How to Assess SaaS Vendors' Security Before You Sign
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign — proportionate to risk.
Step 1: Tier vendors by risk
Classify each vendor by:
- Data sensitivity: what data will they hold (none, internal, personal, regulated)?
- Access: will they integrate with Microsoft 365, Entra ID or your cloud accounts?
- Criticality: what happens if they're unavailable for a week?
High-tier vendors get a full review; low-tier vendors a light one.
Step 2: Request evidence
For high-tier vendors:
- SOC 2 Type II report (or ISO 27001 certificate and statement of applicability).
- Recent penetration test summary.
- Incident history and how incidents were disclosed.
- Data location, retention and deletion practices.
- Sub-processor list.
Step 3: Ask targeted questions
- Do they support SSO with your identity provider and enforce MFA for their own staff?
- How is customer data segregated and encrypted?
- What OAuth permissions does their integration request in Microsoft 365?
- How quickly will they notify you of an incident?
Step 4: Review integrations
Check the permissions their app requests in Entra ID. Prefer least-privilege scopes and integrations that can be restricted to specific mailboxes or sites.
Step 5: Contract
Include security requirements, notification timelines, audit rights, data return and deletion.
Step 6: Monitor
Reassess high-tier vendors annually and monitor news and threat intelligence for incidents.
- Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom Incident Teardowns
- Monitoring Third-Party SaaS Risk Signals and Breach Notifications Detection & Response
- CIO Brief: Third-Party Ransomware and Your Disclosure Obligations CIO Briefings