Skip to content

    Articles tagged: Third Party

    10 articles on Third Party from the Top Floor insights library.

    • 2026-08-25

      How Long Does a Customer Security Review Take?

      From the seller's side, a customer security review takes as long as the buyer's process plus your own response latency, and only the second half is yours to move. The reviews that stall are rarely stalled by a missing control.

    • 2026-08-25

      Do Your Subprocessors Need Their Own SOC 2?

      No. Neither the SOC 2 description criteria nor the GDPR require a third party to hold its own SOC 2 report. What your report needs is evidence that you monitor the vendors whose controls you rely on, and the AICPA lists a vendor SOC 2 report as one monitoring method among several. What to do when a vendor has none.

    • 2026-08-23

      What the DORA Register of Information Requires

      Fourteen linked tables, machine-validated, with the LEI as the only identifier that works. In the ESAs' dry run, 6.5% of registers passed every data quality check and 86.4% of the failures were an empty mandatory field.

    • 2026-08-19

      AI Vendor Risk Assessment: The Questions That Matter

      Six questions do most of the work in an AI vendor review. The standard instruments have caught up in form (CSA's AI-CAIQ runs to 320 questions) but length is not signal, and vendors still clear reviews that never press on the six.

    • 2026-08-16

      Does DORA Apply to US Companies?

      Almost certainly not directly, and almost certainly yes in practice. DORA binds EU financial entities, not their overseas vendors, but Articles 28 to 30 mean it arrives at your door as a contract addendum with a signature deadline attached.

    • 2026-08-16

      What a DORA Addendum Actually Asks You to Sign

      Nine baseline terms under Article 30(2), six more under Article 30(3) when your service supports a critical or important function. A clause-by-clause read of the addendum European financial customers are sending their technology vendors.

    • 2026-08-16

      Do You Need a BAA? A Decision Guide for SaaS Vendors

      If protected health information can sit on your systems, plan on signing one, even encrypted, even if you never look at it. HHS said so in the Omnibus preamble in 2013 and the conduit exception is narrower than almost everyone assumes.

    • 2026-08-16

      Merchant or Service Provider? The PCI AOC Your Customers Want

      A merchant accepts cards for its own goods. A service provider handles or can affect the security of card data on someone else's behalf. Many SaaS companies are both, and sending the wrong attestation is how a vendor review stalls.

    • 2026-08-16

      CMMC Flow-Down: What Primes Can and Cannot Require of Subs

      A prime cannot make you Level 2 by being Level 2. The level follows the data they share. How to answer the questionnaire on your desk without over-committing, and where regulation ends and contract begins.

    • 2026-03-07

      Building a Vendor Risk Management Program from Scratch

      A step-by-step guide to inventorying vendors, classifying risk tiers, running assessments, and meeting SOC 2, ISO 27001, and NIST CSF supply chain requirements.