Tier vendors by the data and access they hold, then apply diligence proportionate to tier. A payroll processor and a design tool should not receive the same review. Auditors accept tiering; what they reject is treating every vendor identically or not at all.
Build the inventory first
You cannot tier what you have not listed. Reconcile three sources: your SSO application list, your card and invoice records, and your team's own answers.
A workable three-tier model
| Tier | Criteria | Diligence | Review cadence |
|---|---|---|---|
| Critical | Production access or customer data at scale | Full review: SOC 2 or ISO cert, pen test summary, DPA/BAA, subprocessors | Annual |
| Important | Internal or employee data, no production access | Certification evidence plus short questionnaire | Every 18-24 months |
| Low | No sensitive data, easily replaced | Record in inventory, basic checks | At renewal only |
What to actually read
Collecting a SOC 2 report and filing it unread is the most common failure. The value is in three places.
- The scope section: does it cover the service you actually use?
- The exceptions: what did the auditor find, and does it matter to you?
- The period: is the report current, or eighteen months stale?
- Subprocessors: who else gets your data downstream?
Ongoing monitoring without a team
- Set calendar reminders on certificate expiry dates
- Subscribe to status and security bulletins for critical vendors
- Re-check at contract renewal, which is a natural forcing function
- Reassess immediately after any vendor breach disclosure
What auditors want to see
A documented tiering rationale, evidence that critical vendors were reviewed, signed agreements where data is involved, and a reassessment record. Perfection across every vendor is not expected; a defensible, followed process is.
Key takeaways
- Tier by data and access, not by spend.
- Actually read scope, exceptions and period on vendor reports.
- Tie reviews to renewals so they happen without extra process.
- Auditors want a defensible process, not exhaustive coverage.
Frequently asked questions
How many tiers should we use?
Three is sufficient for most small teams. More tiers create classification debate without improving outcomes.
What if a critical vendor has no SOC 2?
Compensate: a detailed questionnaire, contractual commitments, restricted data scope, or accept and document the risk explicitly.
Do we need to assess fourth parties?
You should know who your critical vendors rely on. Full assessment of them is usually disproportionate for a small team.
How long does setup take?
Three to six weeks for inventory, tiering and first-round diligence on critical vendors.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call