Skip to main content
Free resource · NIS2 & DORA

Third-Party Risk Register for NIS2 & DORA

Document ICT suppliers, assign ownership, schedule reviews, and maintain audit-ready third-party risk records.

  • Editable Excel register
  • ICT supplier classification guidance
  • Contract security review checklist
  • Governance and review planning
  • Third-party risk management checklist
GDPR-conscious Free, no strings
The third-party risk management lifecycle this register supports
Identify ICT supplier
Assess business criticality
Review security requirements
Assign ownership
Schedule reviews
Maintain evidence
— 01 · The challenge

Why do so many organizations struggle with third-party risk management?

ICT (information and communication technology) supplier oversight usually fails on records, not intentions.

Common third-party risk challenges
What security and compliance teams need
ICT supplier information is spread across multiple systems.
One complete third-party risk register.
Suppliers are assessed during onboarding but rarely reviewed again.
A structured review schedule with clear ownership.
Contract security requirements are difficult to track.
A consistent contract security checklist.
Audit evidence is stored in different locations.
One place to record reviews and supporting evidence.
Critical suppliers are not clearly identified.
A simple way to classify ICT suppliers by business impact.
— 02 · Inside the download

What's inside the Third-Party Risk Register

01

Third-party risk register

A ready-to-use Excel workbook for documenting ICT suppliers, assigning ownership, tracking review dates, and maintaining audit-ready records. A practical foundation for day-to-day third-party risk management.

02

ICT supplier classification

A practical approach to classifying ICT suppliers based on business criticality, operational impact, and access to systems and data — so you prioritize oversight where it matters most.

03

Contract security review checklist

A checklist for reviewing contractual cybersecurity requirements: security responsibilities, incident notification obligations, audit rights, subcontractor requirements, and business continuity provisions.

04

Governance and review planning

A structured approach to assigning business owners, scheduling supplier reviews, tracking review status, and maintaining supporting evidence throughout the supplier lifecycle — not only during audits.

05

Third-party risk management checklist

A final checklist confirming suppliers are classified, contracts reviewed, ownership assigned, review schedules established, and evidence documented before an internal review or regulatory audit.

Third-party risk management starts with a complete register

Use a practical Excel workbook to document ICT suppliers, review schedules, and supporting evidence.

Download the Third-Party Risk Register
— 03 · Why it works

Why teams use this register

Maintain a complete ICT supplier inventory

Keep supplier information, business ownership, review history, and supporting evidence in one place instead of across multiple spreadsheets and documents.

Support third-party risk under NIS2 and DORA

Document supplier oversight, contract reviews, and governance activities using a practical structure aligned with third-party risk management requirements.

Improve audit readiness

Maintain review dates, ownership, and supporting evidence throughout the year instead of rebuilding documentation before an internal or regulatory audit.

Standardize supplier reviews

Apply the same review process across ICT suppliers, helping security, procurement, and compliance teams work from one consistent framework.

— 04 · FAQ

Frequently asked questions

What is TPRM?

TPRM stands for Third-Party Risk Management. In practice, it's the process of understanding which ICT suppliers create the most risk, deciding how often they should be reviewed, and keeping enough evidence to show those reviews actually happened.

What is a third-party risk register?

Think of it as the working document behind your TPRM process. It brings supplier details, ownership, review dates, contract status, and supporting evidence together, so information isn't scattered across spreadsheets, contracts, and emails.

Does NIS2 require a TPRM program?

NIS2 doesn't tell you exactly how to organize third-party risk management. It does expect organizations to manage supply chain cybersecurity risks. A documented TPRM process makes that much easier to demonstrate during an audit.

Can this register help with DORA?

Yes. If you're subject to DORA, the register gives you one place to track ICT suppliers, ownership, review history, and supporting evidence. It won't make you compliant on its own, but it helps keep the information auditors usually ask for together.

Do I need TPRM software to manage supplier risk?

Not always. Many organizations start with a structured register before investing in dedicated TPRM software. As the number of ICT suppliers grows, specialized platforms can automate reviews, reminders, and reporting, but a clear process should come first.

— 05 · Beyond the register

Looking beyond the register?

A well-maintained register is only one part of managing third-party risk. Q-Sec helps organizations strengthen supplier governance and prepare for NIS2 and DORA with practical cybersecurity services.

Talk to Q-Sec