intent, it is the calendar. Review dates, certificate expiries and questionnaire refreshes sit on the compliance calendar with a named owner and a reminder that fires before the date. Every completed review leaves a dated record, which is exactly the artifact CC9.2 and A.5.22 ask you to produce.

automated evidence collection
COMPARE

Three kinds of vendor risk management software, and who each one is for

Buyers usually compare these three groups as if they were the same product. They are not. They answer different questions, they cost very different amounts, and picking the wrong group is how a 40 person company ends up paying enterprise money for a workflow engine nobody fills in. Here is the honest map, including where Complies is the wrong answer.

Dimension Security ratings platform Enterprise TPRM suite Complies
Example vendors UpGuard, Bitsight, SecurityScorecard ProcessUnity, Prevalent, Venminder, OneTrust Complies
Core question answered How exposed does this vendor look from the outside, right now How do we run a governed assessment workflow across hundreds of third parties Do we have a defensible vendor program our auditor will accept
How it works Continuous external scanning produces a score per vendor Questionnaire libraries, workflow, scoring models, issue management One register tied to your controls, evidence and compliance calendar
Built for Security teams that want a live signal on supplier exposure Organizations with a dedicated third party risk function Teams of 5 to 200 where vendor risk is part of someone's week
Published pricing UpGuard publishes Standard at $1,750 a month billed annually; higher tiers quote-only None of these publish figures. Quote-only, annual contracts $79, $199 and $499 a month, published, vendor risk from Growth
Typical contract Annual, priced by vendors monitored Annual, often with an implementation project Monthly or yearly, self-serve signup, no sales call
Framework evidence Feeds a control, but is not the control record itself Deep, and priced accordingly SOC 2 CC9.2, ISO 27001 A.5.19 to A.5.22, PCI DSS 12.8 mapped in place
External scanning Yes, this is the product Often bundled or integrated No. Complies does not scan vendors from the outside

Read that honestly. If you need a live external signal on a supplier, a security ratings platform is the right buy and Complies does not replace it. If you employ a third party risk team and assess hundreds of suppliers with a governed workflow, an enterprise TPRM suite earns its price. If what you actually need is a defensible vendor register your SOC 2 or ISO 27001 auditor accepts, without a sales cycle, that is the middle of the road we built for. If you are weighing the compliance platforms that ship a TPRM module, compare them in detail on Vanta alternatives, Drata alternatives and OneTrust alternatives.

VENDOR BY VENDOR

Vendor risk management software compared, and what each one actually publishes

Pricing in this category is mostly hidden, which is the practical problem when you are trying to budget. Below is what each platform publishes on its own site as of August 2026, read directly rather than copied from a directory. Where a vendor publishes nothing, this table says so instead of guessing, because invented pricing is worse than no pricing.

Platform What it is Published pricing (August 2026) Best for
Complies Compliance platform with vendor risk built in Published: $79, $199, $499 a month. Vendor risk from Growth. Monthly billing Teams of 5 to 200 that need a defensible vendor program for an audit
UpGuard Security ratings and continuous external monitoring Standard $1,750 a month billed annually, monitors 50 vendors, additional vendors $79 a month. Professional, Corporate and Enterprise+ quote-only Security teams that want a live external exposure score per vendor
Bitsight Security ratings and cyber risk analytics No figures published. Quote-only Enterprises benchmarking supplier and portfolio cyber risk
SecurityScorecard Security ratings and supply chain detection No figures published. Quote-only Programs that want an outside-in rating alongside questionnaires
ProcessUnity Enterprise third party risk workflow suite No figures published on its site. Quote-only Dedicated third party risk teams running governed assessments
Prevalent Third party risk management platform and assessment services No figures published. Quote-only Programs that want assessments run for them as a managed service
Venminder TPRM platform with outsourced due diligence analysis No figures published. Quote-only Banks and financial institutions with examiner-driven requirements
OneTrust Privacy and GRC suite with a third party management module No figures published. Quote-only, modular Large organizations already buying privacy and consent modules
Vanta Compliance automation platform, TPRM sold standalone or as an add-on No figures published. Quote-only. Vendr reports a $20,000 median across 372 purchases, re-verified August 2026 Funded startups running a sales-led compliance rollout
Drata Compliance automation platform, TPRM bundled rather than sold separately No figures published. Quote-only. Vendr reports a $24,868 median, February 2026 Startups that want third party risk inside their audit platform

