Practical guideEN057

SaaS Vendor Security Checklist: How to Verify Before You Buy

A concise checklist for small businesses to assess SaaS vendor security before purchase, covering certifications, data handling, incident response, and contracts.

Before you commit to a new SaaS tool, run a focused security check. Start with the most critical question: Where does your data live, and who can access it? Ask the vendor for proof of security certifications like SOC 2 or ISO 27001, and confirm they support multi-factor authentication (MFA). Do not rely on marketing pages; request the actual reports and read the data processing agreement carefully.

Use this checklist as a practical starting point, built on guidance from NIST and CISA. Focus on what matters for your business: basic controls, certifications, data handling, and incident readiness. If a vendor is hesitant to provide clear answers, that is a red flag.

Basic Security Controls to Confirm First

Every SaaS vendor should enforce basic security controls. According to CISA, these include MFA for all users, strong password policies, and regular software updates. Ask directly: Do you support MFA for all admin accounts? Can we restrict access by role? Do you provide audit logs? These are non-negotiable for protecting your data.

If the vendor cannot answer clearly or says MFA is optional, treat it as a warning sign. For cloud apps, CISA emphasizes secure configuration and MFA as top priorities.

  • MFA enabled for all admin users.
  • Role-based access controls available.
  • Audit logs accessible to customers.
Sources and verification date: [2]

Independent Certifications and Assessments

Look for third-party certifications like SOC 2 Type II or ISO 27001. Ask for the latest report; established vendors will share it. If the vendor is smaller and lacks certifications, evaluate alternative controls and ask why they have not pursued them. CISA's guidance suggests verifying claims with evidence.

Also ask if they participate in frameworks like the Cloud Security Alliance CAIQ. A credible vendor will have a security page or trust center with current documentation.

  • Request a copy of the SOC 2 report or ISO certificate.
  • Check the date and scope of certifications.
  • Ask about any known gaps or pending assessments.
Sources and verification date: [2][3]

Data Handling, Encryption, and Subprocessors

Understand what data the vendor collects, how it is used, and whether it is shared with subprocessors. Demand a data processing agreement and a list of subprocessors. Confirm encryption in transit (TLS) and at rest. The U.S. ITA advises investigating partners' backgrounds; for SaaS, check if the vendor screens employees and has a clear data retention policy.

Ask about data deletion: Can you export your data and get it erased when you leave? Avoid vendors that make it difficult.

  • Encryption in transit and at rest.
  • Data retention and deletion policy.
  • Subprocessor list and notification process.
Sources and verification date: [1]

Incident Response and Business Continuity

Even strong vendors face breaches. What matters is their response. Ask for their incident response plan: How do they notify customers? What is the time frame? CISA recommends having your own plan, but you also need to know the vendor's obligations. NIST's CSF guide highlights incident response as core to risk management.

Check their uptime SLA and business continuity plans. For regulated industries, ask about specific compliance (e.g., HIPAA, PCI DSS). Ensure breach notification responsibilities are written into the contract.

  • Documented incident response process.
  • Clear breach notification time frame.
  • Business continuity and disaster recovery plans.
Sources and verification date: [2][3]

Contractual Protections and Exit Strategy

Your contract should protect you. Include clauses for data ownership, return and deletion upon termination, and liability limits. The U.S. ITA advises due diligence on partners; ensure the vendor has financial stability and cyber insurance. Also, define service level commitments and penalties for non-compliance.

Plan your exit: Confirm you can export all data in a standard format and that deletion is verifiable. Avoid long lock-in periods without flexibility.

  • Data export and deletion rights.
  • Liability and indemnification terms.
  • Service level agreement with remedies.
Sources and verification date: [1]

What to verify

  • Certifications may expire or change scope; always verify current status with the vendor or issuing body.
  • Laws and regulations vary by jurisdiction and industry; consult a qualified advisor for compliance.
  • SaaS features and security practices change; confirm details directly with the vendor before reliance.

Questions and answers

What if a vendor refuses to share security documentation?

As a first step, ask for a security whitepaper or trust center summary. If nothing is provided, treat it as a red flag. For sensitive data, require a SOC 2 or ISO certificate; most established vendors share at least an executive summary. If they refuse all verification, consider alternative vendors. [2]

Is multi-factor authentication truly mandatory?

Yes, it is a core control. CISA lists MFA as essential for all users, especially administrators. Without MFA, a single stolen password can expose your data. If a vendor does not support MFA, do not use them for business-critical processes. [2]

How often should I re-check vendor security?

At least once a year, or when the vendor updates terms or experiences a major incident. Also review if your data usage changes. NIST's CSF guide encourages integrating security reviews into your regular risk management cycle. [3]

Sources and verification date

  1. Official source: trade.govtrade.gov · Checked
  2. Official source: cisa.govcisa.gov · Checked
  3. Official source: csrc.nist.govcsrc.nist.gov · Checked

Related reading