Tier first, then assess in proportion
A program that sends the same 300-question form to every vendor collects a mailbox of PDFs and learns little. TPRM starts with an inventory and a tiering: what data, access and business activity does the supplier touch, and what would its failure interrupt? A critical tier gets a contextual assessment, evidence and a remediation plan; a low tier gets a short attestation and external monitoring. Proportion is what makes the program sustainable at hundreds of suppliers.
Between two assessments
An assessment describes a supplier on the day it answered. Monitoring covers the rest: external security ratings and attack-surface signals, breach news, a certificate that expires, a SOC 2 period that lapses. A degraded signal should re-open the supplier’s risk, not wait for next year’s questionnaire. This is where a composite grade that blends the assessment, the business impact of the service and the external signals earns its place, provided its computation is visible.
What NIS2 and DORA require
NIS2 lists supply-chain security among the mandatory risk-management measures, including the security practices of direct suppliers and service providers. DORA devotes a full chapter to ICT third-party risk: a strategy, a register of information on every contractual arrangement, pre-contracting due diligence, mandatory contract clauses, exit strategies for critical services, and an EU oversight regime for critical ICT providers. TPRM is the program those obligations describe.