Independent technical review · engineering partner

Cyber security & IT vendor due diligence,
evidence a reviewer can cite.

TrustChange runs technology vendor due diligence for EU-facing fintech, crypto, banking and payments teams. We review a third-party vendor across cyber security, application security, hosting, operations, data model, regulatory fit and contract posture — and deliver a ranked findings register with a reviewer-ready evidence pack your MLRO, DPO and external auditor can cite. No SaaS licence, no legal opinion — a scoped, independent engineering review.

  • EU-based engineers
  • Independent, evidence-based
  • MiCA / PSD2 aware
  • AML / Travel Rule aware
  • GDPR-aware storage

What "vendor due diligence" means here

Cyber security vendor due diligence versus a certification or a questionnaire

Most searches for cyber security vendor due diligence or IT vendor due diligence land on either a certification audit (SOC 2, ISO 27001) or a self-assessment questionnaire. Both have their place, and neither is what TrustChange delivers. We run an independent, evidence-based technical review, scoped to your use case and delivered in a form your reviewer can cite. Existing certifications feed in as evidence; they do not replace the review.

Reviewing your own build instead? See technical due diligence services. Broader advisory shapes: fractional CTO services and the wider CTO advisory practice. Security engineering: crypto & fintech security engineering.

Scope

Eight layers in every IT vendor due diligence engagement

Vendor due diligence is not one questionnaire. It is eight layers of evidence-based review that must agree on every finding. We work through them in parallel, on one plan, with one team accountable end to end.

Reference scope for a cyber security & IT vendor due diligence engagement
LayerWhat we review
Cyber security controls IAM & SSO posture, secrets management, key custody, encryption in transit and at rest, MFA and admin-plane isolation We review evidence — configuration exports, screenshots, logs — not just marketing.
Application security SDLC review, dependency and licence scan, secure-coding practice, code review, third-party pen-test cadence and remediation trail The question is not whether they had a pen test; it is what happened to the findings.
Infrastructure & hosting Hosting regions, cloud posture, network segmentation, backup and DR, tenant isolation Data residency for EU customers is a hard requirement, not a preference.
Operations & change Deployment cadence, observability, on-call and incident response, change management How fast can they roll back? How is a change reversed if it breaks your integration?
Data model & privacy Data map, retention rules, sub-processors, cross-border transfers, DPA and SCC posture under GDPR A DPA that is signed but silent on sub-processors is not a control.
Regulatory fit How the vendor supports MiCA, PSD2, AML/Travel Rule and your licence context; artefacts your reviewer will accept TrustChange assesses fit; your legal advisers decide compliance.
Financial & continuity Concentration risk, exit path, escrow of code or data where relevant, business continuity If the vendor disappears tomorrow, what do you have to continue serving customers?
Contract & controls attestations MSA, DPA, SOC / ISO reports where relevant, right-to-audit, sub-processor lists, penetration-test summaries We read what exists; missing artefacts are recorded as gaps, not filled with assumptions.

Assessment path

From kick-off to a reviewer-ready pack

Five steps, in this order. The pace is predictable because the deadlines are published to the vendor at kick-off; delays on the vendor side are recorded as gaps, not absorbed as slippage on our side.

  1. 01

    Kick-off

    Week 1

    We align on scope with your procurement, security and compliance leads: which vendor, which use case, which controls matter most.

  2. 02

    Evidence request

    Week 1

    A written evidence pack request goes to the vendor with clear deadlines; missing items are tracked as gaps.

  3. 03

    Review

    Weeks 2–3

    TrustChange engineers review the evidence across the eight layers; interviews with the vendor's security and engineering leads run in parallel.

  4. 04

    Findings & fit

    Week 4

    A ranked findings list with severity, evidence and recommended remediation; a fit call for your use case.

  5. 05

    Reviewer bundle

    Week 4

    The final report is delivered in a form your MLRO, DPO and external reviewer can read and cite — with the raw evidence attached.

Engagement

How to buy technology vendor due diligence

Same engineers, same standard. Only the commercial shape changes.

  • Fixed-scope review

    A defined vendor, defined use case, fixed price and date. The default shape for a single-vendor engagement.

  • CTO advisory retainer

    Recurring capacity for vendor reviews across a portfolio, plus architecture support.

  • Dedicated team

    A standing squad for programmes with vendor reviews, integration and hardening in one plan.

  • Staff augmentation

    Senior engineers embedded in your security or procurement team to run reviews under your process.

Questions

FAQ: cyber security & IT vendor due diligence

Six answers up front on scope, vs certifications and questionnaires, vendor types, timeline, compliance framing and remediation. Bring the rest to the call.

What does cyber security vendor due diligence from TrustChange actually deliver?

An independent, evidence-based technical review of a third-party vendor: cyber security posture, application security, hosting and operations, data model and privacy, regulatory fit, financial continuity and contract artefacts. You get a ranked findings register, a fit call for your use case, a remediation plan and a reviewer-ready pack for your MLRO, DPO and external auditor. TrustChange is an engineering partner, not a legal-advice firm and not a certifying body — we assess evidence and record what is present, missing or contested.

How is your IT vendor due diligence different from a certification audit or a security questionnaire?

A certification audit (SOC 2, ISO 27001, PCI DSS) tests whether the vendor met a defined standard on a defined day, under a scope the vendor set with the auditor. A security questionnaire is a self-assessment. IT vendor due diligence from TrustChange sits between and beyond both: independent, evidence-based, scoped to your use case, and delivered in a form your reviewer can actually cite. Existing certifications feed in as evidence; they do not replace the review.

Which vendor types do you typically assess?

KYC / KYB and sanctions-screening providers, PSP and acquiring partners, custody and MPC vendors, on/off-ramp providers, ledger and reconciliation SaaS, market-data feeds, cloud and hosting providers, developer-tooling and observability vendors, and — for regulated operators — any vendor that touches money, customer data or key material. The eight-layer scope on this page adapts to the vendor class in the kick-off.

How long does a technology vendor due diligence engagement take?

Most reviews land in three to four weeks end to end, gated by how quickly the vendor returns the evidence pack. Focused, single-lens reviews (for example a cyber-security-only assessment for a small SaaS) can complete inside two weeks. TrustChange publishes the deadline schedule with the vendor at kick-off so nothing slips on our side; delays on the vendor side are recorded as gaps in the register.

How do you handle MiCA, PSD2, AML/Travel Rule and GDPR in the review?

TrustChange is an engineering partner, not a law firm — your compliance team and MLRO set the policy and confirm the legal position. What we do is review evidence against the technical shape of those regimes: for GDPR, data map and sub-processor list against DPA / SCC posture; for AML, screening cadence, list versions and Travel Rule handling; for PSD2, SCA and consent flows; for MiCA, records and controls where the vendor touches digital assets. Nothing about licence or authorisation status is claimed on the vendor's behalf.

What happens after the report — do you also remediate?

Optionally, yes. If the vendor is a hold-with-remediation, we can run the remediation follow-through: track the vendor's fixes, re-review evidence and re-issue the reviewer pack when items close. If the finding is on your side (integration hardening, key handling, monitoring), a TrustChange dedicated team or staff augmentation can pick that up under the wider engineering practice. If it is a no-go, we help you scope replacement vendors.

Book a discovery call for cyber security vendor due diligence

Bring the vendor, the intended use case, the licence context and the deadline. We come back with a scoped plan, an evidence-pack request and a reviewer-ready delivery schedule. No demo theatre.