scoping banner2

TPRM Scoping Study

WHY IT MATTERS

You May Already Be Required to Manage This.

Third-party risk management isn’t a best practice reserved for enterprise organizations. For many mid-market businesses, it’s a documented compliance obligation — built into HIPAA Business Associate requirements, NIST 800-171 supply chain provisions, PCI-DSS, enterprise vendor contracts, and cyber insurance policy conditions.

You may not call it TPRM. But every vendor who touches your sensitive data — patient records, financial data, PII, CUI, proprietary systems — is a point of exposure that your regulators, insurers, and enterprise clients expect you to manage.

HIPAA /
Business Associates

If your business is a Covered Entity or Business Associate under HIPAA, you are required to have written agreements with vendors who access Protected Health Information — and to conduct reasonable due diligence on their security practices. Undocumented vendor relationships are among the most commonly cited HIPAA vulnerabilities.

NIST 800-171 /
CMMC

Federal contractors and subcontractors handling Controlled Unclassified Information (CUI) are required under NIST 800-171 to manage third-party access to CUI. CMMC certification extends this obligation formally. If your clients work with the federal government, their supply chain security requirements flow down to you — and to your vendors.

PCI-DSS

The PCI Data Security Standard requires organizations to manage third-party service providers who handle cardholder data. Vendor due diligence and ongoing monitoring are explicit requirements, not optional additions.

Cyber
Insurance

Insurers are beginning to ask about vendor risk management practices at renewal. Demonstrating a documented, active TPRM program positions you favorably in underwriting conversations — and may be required as a condition of coverage.

Enterprise Contracts

Vendor agreements with enterprise clients increasingly include third-party risk requirements — requiring you to demonstrate that you’ve assessed and monitor the vendors who handle data you received from that enterprise client. One contract clause can create an immediate, non-negotiable TPRM obligation.

SCOPING STUDY

A Fixed-Fee Engagement That Defines Your Vendor Risk Perimeter.

Before you can manage vendor risk, you need to understand it. The TPRM Scoping Study is a 30-day engagement that maps your sensitive data, identifies which vendors have access to it, and establishes whether and to what extent a formal TPRM program is warranted — and what that program would involve.

It answers the questions many organizations have never formally asked: What constitutes sensitive data in our specific context? Which vendors actually touch it? What are our obligations? What would a program cost?

What You Get:

• A vendor audit
• A penetration test
• A generic checklist that you forward
to your vendors
• A software-generated output
• A static document

Vendor qualification is determined by data flow, not product type. A vendor whose product connects to, processes, or accesses your systems or customer data may be in scope regardless of the apparent nature of their product or service

A note on data segregation
Limiting which systems and vendors can access sensitive data reduces your attack surface — and your compliance scope. For PCI-DSS and CUI environments, unsegregated data means your entire network infrastructure is in scope for audit. That is a costly oversight that many organizations don’t discover until it’s too late. One of the practical benefits of the Scoping Study is identifying opportunities to tighten that perimeter before a full program begins.

DELIVERABLES

Everything You Need to Better Understand Your Obligations.

Scoping Study
Report

A formal written report documenting your sensitive data definition, data flow maps, vendor inventory, compliance obligation landscape, and a block assignment recommendation. Written in plain business language — suitable for ownership, legal counsel, or regulators.

A structured document listing your identified in-scope vendors with placeholder fields for information to be gathered later. A partially completed inventory at this stage with documented gaps is more defensible than no inventory at all.

Block Assignment Recommendation

Delivered within 30 days of engagement start.

PRICING

Transparent. Fixed. No Surprises.

$7,500

Flat Fee – No Ongoing Commitment

Conversion Credit:
Clients who engage a full 3-Year TPRM Program within 90 days of their Scoping Study receive the full $7,500 fee as a credit toward their $15,000 TPRM Program foundation phase fee. The scoping study isn’t a sunk cost — it’s a head start on a program you may already need.

THE PROCESS

Simple. Structured. Delivered in 30 Days.

process 1

Engage

Sign a simple services agreement. No long-term commitment required. We schedule your kickoff call and begin gathering information about your business, your data, and your vendor relationships.

process 2

Map

We work with you to define your sensitive data, map how it flows through your organization, and identify which vendors touch it — based on access, not assumptions. This typically involves two to three working sessions with your team.

process 3

Scope

We identify your in-scope vendor population, assess your compliance obligations, and establish a preliminary block assignment. You develop a clear understanding of what a full program would involve before committing to one.

process 4

Report

You receive your complete deliverable package — Scoping Study Report, Preliminary Vendor Inventory, and Block Recommendation — within 30 days. We walk through the findings together and answer your questions.

IS THIS RIGHT FOR YOU?

The TPRM Scoping Study Is the Right Starting Point If…

You should start here if:

You’ve done a scoping study and know your vendor population — now you need active management
Your TPRM obligation is immediate and non-negotiable
You’re already engaged in the Cybersecurity Governance Program and want to extend your due diligence to vendors
You want a partner managing your vendor risk function, not just a document
You’re ready to jump in — the full TPRM Program includes a scoping study as part of the 90-day Foundation Phase

Not sure which is right for your situation? Schedule a 30-minute call and we’ll help you figure it out.

COMMON QUESTIONS

Ready to better understand your vendor risk obligation?

Schedule a 30-minute conversation. We’ll discuss your specific situation, your compliance obligations, and whether a TPRM Scoping Study is the right starting point for your business.