Two families of tools claim to tell you whether a vendor is safe. Security rating platforms scan a vendor's external footprint and produce a score, continuously, without the vendor's participation. Assessment-driven TPRM platforms collect the vendor's own answers and evidence through questionnaires, periodically, with the vendor's full participation.
Buyers routinely frame this as a versus decision, and vendors on both sides encourage it. The honest answer is that the two measure different things, disagree for structural reasons, and map to different program needs. This guide explains what each does well, where each stops, what their disagreement actually tells you, and how to decide what your program needs, including when the right answer is one, the other, or both.
What ratings-only platforms measure well
Security rating tools observe a vendor from the outside, the way an attacker would during reconnaissance. Done well, this covers:
- External attack surface. Open ports, exposed services, forgotten subdomains, unmaintained assets.
- Configuration hygiene. TLS versions and certificate management, email authentication (SPF, DKIM, DMARC), DNS security posture.
- Observable patching behavior. Known-vulnerable software versions visible on public-facing services.
- Compromise indicators. Leaked credentials in breach corpuses, botnet traffic attributed to the vendor's ranges, leak-site listings.
Their structural advantages are real and worth naming plainly. They are continuous: the score updates as the vendor's surface changes, not once a year. They are independent: no self-reporting bias, no waiting for a questionnaire response. They scale: rating 500 vendors costs roughly the same effort as rating 50. And they are comparable: every vendor is measured with the same instrument, which makes portfolio-level views possible.
Where ratings stop
The same outside-in method that gives ratings their independence imposes hard limits.
- They cannot see internal controls. Access reviews, offboarding discipline, backup testing, incident response capability, security training, segregation of duties: none of it is visible from the internet, and much of vendor risk lives exactly there.
- Attribution is fragile. Scores depend on correctly mapping domains and IP ranges to the vendor. Shared infrastructure, subsidiaries, and stale asset maps produce scores that partly measure someone else's hygiene. Any rating you act on deserves an attribution check first.
- The score compresses too much. A single number blends signal families with very different meanings for you. A vendor with sloppy marketing-site TLS and excellent production security can score the same as the reverse case, and only one of them should worry you.
- They measure the vendor, not your relationship. The rating is identical whether the vendor stores your regulated data or supplies your office snacks. Risk is a function of exposure, and exposure is invisible from outside.
What assessment-driven TPRM measures well
Questionnaire-based assessment goes where scans cannot: inside the vendor's control environment, with the vendor's participation. Done well, it covers governance and process (policies, risk management, training), identity and access management, data handling for your specific data classes, resilience and incident response, and, through evidence requirements, whether claimed controls are certified or demonstrable rather than merely asserted. Its structural advantages mirror the ratings list: it is relationship-aware (you ask about your data, your integration, your notification timelines), it is deep (hundreds of control-level questions against a scan's external surface), and it is contractual (the assessment process creates documented commitments you can enforce).
Where assessments stop
- They are point-in-time. The answers were true, at best, on the day they were written. Everything after is unverified until the next cycle, typically 12 to 24 months later.
- They are self-reported. Evidence requirements and audit reports mitigate this, but a determined or merely optimistic vendor can present a control environment tidier than the one they operate.
- They are expensive on both sides. Analyst hours to score and validate, vendor hours to respond. Cost scales with portfolio size and caps how often you can reassess.
- They lag reality. A vendor whose environment deteriorated in June looks fine in your records until the next assessment lands, possibly a year later.
Read the two "where it stops" lists together and the pattern is exact: each method's blind spot is the other's strength. Ratings are continuous, shallow, and outside-in. Assessments are periodic, deep, and inside-out.
Why the two signals disagree, and what the gap means
Put both signals on the same vendor and they will sometimes disagree sharply. A vendor with a strong completed assessment and a deteriorating external rating. A vendor with a mediocre questionnaire and a spotless external surface. The disagreement is not a defect in either tool. It is information, and it is arguably the most valuable read available in vendor risk:
- Good assessment, deteriorating external signal suggests the attested control environment is no longer operating as described: drift, staffing loss, a migration gone wrong, or an environment change since attestation. This is the case that annual assessment structurally cannot catch, and the strongest trigger for an off-cycle reassessment.
- Weak assessment, clean external signal suggests immature governance with competent operations, common in young engineering-led vendors. The external surface is fine today; the missing process is the risk that shows up under stress, in incident response and offboarding.
- Both degrading is your clearest escalation case, and both strong is your clearest approval, but note that agreement is only meaningful when you are measuring with both instruments.
Programs that run only one signal never see the gap at all. A ratings-only program mistakes a clean scan for a healthy vendor. An assessment-only program mistakes a filed questionnaire for current truth.
