TPRM Maturity Checklist

A free, framework-grounded self-assessment anchored to NIST CSF 2.0, NIST 800-53, and NIST SP 800-161, with HECVAT as the reference for higher-ed vendor due diligence. Use this checklist to score your third-party risk program across five dimensions in a couple of minutes — then find the lowest one and fix it first.

What’s Inside

  • Five Stages × Five Dimensions, Scored 1–5: Place your program on a maturity ladder from L1 (ad-hoc questionnaires) to L5 (integrated term management), then score it across Governance & ownership, Intake & tiering, Assessment & due diligence, Continuous monitoring, and Lifecycle & offboarding.
  • Framework-Anchored, Not Vendor Opinion: Every dimension ties to a recognized reference — NIST CSF 2.0 GV.SC, the NIST 800-53 SR family and PM-30, NIST SP 800-161, and the HECVAT for higher-ed vendor due diligence.
  • A Score You Can Act On: Read your headline stage for leadership in one line, find your lowest dimension (the bottleneck), and commit to the single next move that raises it.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Book a Demo