Cloud and SaaS vendor assessment
Cloud suppliers are rarely short of documentation. The difficulty is that the answer to a single question is distributed across a certificate, an attestation report, a trust page, the processing terms and a sub-processor list maintained somewhere else entirely — each written for a general audience rather than for your engagement.
Sample assessment
Northstar Cloud AB · SaaS service
- Hosting region
- eu-north-1 (Stockholm)
- Sub-processor list
- Published, 11 entries
- Support access model
- Follow-the-sun support
- Attestation report
- SOC 2 Type II, 12 months
- Processing terms
- DPA with SCCs annexed
- Incident notification
- Process documented
Every line is read from supplier documentation. Governli reviews evidence; it does not scan supplier infrastructure.
Finding
Partial evidenceData residency
Hosting inside the EU is evidenced. The support model indicates that authorised support personnel may access production data from outside the EEA, and no transfer safeguard is mapped to that path.
Decision implication: Clarification required before approval
What makes cloud procurement its own problem
With a traditional supplier, the thing you are buying and the thing that was audited tend to be the same. With cloud services they routinely diverge. The supplier operates one platform for all customers, publishes assurance at the level of the whole company or the flagship product, and delivers your service through a particular tenant, region, module and support model that the published material may never mention.
Some controls are the supplier's, some are yours to configure, and some belong to the hyperscaler underneath. The assessment needs to be clear about which of your requirements you are actually responsible for satisfying.
A SaaS provider inherits controls from its infrastructure provider. Its certificate covers its own management system; the underlying platform has its own. Neither automatically covers the other.
Sub-processors, regions and features change during the contract term. That makes notification and objection terms far more consequential than they are for static suppliers.
New modules are frequently outside the last examination or certification cycle — a specific version of the same question the ISO and SOC 2 reviews ask.
The evidence set for a hosted service
Most of this is already public for an established SaaS supplier, which is an advantage — the collection step is quick, and the assessment can spend its effort on whether the material reaches your engagement.
- ISO 27001 certificate and Statement of Applicability
- SOC 2 Type I or Type II report
- CSA CAIQ or STAR self-assessment
- Data processing agreement and transfer documentation
- Published sub-processor list and change notification terms
- Security white paper and service architecture material
- Continuity, backup and recovery documentation
- Penetration test summary where the supplier shares one
Read individually, each document looks reassuring. The value of assessing them together against one requirement catalogue is that contradictions and silences become visible — a residency statement in a white paper that the processing terms do not commit to, or a control examined in a report for an environment the DPA does not mention.
Worked example: support access from outside the contracted region
Illustrative only. A SaaS supplier offers EU hosting, supplies a current ISO 27001 certificate and a standard DPA, and publishes a sub-processor list. Your requirement is that personal data is processed within the EEA, including any access by supplier personnel or sub-processors.
Personal data for the contracted service must be stored and processed within the EEA, including remote access by supplier staff and sub-processors, unless a documented transfer mechanism applies.
Product documentation confirms an EU hosting region for the tenant. ISO 27001 certificate covers the supplier's operations. DPA includes standard transfer provisions. Published sub-processor list includes a support platform and a follow-the-sun support provider, both with non-EEA locations noted.
Storage location is supported; processing location is not. Hosting evidence addresses data at rest, but the sub-processor list indicates support access may originate outside the EEA, and no document states whether that access involves personal data or how it is controlled. Recommended follow-up: ask whether support personnel access customer data, from which locations, under what technical restrictions, and which transfer mechanism applies.
The hosting evidence is retained and the requirement stays open on the access dimension only — a precise question rather than a general residency concern. Depending on the answer, the outcome may be an EU-only support option where the supplier offers one, a documented transfer assessment, or acceptance with the scope of access recorded.
No single document was wrong. The gap only appeared because the requirement was assessed across all of them at once — the point of Requirements-to-Evidence Mapping.
How this fits with the rest of the review
A cloud assessment usually draws on several narrower reviews at once: the ISO 27001 certificate and its scope, the SOC 2 report's period and criteria, the processing terms and, where control implementation is the concern, a vendor security assessment. Where commercial, contractual and operational requirements also apply, run it as full vendor due diligence instead of separate exercises. Suppliers falling under sector obligations are covered in NIS2 supplier requirements and DORA ICT supplier requirements. Browse all solutions.
Governli assesses documentary evidence. It does not connect to cloud environments, scan configuration or monitor a service continuously, and it does not guarantee that a cloud supplier is secure or compliant. Conclusions reflect the evidence supplied, the requirements configured and the reviewer's judgement of your context.
Cloud vendor assessment FAQ
A SaaS supplier publishes everything on a trust page. Is an assessment still worth running?+
Published material tells you what the supplier chose to make available; it does not tell you whether it covers the tenant, region and module you are contracting for, or whether it addresses the requirements specific to your use. Where a supplier publishes well, the assessment is faster — the evidence is already there — but the mapping step is what turns it into a decision about your engagement.
How should sub-processors be handled for a cloud service?+
Treat the list as evidence in its own right. What matters for most buyers is which sub-processors touch customer data, where they process it, how changes are notified and whether an objection route exists. The list itself usually comes from a public page while the commitments around it live in the processing terms, so both are needed to close a sub-processor requirement.
Does Governli scan cloud configuration or monitor services continuously?+
No. Governli does not connect to a supplier's cloud environment, scan configuration, or perform continuous technical monitoring of a service. It assesses the documentary evidence you and the supplier provide, at the point the assessment is run.