Guide · For MSSPs
How RiskBee maps to ISO 27001, SOC 2, DORA and CMMC for MSSPs
RiskBee runs vendor risk management as a set of automated engines - inherent-risk scoring at intake, AI contract extraction, evidence-weighted health scoring, and fourth-party sub-processor discovery. This is how each one maps to the specific controls MSSP clients get audited against.
Last updated: 2026-08-28
Framework compliance mapping
| Framework | Specific control | How RiskBee solves it | MSSP audit evidence generated |
|---|---|---|---|
| ISO 27001:2022 | Annex A 5.19-5.22 (Supplier relationships & change management) | An inherent risk score at intake plus an independent vendor tier that sets review cadence (12 months for Critical vendors, 24 for Important) and automated re-review reminders. | Centralised vendor register, documented tiering methodology, and a review-history log. |
| SOC 2 Type II | CC9.2 (Risk assessment of vendors and business partners) | Evidence-weighted health scoring that credits verified certifications far above self-reported answers, blended with continuous external attack-surface monitoring. | Audit-ready vendor health scores (A-F), a verified evidence repository, and gap-analysis reports. |
| DORA | Articles 28-30 (ICT third-party risk management, concentration risk assessment & contract terms) | Automated sub-processor discovery from vendor DPAs and trust centers, with a concentration-risk flag on any sub-processor supporting more than half the active vendor fleet, plus instant blast-radius search. | Sub-processor registry, concentration-risk dashboards, and multi-tier supply-chain maps. |
| CMMC 2.0 / NIST SP 800-171 | Flow-down obligations & breach notification | AI contract analysis extracts customer-facing duties - audit rights, breach-notification windows, pen-test cadence - and opens a gap task automatically when supporting evidence is missing. | Flow-down clause logs, open gap-task reports, and vendor obligation schedules. |
| NIST CSF 2.0 | Govern (GV.SC) - Cyber supply chain risk management | A sector-based labour-risk taxonomy layered on top of the core security, privacy and compliance score, plus continuous external attack-surface signals. | Combined supply-chain risk profiles spanning cybersecurity, contractual, and labour-risk signals. |
RiskBee is a compliance-mapping and evidence-automation engine, not a certification body - it keeps the vendor register, evidence trail and review cadence an auditor expects to see. The ISO 27001 or SOC 2 attestation itself still comes from an accredited auditor.
The vendor lifecycle
Intake & inherent risk
Adding a vendor captures a data sensitivity classification (categories like PHI, PCI, biometric and credential data weigh heaviest) and access level (from none up to privileged, with an added weight for on-site physical access) into an inherent risk score - an early warning before any evidence exists. Business criticality separately sets the vendor's tier (Critical, Important or Low impact), which drives review cadence (12 months for Critical, 24 for Important) and how complete its evidence file needs to be before it counts as reviewed.
AI contract extraction
Drop in a contract PDF and RiskBee's AI separates the signing counterparty from the underlying vendor - critical for reseller and distributor deals - capturing who bills the client and who actually provides support. It flags contract-risk clauses and extracts up to 10 customer-facing obligations (breach notification windows, audit rights, pen-test cadence). Any obligation without matching evidence on file opens a gap task automatically, typically due 30 days before the contract renews.
Evidence-weighted health scoring
Rather than taking a vendor's word for it, RiskBee grades evidence on a graduated scale - a verified SOC 2 or ISO 27001 certificate earns full credit; an independent registry listing, gated documentation, or a scraped/attested claim earns progressively less; a generic policy reference earns the least. Scores roll up into three weighted domains - Security (50%), Privacy (30%) and Compliance (20%) - then adjust for continuous external attack-surface signals (TLS, DMARC, SPF, certificate health), capped at 10% of the total score.
Fourth-party sub-processor discovery
RiskBee crawls a vendor's trust center or DPA page and uses AI to extract its own sub-processors, matching them by domain or legal name against every other vendor in the client's workspace. Any sub-processor supporting more than half of the client's active vendor fleet is flagged automatically as a concentration risk - a single point of failure hiding several supply-chain layers deep.
Blast radius search
When a vendor or cloud provider has an incident, a free-text search across the whole vendor and sub-processor graph splits exposure into vendors used directly (with a current risk score) and vendors exposed indirectly through a sub-processor relationship, showing where that relationship was verified from.
The evidence-credit hierarchy
Health scoring does not treat every piece of evidence equally - a verified certificate is worth far more than an unverified claim:
| Evidence type | Credit | Example |
|---|---|---|
| Verified certification | Full credit | SOC 2, ISO 27001 with a valid certificate on file |
| Independent registry | High credit | Listed with AICPA, ISO or a recognised registry |
| Gated / attested documentation | Partial credit | Shared under NDA or claimed with a supporting doc |
| Scraped or self-attested claim | Reduced credit | Found on a trust-center scan with no formal proof |
| Generic policy reference | Capped low | A public terms-of-service or privacy page |
The concentration-risk formula
Fourth-party concentration is a simple share calculation, run automatically across every sub-processor in a client's workspace:
Built for the MSSP operating model
Multi-tenant isolation
Client workspaces stay logically separate - vendor lists, contracts and sub-processor maps never cross between clients.
Reseller channel support
Every contract records its procurement channel (direct, reseller, marketplace or distributor) plus who bills it and who supports it, so obligations land on the right party.
Automated client deliverables
Vendor risk registers, concentration-risk dashboards and renewal projections generate on demand instead of getting rebuilt by hand every quarter.