Guide · For MSSPs

How RiskBee maps to ISO 27001, SOC 2, DORA and CMMC for MSSPs

RiskBee runs vendor risk management as a set of automated engines - inherent-risk scoring at intake, AI contract extraction, evidence-weighted health scoring, and fourth-party sub-processor discovery. This is how each one maps to the specific controls MSSP clients get audited against.

Last updated: 2026-08-28

Framework compliance mapping

FrameworkSpecific controlHow RiskBee solves itMSSP audit evidence generated
ISO 27001:2022Annex A 5.19-5.22 (Supplier relationships & change management)An inherent risk score at intake plus an independent vendor tier that sets review cadence (12 months for Critical vendors, 24 for Important) and automated re-review reminders.Centralised vendor register, documented tiering methodology, and a review-history log.
SOC 2 Type IICC9.2 (Risk assessment of vendors and business partners)Evidence-weighted health scoring that credits verified certifications far above self-reported answers, blended with continuous external attack-surface monitoring.Audit-ready vendor health scores (A-F), a verified evidence repository, and gap-analysis reports.
DORAArticles 28-30 (ICT third-party risk management, concentration risk assessment & contract terms)Automated sub-processor discovery from vendor DPAs and trust centers, with a concentration-risk flag on any sub-processor supporting more than half the active vendor fleet, plus instant blast-radius search.Sub-processor registry, concentration-risk dashboards, and multi-tier supply-chain maps.
CMMC 2.0 / NIST SP 800-171Flow-down obligations & breach notificationAI contract analysis extracts customer-facing duties - audit rights, breach-notification windows, pen-test cadence - and opens a gap task automatically when supporting evidence is missing.Flow-down clause logs, open gap-task reports, and vendor obligation schedules.
NIST CSF 2.0Govern (GV.SC) - Cyber supply chain risk managementA sector-based labour-risk taxonomy layered on top of the core security, privacy and compliance score, plus continuous external attack-surface signals.Combined supply-chain risk profiles spanning cybersecurity, contractual, and labour-risk signals.

RiskBee is a compliance-mapping and evidence-automation engine, not a certification body - it keeps the vendor register, evidence trail and review cadence an auditor expects to see. The ISO 27001 or SOC 2 attestation itself still comes from an accredited auditor.

The vendor lifecycle

Intake & inherent risk

Adding a vendor captures a data sensitivity classification (categories like PHI, PCI, biometric and credential data weigh heaviest) and access level (from none up to privileged, with an added weight for on-site physical access) into an inherent risk score - an early warning before any evidence exists. Business criticality separately sets the vendor's tier (Critical, Important or Low impact), which drives review cadence (12 months for Critical, 24 for Important) and how complete its evidence file needs to be before it counts as reviewed.

AI contract extraction

Drop in a contract PDF and RiskBee's AI separates the signing counterparty from the underlying vendor - critical for reseller and distributor deals - capturing who bills the client and who actually provides support. It flags contract-risk clauses and extracts up to 10 customer-facing obligations (breach notification windows, audit rights, pen-test cadence). Any obligation without matching evidence on file opens a gap task automatically, typically due 30 days before the contract renews.

Evidence-weighted health scoring

Rather than taking a vendor's word for it, RiskBee grades evidence on a graduated scale - a verified SOC 2 or ISO 27001 certificate earns full credit; an independent registry listing, gated documentation, or a scraped/attested claim earns progressively less; a generic policy reference earns the least. Scores roll up into three weighted domains - Security (50%), Privacy (30%) and Compliance (20%) - then adjust for continuous external attack-surface signals (TLS, DMARC, SPF, certificate health), capped at 10% of the total score.

Fourth-party sub-processor discovery

RiskBee crawls a vendor's trust center or DPA page and uses AI to extract its own sub-processors, matching them by domain or legal name against every other vendor in the client's workspace. Any sub-processor supporting more than half of the client's active vendor fleet is flagged automatically as a concentration risk - a single point of failure hiding several supply-chain layers deep.

Blast radius search

When a vendor or cloud provider has an incident, a free-text search across the whole vendor and sub-processor graph splits exposure into vendors used directly (with a current risk score) and vendors exposed indirectly through a sub-processor relationship, showing where that relationship was verified from.

The evidence-credit hierarchy

Health scoring does not treat every piece of evidence equally - a verified certificate is worth far more than an unverified claim:

Evidence typeCreditExample
Verified certificationFull creditSOC 2, ISO 27001 with a valid certificate on file
Independent registryHigh creditListed with AICPA, ISO or a recognised registry
Gated / attested documentationPartial creditShared under NDA or claimed with a supporting doc
Scraped or self-attested claimReduced creditFound on a trust-center scan with no formal proof
Generic policy referenceCapped lowA public terms-of-service or privacy page

The concentration-risk formula

Fourth-party concentration is a simple share calculation, run automatically across every sub-processor in a client's workspace:

Concentration share = (vendors relying on this sub-processor ÷ total active vendors) × 100 - flagged as high-reliance once it passes 50%.

Built for the MSSP operating model

Multi-tenant isolation

Client workspaces stay logically separate - vendor lists, contracts and sub-processor maps never cross between clients.

Reseller channel support

Every contract records its procurement channel (direct, reseller, marketplace or distributor) plus who bills it and who supports it, so obligations land on the right party.

Automated client deliverables

Vendor risk registers, concentration-risk dashboards and renewal projections generate on demand instead of getting rebuilt by hand every quarter.