Skip to content
Foxx Cyberfoxxcyber/docs

Vendor and Asset Registers

Keep the client's third-party register with dated reviews and contract dates, and an asset register with classification, impact ratings, recovery objectives, crown jewels and CMMC asset categories.

Two registers describe what the client depends on: the vendors that hold its data or run its services, and the assets its business runs on. Both link to risks, both appear on the board report and in the client portal, and both import and export like every other register.

The vendor register

Open Vendors → Add vendor. One entry per company, even if they provide several services. Each vendor gets a reference (V-001), and Save vendor keeps it.

PartFields
The vendorName, service, category (SaaS, cloud, MSP or MSSP, software, hardware, professional services, payments, communications, facilities, other), website.
ExposureCriticality (critical, high, medium, low): how badly the business suffers if the vendor fails or is breached. Data access (none, internal, confidential, regulated): the most sensitive data they can reach. Data types.
RelationshipStatus (proposed, active, offboarding, ended), the relationship owner at the client, the vendor contact, contract start and end dates, and the review cycle in months (0 for no scheduled review).
Internal notesFor your team only. Never shown in the portal or in reports.

Vendor reviews

On a vendor's page, fill in Record a review with the date (Reviewed on), the Reviewer, the Outcome (approved, approved with conditions, rejected), a Risk rating (low, moderate, high, critical), What was examined (a SOC report, a questionnaire, a contract review) and the Findings and conditions, then choose Record review. The Reviews list shows what was examined and found in one column. The next review date defaults to one review cycle later; you can set it yourself. Reviews are kept as a dated history.

A live vendor on a review cycle is shown as:

StateWhen
Never reviewedOn a cycle, with no review recorded.
OverdueThe next review date has passed.
DueThe next review is within 30 days.
CurrentOtherwise.

A live vendor whose contract ends within 60 days (or has already ended while the vendor is still marked live) is flagged as ending. Overdue reviews, never-reviewed vendors and ending contracts surface on the register, the client overview and the board report, and reviews and contract ends appear in Monitoring. Live vendors with no review cycle are counted as loose ends.

Contracts, risks and assets

A vendor's page links it to:

  • Contracts and assurance from the library: the contract, BAA or DPA, SOC report or questionnaire. Upload adds a new one straight into the evidence library, linked to the vendor.
  • Risks the vendor creates or carries.
  • Assets they provide or host: set the vendor on an asset and it shows here.

The asset register

Open Assets → Add asset. Each asset gets a reference (A-001), and Save asset keeps it.

FieldNotes
Name, Kind, Description, QuantityKind is hardware, software, SaaS, cloud, data, network, facility, people, process or other.
Owner, LocationWho is accountable, and where it lives.
ClassificationPublic, internal, confidential or regulated.
CriticalityCritical, high, medium or low.
Confidentiality impact, Integrity impact, Availability impact1 to 5 each.
Recovery time objective, Recovery point objectiveIn hours.
Crown jewelThe few assets whose loss would stop the business.
CMMC asset categoryCUI asset, security protection asset, contractor risk managed asset, specialized asset or out of scope, for CMMC Level 2 scoping.
StatusPlanned, active or retired.
VendorThe vendor that provides or hosts it.
NotesInternal only, never shown in the portal or in reports.

Link each asset to the risks against it from the asset's page. Crown jewels appear on the client overview and in the board report's "What we protect" section.

Views of each register

Like the risk register, each register has chips over its list, each with a count, and the list is headed by the view:

  • Vendors: Live (Live vendors), Critical or high, Review needed (Vendors due a review), Contract ending (Contracts ending soon), Ended (Vendors no longer used) and All.
  • Assets: Live (Live assets), Crown jewels, Critical or high, Regulated data (Assets holding regulated data), CMMC scope (Assets in CMMC scope), Retired and All.

Each register has a search box and sortable columns, and Export and Import above the list.

What assessors see

Assessors from a partner firm can read both registers on the clients they are assigned to, for context. They do not see the risks or the contracts and assurance documents linked to a vendor or asset, the contract dates or the Contracts ending tile, or the internal notes, and they cannot change anything here.

Importing existing registers

If the client already keeps a vendor list or an asset inventory in a spreadsheet, import it through the preview on Import / export. A row with a reference (V-004, A-017) updates that record; without one, a row whose name matches an existing vendor or asset updates it. An asset's Vendor column can name a vendor added on the Vendors sheet of the same file. See Import and Export.

Last updated October 9, 2026