Join our Newsletter — 33% off our NHI Course

Due Diligence

Due diligence is the set of checks completed before a third party is approved for use. It typically includes questionnaires, certifications, contracts, test results, and insurance review. The goal is to verify that the vendor’s controls match the organization’s risk tolerance before access is granted.

Expanded Definition

In security governance, due diligence is the structured evidence gathering that happens before a third party is trusted with data, systems, or operational access. It is broader than a simple vendor questionnaire. It usually combines control attestation, policy review, independent assurance reports, security test evidence, privacy terms, incident history, and contractual commitments so the approving organisation can judge whether the third party’s controls are adequate for the intended relationship.

Definitions vary across vendors and procurement functions, but in cyber risk management the term is best understood as a decision support process, not a one-time checklist. NIST Cybersecurity Framework 2.0 treats third-party risk as part of governance and risk management, which makes due diligence a foundational input to access decisions, onboarding, and ongoing oversight. Strong practice distinguishes due diligence from due care: due diligence asks whether the external party is acceptable; due care is the continuing duty to manage the risk after approval. The most common misapplication is treating due diligence as a form-filled approval gate, which occurs when teams accept self-attestation without validating the evidence behind it.

Examples and Use Cases

Implementing due diligence rigorously often introduces onboarding delay and review overhead, requiring organisations to weigh faster procurement against stronger risk decisions.

  • A cloud provider is reviewed against security questionnaires, SOC 2 reports, and contractual breach notification terms before production data is shared.
  • A payroll processor is assessed for access controls, encryption, incident response maturity, and privacy obligations before employee records are transferred.
  • A software supplier is asked for penetration test summaries, vulnerability management evidence, and subprocessor disclosures before integration into the development pipeline.
  • A managed service provider is evaluated for background screening, privileged access handling, and insurance coverage before remote administrative access is granted.
  • An AI service is reviewed for data handling, model training constraints, logging, and human oversight requirements before business users connect sensitive workflows.

For security teams, the practical test is whether the evidence collected supports a risk-based decision rather than a paperwork exercise. Guidance from NIST Cybersecurity Framework 2.0 is especially useful when mapping third-party review to governance and supply chain risk expectations.

Why It Matters for Security Teams

Due diligence matters because third parties often become extensions of the organisation’s trust boundary. Weak review processes can lead to approving vendors with poor access controls, weak incident response, unclear subcontractor chains, or contractual gaps that leave the buyer exposed when something fails. In identity-heavy environments, this becomes especially important when a vendor will receive privileged access, API credentials, service accounts, or other non-human identities. Without disciplined review, organisations may grant access on the assumption that the supplier is “standard” or “already vetted,” even though the actual service, hosting model, and data flow may differ materially from prior engagements.

Due diligence also supports defensible governance. It creates an evidence trail for procurement, legal, security, and privacy teams, and it helps align contract language with actual technical risk. Frameworks such as the NIST Cybersecurity Framework 2.0 and identity assurance guidance in NIST SP 800-63 reinforce the need to verify trust before access is extended. Organisations typically encounter the consequences only after a supplier breach, at which point due diligence becomes operationally unavoidable to reconstruct what was known, what was accepted, and why the approval was granted.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.SC-01 CSF 2.0 addresses supplier and third-party risk governance.
NIST SP 800-63 IAL/AAL/FAL Identity assurance concepts guide trust decisions when third parties receive access.
NIST SP 800-53 Rev 5 SR-3 Supply chain controls formalise third-party risk evaluation and approval evidence.
ISO/IEC 27001:2022 A.5.19 ISO 27001 includes information security in supplier relationships.
DORA Article 28 DORA requires ICT third-party risk oversight and documented contractual safeguards.

Require documented control evidence and contractual commitments before onboarding suppliers.