Vendor and Asset Registers
Keep the client's third-party register with dated reviews and contract dates, and an asset register with classification, impact ratings, recovery objectives, crown jewels and CMMC asset categories.
Two registers describe what the client depends on: the vendors that hold its data or run its services, and the assets its business runs on. Both link to risks, both appear on the board report and in the client portal, and both import and export like every other register.
The vendor register
Open Vendors → Add vendor. One entry per company, even if they provide
several services. Each vendor gets a reference (V-001), and Save
vendor keeps it.
| Part | Fields |
|---|---|
| The vendor | Name, service, category (SaaS, cloud, MSP or MSSP, software, hardware, professional services, payments, communications, facilities, other), website. |
| Exposure | Criticality (critical, high, medium, low): how badly the business suffers if the vendor fails or is breached. Data access (none, internal, confidential, regulated): the most sensitive data they can reach. Data types. |
| Relationship | Status (proposed, active, offboarding, ended), the relationship owner at the client, the vendor contact, contract start and end dates, and the review cycle in months (0 for no scheduled review). |
| Internal notes | For your team only. Never shown in the portal or in reports. |
Vendor reviews
On a vendor's page, fill in Record a review with the date (Reviewed on), the Reviewer, the Outcome (approved, approved with conditions, rejected), a Risk rating (low, moderate, high, critical), What was examined (a SOC report, a questionnaire, a contract review) and the Findings and conditions, then choose Record review. The Reviews list shows what was examined and found in one column. The next review date defaults to one review cycle later; you can set it yourself. Reviews are kept as a dated history.
A live vendor on a review cycle is shown as:
| State | When |
|---|---|
| Never reviewed | On a cycle, with no review recorded. |
| Overdue | The next review date has passed. |
| Due | The next review is within 30 days. |
| Current | Otherwise. |
A live vendor whose contract ends within 60 days (or has already ended while the vendor is still marked live) is flagged as ending. Overdue reviews, never-reviewed vendors and ending contracts surface on the register, the client overview and the board report, and reviews and contract ends appear in Monitoring. Live vendors with no review cycle are counted as loose ends.
Contracts, risks and assets
A vendor's page links it to:
- Contracts and assurance from the library: the contract, BAA or DPA, SOC report or questionnaire. Upload adds a new one straight into the evidence library, linked to the vendor.
- Risks the vendor creates or carries.
- Assets they provide or host: set the vendor on an asset and it shows here.
The asset register
Open Assets → Add asset. Each asset gets a reference (A-001), and
Save asset keeps it.
| Field | Notes |
|---|---|
| Name, Kind, Description, Quantity | Kind is hardware, software, SaaS, cloud, data, network, facility, people, process or other. |
| Owner, Location | Who is accountable, and where it lives. |
| Classification | Public, internal, confidential or regulated. |
| Criticality | Critical, high, medium or low. |
| Confidentiality impact, Integrity impact, Availability impact | 1 to 5 each. |
| Recovery time objective, Recovery point objective | In hours. |
| Crown jewel | The few assets whose loss would stop the business. |
| CMMC asset category | CUI asset, security protection asset, contractor risk managed asset, specialized asset or out of scope, for CMMC Level 2 scoping. |
| Status | Planned, active or retired. |
| Vendor | The vendor that provides or hosts it. |
| Notes | Internal only, never shown in the portal or in reports. |
Link each asset to the risks against it from the asset's page. Crown jewels appear on the client overview and in the board report's "What we protect" section.
Views of each register
Like the risk register, each register has chips over its list, each with a count, and the list is headed by the view:
- Vendors: Live (Live vendors), Critical or high, Review needed (Vendors due a review), Contract ending (Contracts ending soon), Ended (Vendors no longer used) and All.
- Assets: Live (Live assets), Crown jewels, Critical or high, Regulated data (Assets holding regulated data), CMMC scope (Assets in CMMC scope), Retired and All.
Each register has a search box and sortable columns, and Export and Import above the list.
What assessors see
Assessors from a partner firm can read both registers on the clients they are assigned to, for context. They do not see the risks or the contracts and assurance documents linked to a vendor or asset, the contract dates or the Contracts ending tile, or the internal notes, and they cannot change anything here.
Importing existing registers
If the client already keeps a vendor list or an asset inventory in a
spreadsheet, import it through the preview on Import / export. A row with
a reference (V-004, A-017) updates that record; without one, a row whose
name matches an existing vendor or asset updates it. An asset's Vendor
column can name a vendor added on the Vendors sheet of the same file. See
Import and Export.