Learn to Build a Real-Time Data Foundation for AI | Join Webinar
Every organization that adopts a cloud platform takes on a shared responsibility: the assurance that its vendors are secure, compliant, and resilient. This is where third-party risk assessments (TPRAs) come in with a systematic evaluation of a vendor's security posture, operational resilience, and compliance standards. TPRAs are a cornerstone of modern security and procurement programs because they provide structured, verifiable evidence of a vendor's security posture. They replace assumption with verifiable proof.
Third-party assessments deliver real benefits across the business:
Faster procurement cycles: Replacing ad-hoc questionnaires with standardized, pre-completed reports
Regulatory compliance support: Helping organizations meet obligations under DORA, GDPR, APRA and other frameworks
Mutual efficiency: Vendors complete an assessment once, and customers access it many times
For Confluent customers, this means less time searching for documentation and more time moving forward with your data streaming strategy. Our Trust Center lists the various assessment reports for your team's needs, whether you are a procurement analyst needing a quick overview or a CISO requiring independently validated evidence.
Our approach to third-party risk management is rooted in our core commitment to security transparency.
We proactively do the heavy lifting so that our customers’ risk and compliance teams don’t have to start from scratch. Rather than responding to each evaluation individually, Confluent maintains current, independently validated assessments across the industry's most widely recognized platforms. When a customer begins due diligence, the relevant evidence is already available—reviewed, up to date, and structured to map directly to the customer's own control framework.
Confluent has completed multiple industry-recognized assessments, each designed for a different use case and level of rigor, so that risk teams can obtain evidence in the format they prefer. The following summarizes what is available today.
ProcessUnity Global Risk Exchange (formerly CyberGRX)
ProcessUnity Global Risk Exchange goes beyond self-attestation by combining vendor-completed assessments with automated validation. Controls are covered via domains like Identity & Access Management, Data protection, and vulnerability management. Confluent's CyberGRX profile is available on the CyberGRX Exchange, where customers can access and map controls against their own frameworks–such as NIST, ISO 27001, PCI-DSS, and HIPAA–without re-requesting the report each year. Higher-tier assessments include evidence review for additional assurance.
CyberVadis
CyberVadis combines questionnaire responses with mandatory supporting documentation, which is typically reviewed remotely by a team of three security analysts using a rigorous six-eyes process to ensure the highest level of accuracy and reliability. This evidence-based approach produces a detailed scorecard covering 20 cybersecurity topics aligned to ISO 27001, NIST CSF, GDPR, and DORA. Confluent's CyberVadis scorecard is available to customers (upon request) seeking a higher confidence level than pure self-reporting, without requiring an on-site audit.
TruSight / S&P Global KY3P
TruSight, now integrated into S&P Global's KY3P platform, represents the gold standard for financial services vendor due diligence. Originally built by a consortium of leading banks, including JPMorgan Chase, Bank of America, and Wells Fargo, it delivers fully independent, validated assessments from trained third-party assessors who examine actual control evidence, not just vendor self-attestation. Assessors inspect policies and procedures, review supporting documentation, and in some cases observe controls operating on-site. The assessment covers 200+ controls across about 26 categories. Confluent's KY3P assessment has been mapped directly to major internal control frameworks by leading financial institutions, making it the go-to report for highly regulated customers in banking, capital markets, and insurance.
Standardized Information Gathering (SIG)
The SIG, developed by Shared Assessments, is the industry's most widely adopted vendor risk questionnaire. Confluent's completed SIG covers 19+ risk domains including cybersecurity, privacy, IT operations, supply chain security, AI, and business resiliency, providing pre-vetted answers to over 850 standard security questions. The questionnaire's built-in framework mapping extends to numerous regulatory requirements, including CMMC, DORA, APRA, and others, and was updated in 2026 to reflect modern risks such as software supply chain compromise and AI-specific security risks. It is ideal for customers whose TPRM programs accept self-reported, standardized questionnaires as a basis for vendor approval.
Consensus Assessments Initiative Questionnaire (CAIQ)
The CAIQ, published by the Cloud Security Alliance (CSA), focuses specifically on cloud-native security controls. Confluent's completed CAIQ provides immediate visibility into how Confluent Cloud aligns with the CSA Cloud Controls Matrix, a standardized framework that helps assess the security capabilities of cloud service providers. While CAIQ serves as baseline assessment, Confluent has also achieved CSA’s Security Trust Assurance and Risk (STAR) Level 2 Certification, marking a commitment to a globally recognized cloud security assurance standard.
Not all assessments serve the same audience. Use this quick guide to identify which report fits your needs:
General procurement or IT risk: Start with the SIG or CAIQ for broad, fast coverage.
Cloud security review: The CAIQ maps directly to cloud-specific controls and is optimized for SaaS evaluations.
Continuous monitoring: CyberGRX's Exchange model allows dynamic, always-current access.
Supply chain or DORA/NIS2 compliance: CyberVadis provides analyst-validated evidence aligned to European regulatory standards.
Financial services or highly regulated industries: Request the TruSight/KY3P report for independently validated, audit-ready evidence.
Assessment | Type | Best For | Validation Level |
CyberGRX | Exchange platform | Tiered risk assessment with automated validation | Auto-validated, tiered evidence review |
CyberVadis | Evidence-based assessment | Supply chain risk; analyst-reviewed scoring | Remote analyst validation (six-eyes review) |
TruSight / S&P KY3P | Assessment-as-a-Service | Financial services institutions; deep independent validation | Independent on-site and remote validation |
SIG | Questionnaire | General vendor due diligence, broad industry use | Self-reported |
CAIQ | Questionnaire | Cloud security due diligence | Self-reported |
As enterprise landscapes are shifting rapidly, security leaders are no longer willing to accept "security by checkbox." The market is demanding deeper transparency, continuous verification and, above all, efficiency. The global TPRM market has been evolving and the forces driving this growth include expanding vendor ecosystems, rising cyberattack frequency and increasingly prescriptive regulation.
For risk, security, and procurement teams, the shift happening across the market translates into three very practical outcomes:
Operational efficiency: Vendor reviews that used to take weeks of back-and-forth questionnaires now take days. Standardized, pre-completed reports mean your team isn't waiting on a vendor to fill out a custom form before a deal or renewal can move forward; the evidence is already there.
Cost optimization: Every hour that your risk or procurement team spends searching for documentation is an hour not spent on higher-value work. The "assess once, share many" model, used by assessments like CyberGRX and TruSight/KY3P, exists specifically to eliminate the duplicative assessment cycles that drive up the real cost of vendor due diligence.
Regulatory risk reduction: Frameworks like DORA in Europe and FFIEC guidance in the US are raising the bar from simple questionnaire completion to evidence-based oversight. Independently validated, current assessments give a defensible, audit-ready record.
By maintaining a comprehensive portfolio of third-party assessments, from the broadly accessible SIG and CAIQ to the independently validated TruSight/KY3P report, Confluent equips your security, risk, and procurement teams with the evidence they need, in the format they want.
Whether you are onboarding to Confluent for the first time, completing an annual vendor review, or preparing for a regulatory audit, the Confluent Trust Center is ready to support you.
Confluent built automated investigator uniting a central triage coordinator, specialized evidence agents, an adversarial evaluator, and a self-learning knowledge base. By treating alerts as a continuous stream, we analyzed 100% of volume and scaled triage throughput.
Hemut is building an AI-native operating system for trucking. Using Confluent Cloud, its platform connects trucks, back-office systems, and AI agents through real-time data, creating an automated “Internet of Freight” that has already processed more than 286 million events.