The Vendr medians are third party benchmark data from a company that brokers real software contracts, not vendor list prices, and they are included because they are the only figures in this category with a disclosed sample size. Treat them as a budgeting anchor, not a quote. Everything else in the pricing column was read off the vendor's own site in August 2026 and should be re-checked before you build a business case, because this category re-prices often.

CAPABILITIES

What vendor risk looks like when it is part of the same system as your controls

One register, every vendor tiered

Each third party sits in one list scored by the data it touches and the access it holds, so a payroll processor gets an annual review at depth and a low-risk design tool does not consume the same week. Tiering is the difference between a program and a pile of PDFs.

Documents with expiry dates and owners

The SOC 2 report, the ISO 27001 certificate, the completed questionnaire, the certificate of insurance and the signed DPA each carry a renewal date and a named human. When something is about to expire you find out beforehand, not when the auditor pulls the file.

Vendor evidence mapped to the control it proves

A completed vendor review is not a folder, it is evidence for SOC 2 CC9.2, ISO 27001 A.5.19 to A.5.22, PCI DSS Requirement 12.8 and, where PHI is involved, your HIPAA business associate obligations. Map it once and it counts in every framework you carry.

Reviews the calendar actually chases

Annual and quarterly reviews land on the same compliance calendar as your access reviews and policy reviews, with reminders that fire early. Most vendor programs do not fail because someone decided not to review a supplier. They fail because the date passed quietly.

Questionnaires you send instead of receive

Your own security questionnaire goes out from the same place your inbound ones get answered, so the vendor file holds the questions you asked and the answers you got, dated, rather than a thread in somebody's email.

Prices you can read before a call

Starter $79 a month, Growth $199, Scale $499, all published, with vendor risk management included from Growth and monthly billing available. You can size this before you talk to anyone, which in this category is unusual.

SETUP

From an unknown vendor list to a program an auditor accepts

01

Build the register from what you already run

Connect AWS, GitHub, Google Workspace and Okta and let the SaaS you actually use populate the list, then add the tools that never went through IT. The first version is always longer than anybody expects, and that is the point.

02

Tier by data and access, not by invoice size

Sort each vendor by what it can reach: customer data, employee data, production access, or nothing sensitive at all. Spend is a bad proxy for risk, and the cheapest tool in the list is often the one with an API key into production.

03

Collect the four things that matter per tier

For critical vendors: a current SOC 2 report or ISO 27001 certificate, a completed security questionnaire, a certificate of insurance, and a signed DPA or BAA. For low-tier vendors, a lighter check and a longer cycle is a defensible decision as long as it is written down.

04

Put every review on the calendar and let it run

Set a cadence per tier, assign an owner, and let reminders do the chasing. When the audit arrives you export the vendor section of the evidence pack instead of reconstructing a year of decisions from memory.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • A customer or auditor has asked how you assess the vendors that touch their data.
  • You are chasing SOC 2, ISO 27001, HIPAA or PCI DSS and the vendor section is the thin part.
  • Your vendor list lives in a spreadsheet that nobody has opened since the last audit.
  • You want vendor risk in the same system as your controls, evidence and policies.
  • You want to see the price before a sales call, and start the same afternoon.

LOOK ELSEWHERE WHEN

  • You need continuous external scanning and a live security rating per vendor.
  • You employ a dedicated third party risk team assessing hundreds of suppliers with a governed workflow.
  • You are a bank or insurer with examiner-driven due diligence and outsourced analyst reports.
  • You need fourth party and supply chain mapping beyond your direct suppliers.
  • You want questionnaire responses reviewed for you as a managed service.
QUESTIONS

Common questions about vendor risk management software

Vendor risk management software is one system that holds every third party your company relies on, scores each by the risk it introduces, stores the due diligence you collected, and enforces a review cadence with named owners. It replaces the spreadsheet and the shared drive folder with a record that shows an auditor you are actively managing suppliers rather than listing them once at onboarding.

