WHY IT MATTERS
You May Already Be Required to Manage This.
Third-party risk management isn’t a best practice reserved for enterprise organizations. For many mid-market businesses, it’s a documented compliance obligation — built into HIPAA Business Associate requirements, NIST 800-171 supply chain provisions, PCI-DSS, enterprise vendor contracts, and cyber insurance policy conditions.
You may not call it TPRM. But every vendor who touches your sensitive data — patient records, financial data, PII, CUI, proprietary systems — is a point of exposure that your regulators, insurers, and enterprise clients expect you to manage.
HIPAA /
Business Associates
If your business is a Covered Entity or Business Associate under HIPAA, you are required to have written agreements with vendors who access Protected Health Information — and to conduct reasonable due diligence on their security practices. Undocumented vendor relationships are among the most commonly cited HIPAA vulnerabilities.
NIST 800-171 /
CMMC
Federal contractors and subcontractors handling Controlled Unclassified Information (CUI) are required under NIST 800-171 to manage third-party access to CUI. CMMC certification extends this obligation formally. If your clients work with the federal government, their supply chain security requirements flow down to you — and to your vendors.
PCI-DSS
–
The PCI Data Security Standard requires organizations to manage third-party service providers who handle cardholder data. Vendor due diligence and ongoing monitoring are explicit requirements, not optional additions.
Cyber
Insurance
Insurers are beginning to ask about vendor risk management practices at renewal. Demonstrating a documented, active TPRM program positions you favorably in underwriting conversations — and may be required as a condition of coverage.
Enterprise Contracts
Vendor agreements with enterprise clients increasingly include third-party risk requirements — requiring you to demonstrate that you’ve assessed and monitor the vendors who handle data you received from that enterprise client. One contract clause can create an immediate, non-negotiable TPRM obligation.
SCOPING STUDY
Before you can manage vendor risk, you need to understand it. The TPRM Scoping Study is a 30-day engagement that maps your sensitive data, identifies which vendors have access to it, and establishes whether and to what extent a formal TPRM program is warranted — and what that program would involve.
It answers the questions many organizations have never formally asked: What constitutes sensitive data in our specific context? Which vendors actually touch it? What are our obligations? What would a program cost?
What You Get:
• Identification of Compliance obligations
• Identification of sensitive data
• Sensitive data flow mapping
• List of vendors with access
• Point of access by vendors
This Is Not:
• A vendor audit
• A penetration test
• A generic checklist that you forward to your vendors
• A software-generated output
• A static document
Vendor qualification is determined by data flow, not product type. A vendor whose product connects to, processes, or accesses your systems or customer data may be in scope regardless of the apparent nature of their product or service
DELIVERABLES
Everything You Need to Better Understand Your Obligations.
Scoping Study
Report
A formal written report documenting your sensitive data definition, data flow maps, vendor inventory, compliance obligation landscape, and a block assignment recommendation. Written in plain business language — suitable for ownership, legal counsel, or regulators.
Vendor
Inventory
A structured document listing your identified in-scope vendors with placeholder fields for information to be gathered later. A partially completed inventory at this stage with documented gaps is more defensible than no inventory at all.
Block Assignment Recommendation
A clear recommendation of which pricing block your vendor population falls into (Block 1: 1–8 vendors / Block 2: 9–16 / Block 3: 17–24), along with the rationale. If you proceed to a full program, the definitive count is confirmed during the foundation phase.
Delivered within 30 days of engagement start.
PRICING
Transparent. Fixed. No Surprises.
$7,500
Flat Fee – No Ongoing Commitment
Conversion Credit:
Clients who engage a full 3-Year TPRM Program within 90 days of their Scoping Study receive the full $7,500 fee as a credit toward their $15,000 TPRM Program foundation phase fee. The scoping study isn’t a sunk cost — it’s a head start on a program you may already need.
THE PROCESS
Simple. Structured. Delivered in 30 Days.

Engage
Sign a simple services agreement. No long-term commitment required. We schedule your kickoff call and begin gathering information about your business, your data, and your vendor relationships.

Map
We work with you to define your sensitive data, map how it flows through your organization, and identify which vendors touch it — based on access, not assumptions. This typically involves two to three working sessions with your team.

Scope
We identify your in-scope vendor population, assess your compliance obligations, and establish a preliminary block assignment. You develop a clear understanding of what a full program would involve before committing to one.

Report
You receive your complete deliverable package — Scoping Study Report, Preliminary Vendor Inventory, and Block Recommendation — within 30 days. We walk through the findings together and answer your questions.
The TPRM Scoping Study Is the Right Starting Point If…
You should start here if:
✔︎ You’ve received a notice — from a regulator, insurer, enterprise client, or lender — to demonstrate how you manage vendor security practices
✔︎ You handle sensitive data — health information, financial data, PII, CUI, or proprietary systems — and use third-party vendors to do it
✔︎ You don’t know which of your vendors actually have access to sensitive data
✔︎ A client or prospect has asked about your vendor risk management program and you can’t answer
✔︎ Your cyber insurance renewal is approaching and you expect questions about third-party risk
✔︎ You’re in or adjacent to a HIPAA, NIST 800-171, or PCI-DSS environment and haven’t formally addressed vendor obligations
✔︎ You want to understand what a bona fide TPRM program would involve before committing to one
You may be ready for the full program instead:
➤ You’ve done a scoping study and know your vendor population — now you need active management
➤ Your TPRM obligation is immediate and non-negotiable
➤ You’re already engaged in the Cybersecurity Governance Program and want to extend your due diligence to vendors
➤ You want a partner managing your vendor risk function, not just a document
➤ You’re ready to jump in — the full TPRM Program includes a scoping study as part of the 90-day Foundation Phase
Not sure which is right for your situation? Schedule a 30-minute call and we’ll help you figure it out.
COMMON QUESTIONS
Ready to better understand your vendor risk obligation?
Schedule a 30-minute conversation. We’ll discuss your specific situation, your compliance obligations, and whether a TPRM Scoping Study is the right starting point for your business.
Ready for active vendor risk management?
The TPRM Scoping Study is the natural starting point. Clients who engage our 3-Year TPRM Program within 90 days receive their full $7,500 fee as a credit toward their TPRM Program foundation phase — making the study a zero-risk first step toward a complete program.
Need to manage your internal security program?
Our Cybersecurity Governance Program addresses your internal security posture. Running both programs concurrently qualifies for a $5,000 package discount on the TPRM foundation phase.

