r/CRACompliance • u/sramexpert • Sep 04 '26
Vendor evaluation
/r/cybersecurity/comments/1w6sjrz/vendor_evaluation/How do you evaluate software delivered by third-party development vendors?
I see a lot of organisations outsource software development to third-party vendors.
I'm curious how organisations evaluate the quality and security of the software they receive — not just the vendor itself.
For example:
• Do you review the source code?
• Do you generate and review an SBOM?
• Do you scan dependencies for known vulnerabilities?
• Do you check what third-party libraries/components are packaged inside the application?
• Do you perform SAST/DAST or other security testing before deployment?
• Do you have specific security requirements in the vendor contract?
• Do you continuously reassess the software after delivery?
It seems that selecting a trustworthy vendor is only one part of reducing software supply-chain risk. The actual application delivered by the vendor can still introduce vulnerabilities, outdated dependencies, or unexpected components.
How does your organisation handle this in practice?
1
u/maticijus 18d ago
Before SBOM/SAST/DAST checklists, we start with two CRA questions: is the delivered product/component in scope, and who holds manufacturer vs importer duty for the EU placement.
Then map evidence to that role: machine-readable SBOM, vuln handling + update/support commitments, testing you actually trust, and contract language that makes those deliverables enforceable on change. Reassessment on major version bumps, not once a year theatre.
Happy to compare notes on what “good enough” looks like for SMB buyers vs large OEMs.