Screenata

Beyond SOC 2

What is an example of a third-party vendor?

September 14, 20263 min read

What is an example of a third-party vendor?

A third-party vendor is any outside company that provides goods or services to your organization under a contract. For a SaaS company the common examples are its cloud provider (AWS, Google Cloud, Azure), payment processor (Stripe), productivity and messaging tools (Google Workspace, Slack), payroll provider (Gusto, Deel), and CRM or support platform (HubSpot, Zendesk). A fourth party is your vendor's vendor, such as the cloud host behind your CRM.

Third-party vendor examples by category

CategoryExamplesTypical data accessRisk tier
Cloud infrastructureAWS, Google Cloud, Azure, CloudflareHosts production and customer dataHigh
Code and deploymentGitHub, Vercel, DatadogSource code, secrets, logsHigh
IdentityOkta, Google Workspace, Microsoft Entra IDControls access to everything elseHigh
PaymentsStripe, BraintreeCardholder and billing dataHigh
Customer communicationZendesk, Intercom, SendGridCustomer names, emails, message contentMedium
HR and payrollGusto, Deel, RipplingEmployee personal and financial dataMedium
Sales and marketingHubSpot, Salesforce, LinkedIn AdsProspect contact dataMedium to low
Professional servicesLaw firm, auditor, penetration testerVaries; often confidential documentsVaries
Office and facilitiesCoworking space, hardware resellerPhysical access, devicesLow

Tier each vendor by what it can reach. A free analytics script on a login page can carry more risk than an expensive consulting contract.

Third, fourth, and nth parties

PartyRelationshipHow you manage the risk
Third partyContracts directly with youSecurity review, contract terms, periodic reassessment
Fourth partyContracts with your vendorYour vendor's subprocessor list and its SOC 2 subservice organization disclosures
Nth partyFurther down the chainConcentration analysis, such as how many critical vendors depend on one cloud region

A SOC 2 report handles fourth parties explicitly. The system description names subservice organizations and states whether their controls are included (the inclusive method) or carved out (the carve-out method). When a vendor carves out its cloud host, you need that host's own report as well.

What compliance frameworks require for vendors

SOC 2 criterion CC9.2 asks you to assess and manage risk from vendors and business partners. ISO 27001 Annex A covers supplier relationships in its organizational controls. HIPAA requires a business associate agreement with every vendor that creates, receives, maintains, or transmits PHI for you.

In practice, an auditor asks for the same four things under each framework: a complete vendor inventory, a risk rating per vendor, evidence of review for the high-risk ones (usually their SOC 2 report or a questionnaire), and signed contracts or BAAs. The most common gap is the inventory itself, because vendors get added by engineers through a package, an API key, or a free-tier signup, without anyone recording it. For the lifecycle around that inventory, see the five stages of third-party management.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.