About the Third Party Risk Management (TPRM) category
What belongs in this category
The Third Party Risk Management (TPRM) category covers products that help organizations understand the risk that comes from vendors, suppliers, partners and service providers. Typical entries keep an inventory of third parties, send and score security questionnaires, rate vendors' internet-facing security from outside (security ratings), watch for breaches and other events at suppliers, and track issues until the vendor fixes them. Vendor risk management products, whose own category was retired, enter here.
Platforms that manage all of an organization's risk and compliance fit Governance, Risk and Compliance (GRC), and products that secure the software components and build pipelines an organization depends on fit Software Supply Chain Security. A ratings product that also maps a company's own internet-facing assets can enter Attack Surface Management.
Related categories to enter
Each category is judged separately, so you can enter a product in every category that matches what it does, with a separate nomination for each. Tailor each nomination to that category's focus. Entering several related categories gives the product more than one chance to be recognized.
How entries are judged
An independent jury of security practitioners, analysts and CISOs scores each nomination on leadership, innovation and impact. Each nomination competes in its category against organizations of similar size and region, so a mid-sized firm is not ranked against a global enterprise. Your entry package, any sponsorship and public votes do not affect the jury's scores.
Strong entries in this category show:
- Leadership — the third-party programs the product supports: vendors assessed and monitored, customers in regulated sectors, and frameworks and questionnaires supported.
- Innovation — a vendor risk problem solved in a new way, such as assessments that take days instead of months, monitoring that catches supplier breaches early, or risk scores tied to the data each vendor holds.
- Impact — results for customers: time to assess a vendor cut, more vendors under continuous monitoring, more issues fixed by suppliers, fewer incidents linked to third parties. Give before-and-after figures.
The jury awards Gold, Silver or Bronze, or a Finalist badge, and results are published on this site and announced to the 600,000+ member Cybersecurity Insiders community. Every approved nomination also enters the separate Community Choice award, decided by public votes.
How to enter
A vendor can enter its own product or service, and a PR agency can enter it on a client's behalf. The nomination form has a confidential field for detail that is shared with the judges and not published, such as customer names, deployment figures or roadmap. Deadlines, pricing and entry steps are on the How it Works page.