Case studies
A major buyer requires a CyberVadis assessment, with a threshold and a deadline. Here are two real files, from the starting point to the score reached, without ever naming our clients or their buyers.
Real, anonymized cases. We publish neither our clients' names, nor their buyers', nor the detail of their gaps: that is their security file, not our sales material.
Check my readiness in 3 minutesThe context. A supplier needed to renew a contract with a major buyer in the energy sector. The CyberVadis assessment gated the renewal, with a firm deadline.
The starting point. At diagnostic, the file capped around 450 out of 1000: real practices, but little evidence to demonstrate them, and no written policy.
What we did. Prioritised gap diagnostic in week 1, documentation baseline written, dated evidence collected, pre-submission review.
The result. 918 out of 1000, rated Mature, file submitted within the buyer's deadline.
The context. A supplier was assessed at the request of an international cosmetics group. A first assessment had come back insufficient, at 550 out of 1000.
The starting point. The score stalled on controls declared as implemented but insufficiently evidenced: untracked access reviews, backups never tested, no documented awareness training.
What we did. The file was reworked control by control, evidence rebuilt and dated, weak points fixed before a new submission.
The result. 959 out of 1000, Platinum level, rated Mature, on a certificate valid for twelve months.
Three minutes to see where your file stands, no email required.
Check my readiness