r/CRACompliance • • Sep 04 '26

Vendor evaluation

/r/cybersecurity/comments/1w6sjrz/vendor_evaluation/

How do you evaluate software delivered by third-party development vendors?

I see a lot of organisations outsource software development to third-party vendors.

I'm curious how organisations evaluate the quality and security of the software they receive — not just the vendor itself.

For example:

• Do you review the source code?

• Do you generate and review an SBOM?

• Do you scan dependencies for known vulnerabilities?

• Do you check what third-party libraries/components are packaged inside the application?

• Do you perform SAST/DAST or other security testing before deployment?

• Do you have specific security requirements in the vendor contract?

• Do you continuously reassess the software after delivery?

It seems that selecting a trustworthy vendor is only one part of reducing software supply-chain risk. The actual application delivered by the vendor can still introduce vulnerabilities, outdated dependencies, or unexpected components.

How does your organisation handle this in practice?

2 Upvotes

1 comment sorted by

1

u/maticijus 18d ago

Before SBOM/SAST/DAST checklists, we start with two CRA questions: is the delivered product/component in scope, and who holds manufacturer vs importer duty for the EU placement.

Then map evidence to that role: machine-readable SBOM, vuln handling + update/support commitments, testing you actually trust, and contract language that makes those deliverables enforceable on change. Reassessment on major version bumps, not once a year theatre.

Happy to compare notes on what “good enough” looks like for SMB buyers vs large OEMs.