Built for the CISO
Security posture starts at vendor selection, not after the breach.
We're the independent buy-side for mid-market technology sourcing. Compliance fit, BAA structure, sub-processor disclosure, and MDR alignment get weighted in the rubric before the vendor reaches your shortlist.
For security leaders at multi-location operators between $25M and $500M in revenue.
Questions this page answers
What a CISO actually wants to know before bringing in a sourcing advisor.
- How is HIPAA, PCI, FFIEC, and SOC 2 weighted in the scoring rubric?
- What does BAA structure look like in the vendor shortlist?
- How are sub-processors and data residency disclosed?
- How does MSSP/MDR alignment with the recommended platforms get evaluated?
- What's the data handling and retention model for the engagement itself?
What CISOs care about
Security posture isn't a procurement checkbox. It's the rubric.
A CCaaS platform that handles PHI, an SD-WAN that traverses regulated traffic, an MSSP that owns your detection — every one of these is a CISO decision dressed up as a procurement decision. Six concerns drive the conversation.
- Compliance fit. HIPAA for healthcare. PCI for retail and hospitality. FFIEC and SOC 2 Type II for financial services. GLBA where it applies. The vendor either maps to your regulatory environment or doesn't.
- BAA structure. For HIPAA-regulated buyers, the Business Associate Agreement is non-negotiable. Vendors who won't sign a real BAA disqualify themselves.
- Sub-processor disclosure. Every cloud platform has sub-processors. Knowing who they are, where they are, and what they touch is the difference between defensible third-party risk management and a future audit finding.
- MSSP / MDR alignment. Your detection stack has to integrate with the platforms you're sourcing. Log formats, telemetry forwarding, SIEM integration. The vendor that doesn't integrate cleanly is the vendor that creates a detection gap.
- Breach history and posture. Recent breach disclosures, third-party penetration test cadence, open critical vulnerabilities. The Vendor Scorecard surfaces them.
- Data residency and encryption. Where the data lives, how it's encrypted at rest, how keys are managed. Vendor claims versus vendor practice.
How Cardinal helps
Four things a CISO gets from a Cardinal engagement.
Security weighted in the rubric, not bolted on.
The Cardinal Method weights compliance and security explicitly by industry. HIPAA at 25 percent for healthcare buyers. PCI at 25 percent for retail. SOC 2 Type II plus FFIEC plus PCI combined at 35 to 45 percent for financial services. Your security team can also write a custom security requirements section that gets its own weighted dimension. The math is published.
A documented security review on every shortlisted vendor.
Every vendor we shortlist gets a security review from the Cardinal Index — current SOC 2 attestation, recent breach history, third-party penetration test cadence, data residency, encryption posture, sub-processor disclosure, open vulnerabilities relevant to your industry. The review lands in the Vendor Scorecard, not as an appendix but as a scored dimension.
BAA structure validated before recommendation.
For HIPAA-regulated buyers, we confirm whether the vendor signs a real BAA, what the BAA actually covers, and where the data flows that BAA needs to follow. Vendors who can't or won't sign a defensible BAA don't reach your shortlist. We filter that in intake.
MSSP and MDR alignment scoped against your detection stack.
If you're running an MSSP for managed detection, the new platform has to feed it. We document telemetry options, log formats, SIEM connectors, and webhook availability on every shortlisted vendor. Detection gaps don't get discovered in production.
Common risks we de-risk
The failure modes that turn a vendor signature into a security incident.
- Vendors with weak or boilerplate BAAs. A BAA that excludes the actual data flow is a BAA that fails the audit. We validate the BAA scope, not just its existence.
- Undisclosed sub-processors. A vendor that won't name its sub-processors is a vendor you can't run third-party risk on. We surface the list during evaluation.
- Recent breach history hidden in marketing. Vendors don't volunteer their incidents. The Cardinal Index tracks disclosed and publicly reported breach events across the active pool.
- Detection gaps after cutover. A vendor whose telemetry doesn't reach your SIEM is a blind spot. We document SIEM connectors during evaluation, not after deployment.
- Data residency drift. Cloud platforms move data across regions for redundancy and performance. The residency commitment in the contract has to match the residency in practice.
- Sales-deck SOC 2 versus actual attestation. "We're SOC 2" without a current Type II report and a scoped audit boundary is marketing. We pull the report.
What you receive
The deliverables that land in security's inbox.
Four documents. Templated, fixed-scope. The Vendor Scorecard carries the documented security review for every shortlisted option.
- Sourcing Brief. Current-state inventory, regulatory context, buyer-supplied security requirements, and the success criteria security signed off on.
- Benchmark Report. Your contract versus comparable mid-market operators on the same service profile.
- Vendor Scorecard. Three shortlisted vendors scored against the rubric, with security review documented — SOC 2 status, breach history, sub-processors, encryption, residency.
- Decision Memo. Commercial terms, implementation plan, and risk register including security risks.
In short
What a CISO gets from a Cardinal engagement.
- Compliance fit weighted explicitly in the scoring rubric — HIPAA, PCI, FFIEC, SOC 2.
- A documented security review on every shortlisted vendor, in the Scorecard.
- BAA structure, sub-processors, and data residency validated before recommendation.
- MSSP and MDR alignment scoped against the new platform's telemetry options.
- Zero buyer fee.
Questions CISOs ask first.
How does security get weighted in your scoring rubric?
Security weighting varies by industry context. For healthcare and regulated buyers, HIPAA and BAA compliance run 25 percent of the scoring weight. For financial services, SOC 2 Type II, FFIEC examiner readiness, and PCI compliance run a combined 35 to 45 percent depending on the engagement. For retail, PCI gets 25 percent on its own. The full weights are published in the Method documentation.
Do you source MSSP and managed security services?
Yes. Our active pool includes 30-plus MSSPs across enterprise security operations, incident response, threat detection, vulnerability management, and compliance-focused security operations. The list is published with the rest of the supplier pool.
How do you handle the security review of recommended vendors?
Every vendor we shortlist for an engagement goes through a security review pulled from the Cardinal Index: current SOC 2 attestation status, recent breach history, third-party penetration test status, data residency, encryption posture, and any open vulnerabilities relevant to your industry. The review is included in the Vendor Scorecard.
What's your data handling during the sourcing process?
Buyer-side data — contracts, infrastructure inventory, integration requirements — is encrypted at rest in our engagement systems. Vendor-side data is shared on a need-to-know basis per the engagement NDA. We do not retain uploaded contracts longer than three years from engagement close. Tier 1 benchmark submissions are deleted after the benchmark is delivered.
Can you include security-specific requirements in the RFP?
Yes. Your security team writes the security requirements section. We integrate it into the sourcing brief and require vendor responses against it. The Cardinal Method explicitly accommodates buyer-supplied security requirements as a scoring dimension.
Filter vendors at the rubric, not at the breach.
Upload a contract. Get the Benchmark Report in five business days. If the numbers warrant a sourcing engagement, we run the Cardinal Method end-to-end with security weighted explicitly.