A decision framework: which do you need, and when
Work through these questions in order.
- Do your vendors hold sensitive data or system access? If yes, you need assessment. External ratings cannot tell you how your data is handled, and no regulator or enterprise customer will accept a score in place of due diligence on data-handling controls.
- Is your reassessment gap longer than your risk tolerance? If a vendor could deteriorate for 12 months before you noticed, and that outcome is unacceptable for your critical tier, you need continuous external signal covering at least that tier.
- Is your portfolio past roughly 50 vendors? Below that, disciplined assessment with event-driven news watching can carry a program. Past it, continuous monitoring becomes the only affordable way to know when to look, because you cannot assess your way to currency at that scale.
- Are you buying ratings for triage or for truth? Ratings are excellent for prioritization: which vendor to assess next, where drift warrants questions. They are weak as verdicts. If a score would be your final answer on a critical vendor, you are asking the instrument for more than it measures.
- Can you operationalize two disconnected tools? This is the question buyers skip. A rating platform and an assessment platform that never share a record push the reconciliation work onto your team, usually as a quarterly manual exercise, usually abandoned by the second quarter.
The honest summary: a small portfolio with low data sensitivity can defer ratings. A program whose vendors touch sensitive data cannot defer assessment. And any program running both signals should plan, from day one, for where they reconcile.
What a unified record changes
If the two signals live in one place, on one vendor record, the workflow changes in four concrete ways:
- Divergence becomes visible by default. Reported posture and live exposure sit side by side, so the gap between them is a flag on the record, not a quarterly analysis project.
- Monitoring gets a memory. Drift is measured against the baseline set by the last completed assessment, and resets only when a new assessment completes, so a score recovering on its own never quietly erases an unexplained deterioration.
- Alerts inherit context. An external finding lands on a record that already knows the vendor's tier, data exposure, and open remediation items, which is the difference between an alert you can triage in minutes and a score change you have to research.
- The audit trail is one trail. When an examiner or customer asks how you oversee a vendor, the answer is one record: criticality, assessment history, evidence, external signal, drift events, and remediation, in sequence.
None of this makes either signal better than it is. It makes their disagreement, which is where the insight lives, impossible to miss.
Evaluation checklist: questions for any tool in this space
For rating platforms:
- How is asset attribution built, and can we correct it per vendor?
- Can the score be decomposed into signal families, or is it one opaque number?
- Does it alert on change, or restate static scores?
- What is the false-positive experience at our portfolio size?
For assessment platforms:
- Which instruments are supported (SIG, CAIQ, custom), and can evidence be required per question?
- Do reviewer decisions override automated scoring, with the override recorded?
- Are remediation items tracked to verified closure with SLAs?
For both, and for any unified platform:
- Do both signals land on the same vendor record?
- Is drift measured against an assessment-set baseline that resets only on completed reassessment?
- Is drift severity tiered before anyone is alerted?
- Can an auditor trace the full sequence from signal to decision on one record?
FAQ
Can a security rating replace vendor questionnaires? No, and reputable rating vendors do not claim it can. Ratings observe the external surface; questionnaires cover internal controls and your specific relationship. For vendors holding sensitive data, due diligence expectations from regulators and enterprise customers require assessment. Ratings are best used to prioritize and to challenge assessments, not to replace them.
Why does our vendor dispute their rating? Usually attribution: the score includes assets that are not theirs, or stale assets they have decommissioned. Sometimes compression: a real but low-relevance finding is dragging a headline number. Treat a dispute as useful signal either way; the resolution process tells you a lot about the vendor's asset management maturity.
If we can only afford one, which comes first? For most programs, assessment comes first, because it is the layer that regulators, auditors, and enterprise customers require, and because it establishes the baseline that makes monitoring meaningful later. Add continuous signal for the critical tier as the program matures, or earlier if your reassessment gap is a risk you cannot accept.
Are the two signals ever genuinely redundant? Rarely, and only at the extremes: a tiny, low-sensitivity vendor may not warrant either beyond a certification check. For any vendor that matters, the signals answer different questions (what is attested versus what is observable now), so one cannot stand in for the other.
Where ThirdSentry fits
ThirdSentry takes a position in this debate, and it is not that one side wins. Vendor Dual-Signal Risk Intelligence carries three layers on every vendor record: business criticality, assessed posture from completed questionnaires, and live external exposure from continuous monitoring. Drift is measured against the assessment-set baseline, tiered as Minor, Moderate, or Severe, and the platform flags the moment reported posture and live signal stop agreeing, because that disagreement is where vendor risk actually announces itself. If you are currently reconciling a rating tool and an assessment tool by hand, book a demo and see both signals on one record.