Comparative analysis and selection rubric for third-party risk management

TPRM
How to Choose a TPRM Platform: Criteria for 2026
NIS2, DORA and the ENS all agree that provider risk cannot be outsourced away by subcontracting the service, which turns third-party risk management (TPRM) into a mandatory compliance function. This document explains what each framework requires on third parties, the five criteria blocks that separate a functional TPRM platform from the rest, and provides a reusable evaluation matrix for RFP/RFI processes.
NIS2, DORA and the ENS all agree that provider risk cannot be outsourced away by subcontracting the service, which turns third-party risk management (TPRM) into a mandatory compliance function. This document explains what each framework requires on third parties, the five criteria blocks that separate a functional TPRM platform from the rest, and provides a reusable evaluation matrix for RFP/RFI processes.
The preview of this whitepaper includes the executive summary, regulatory context and methodological approach that frames the rest of the document. Download to access full templates, matrices and checklists.
Gorka Gonzalo
Founder & CEO
Founded Hodeitek in 2023 and runs the company. A cybersecurity and AI expert, he sets the technical and product direction of HodeiShield and personally leads the most critical engagements — from defense strategy to applying AI in threat detection. He is the client's direct point of contact: whoever scopes the work also answers for the result.
“This whitepaper is the clearest guide I've seen on NIS2 in 2026.”
Article 21.2.d of NIS2 requires essential and important entities to manage the security of their direct suppliers and service providers as part of their risk management policy. This guide explains what the article actually requires, how it relates to the ENS and DORA, and proposes a phased implementation plan with checklists and a reusable supplier assessment questionnaire template.
Regulation (EU) 2022/2554 (DORA) has applied directly across the EU since 17 January 2025 and governs how financial entities must manage ICT risk, classify and notify incidents, test their resilience (including TLPT) and manage their technology providers. This manual translates DORA's five pillars into a step-by-step implementation plan, with an exhaustive checklist per pillar and a reusable ICT provider factsheet template.