It is the same category. Third party risk management software, vendor risk management software and TPRM platform all describe a tool that inventories your suppliers, assesses the risk each one carries, tracks the evidence behind that assessment, and re-checks it on a schedule. Enterprise buyers tend to say third party risk, smaller teams tend to say vendor risk, and the product does the same job.

Most of the category is quote-only. UpGuard publishes Standard at $1,750 a month billed annually for 50 monitored vendors, with extra vendors at $79 a month, and its higher tiers are quote-only. Bitsight, SecurityScorecard, ProcessUnity, Prevalent, Venminder, OneTrust, Vanta and Drata publish no figures at all. Complies publishes $79, $199 and $499 a month, with vendor risk included from the $199 Growth plan.

Yes, in substance. SOC 2 criterion CC9.2 covers assessing and managing risks from vendors and business partners, and auditors test it by asking for your vendor inventory, how you tiered it, and evidence that reviews happened. A critical vendor with no security review on file is one of the more common findings in a first Type 2.

Yes. ISO/IEC 27001:2022 Annex A devotes four controls to it: A.5.19 information security in supplier relationships, A.5.20 addressing security within supplier agreements, A.5.21 managing security in the ICT supply chain, and A.5.22 monitoring, review and change management of supplier services. A.5.22 is the one that catches people, because it asks for evidence you re-check suppliers on a schedule.

Vendor management is commercial: contracts, renewals, spend, performance and the relationship. Third party risk management is about the risk that supplier introduces to your data, your operations and your compliance obligations. They overlap in the register and diverge in what you do next. A procurement tool tracks the contract value; a TPRM tool tracks whether the vendor can be trusted with production access.

A vendor risk assessment is the structured review you run on a single supplier before you onboard it and then periodically afterwards: what data it will touch, what access it needs, what its security posture looks like, and what contractual protections you have. The output is a tier, a decision, an owner and a review date. Our full walkthrough covers the tiering model, the questionnaire and what to collect at each tier.

No, and trying is how programs collapse. A risk-based approach is what the frameworks expect: assess depth in proportion to the data and access involved. A vendor holding customer records or production credentials earns a full questionnaire and an annual review. A stock photo subscription earns a line in the register and a note explaining why it stops there. Write the reasoning down, because the reasoning is what gets tested.

For a critical vendor: a current SOC 2 Type 2 report or ISO 27001 certificate, a completed security questionnaire, a certificate of insurance, a signed data processing agreement, and a business associate agreement if PHI is involved. Read the SOC 2 rather than filing it, because the exceptions in Section 4 and the complementary user entity controls are the parts that actually change what you have to do.

For ten or fifteen vendors, honestly yes, and we will say so. It stops working at the point where certificates start expiring, owners change, and nobody notices for eight months, which in practice is somewhere between thirty and fifty vendors. The tell is simple: if you cannot answer "when was this vendor last reviewed and by whom" in under a minute, the spreadsheet has already failed.

A security ratings platform such as UpGuard, Bitsight or SecurityScorecard scans a vendor from the outside and produces a continuously updated score. That is a genuinely useful signal and Complies does not produce it. What Complies produces is the program record: the tier, the documents, the decision, the owner, the review dates and the mapping to SOC 2, ISO 27001 and PCI DSS control requirements. Larger programs run both.

More than the finance report shows. Once you count SaaS bought on a card, tools connected through OAuth, and subprocessors of your main platforms, a 50 person software company commonly lands somewhere between 60 and 150 third parties. The first honest inventory is usually the most useful thing a vendor risk program produces, because it surfaces the ones nobody was tracking at all.

GO DEEPER

Frameworks and guides

Vendor risk in the same system as your controls and evidence

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.