Provider Risk Pack
The vendor programme, and a deep assessment of the vendor that holds your admin rights. Run every supplier properly, then run your MSP properly — because one row in a register does not cover the party with delegated admin on your tenant. 14% off buying separately.
What this actually gives you
- Scoring your MSP the same way as your stationery supplier is how a register ends up with one green row next to the party holding RMM on every endpoint, delegated admin in your tenant and your backups.
- Verizon’s 2026 DBIR puts third-party involvement in 48% of breaches; 75% of MSPs were breached in the past year.
- The programme tells you which supplier needs the deep look; the assessment gives it, and feeds one much richer row back into the register rather than replacing it.
Every vendor programme has one supplier that does not fit the template, and it is usually the one with the most access.
Vendor Risk Operations Kit — the programme, vendor by vendor: the dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder aimed at the failures supervisors actually flag.
MSP & MSSP Assessment Kit — the deep dive on the one relationship that is really an administrative plane: what they hold, every path they use in, 40 controls they must evidence, 20 contract clauses against UK, DFS, HIPAA, DORA and NIS2 expectations, whether you could leave, and a 60-minute drill for the night they are breached.
Why the pair. The vendor programme is right to score every supplier the same way — that is what makes it defensible. But scoring your MSP the same way as your stationery supplier is how a register ends up with one green row next to the party that holds RMM on every endpoint, delegated admin in your tenant and your backups. Verizon's 2026 DBIR puts third-party involvement in 48% of breaches; 75% of MSPs were breached in the past year. The programme tells you which supplier needs the deep look. This gives you the deep look.
The MSP kit feeds a single, much richer row back into the programme's register rather than replacing it — they are designed to compose.
Two tiers, because the Vendor Risk Operations Kit is sold as a practitioner or an MSSP licence rather than an organisation one.
What's in this bundle
Vendor Risk Operations Kit
The programme is designed — this is how you run it, vendor by vendor, and what you hand the examiner. The dossier, a quarterly scorecard whose rating has consequences, an annual review that ends in a decision, the incident playbook, a tested exit plan, an AI overlay with hard stops, and a Register of Information builder with ten quality checks aimed at the failures supervisors actually flag.
MSP & MSSP Assessment Kit
Your MSP is your administrative plane. Assess what they hold, how they reach you, what they can evidence, what the contract says and whether you could leave — with a scenario that proves you can act the night they are breached.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee