Supplier guide
A major energy customer requires a CyberVadis assessment, with a threshold and a deadline. Nobody in house whose job this is. This page explains how the platform actually scores, where suppliers lose points, and what can be done before your deadline.
SecuredShift is not affiliated with TotalEnergies or CyberVadis. This page describes a supplier assessment situation as we encounter it in the field.
Check my readiness in 3 minutesYou will read everywhere that you need 700 out of 1000. That is a simplification.
The threshold is set by the buyer, not by the platform. It depends on how critical the data you handle for them is, on your level of access to their systems, and sometimes on the contract itself. Two suppliers of the same group can face two different bars.
What is verifiable, on the other hand, is the reference point: the average score across companies assessed by CyberVadis is 670 out of 1000. That figure is printed on the assessment reports. In other words, the level a major buyer expects usually sits above the market average, and that is the whole problem.
The first question to ask your procurement contact is the exact threshold and the campaign date. Until you have those two, you are working blind.
Every control receives one of three verdicts: fully validated, partially validated, not validated.
Your answer is not what decides, the attached evidence is. A control declared as implemented, with nothing capable of demonstrating it, does not earn the points you expect.
The assessment reads on two crossed axes: four focus areas, data privacy, data protection, business continuity and third-party security; and four functions, identify, protect, detect, react.
That crossing explains something many discover too late: you can clear a solid overall score and still be weak on one specific area, the very one your customer looks at.
On the assessments we support, the largest available gains almost never come from missing controls. They come from controls declared as implemented but insufficiently evidenced.
Each of these is worth several points. None of them requires a six-month project: they require dated evidence.
The CyberVadis performance report maps every assessed control to Article 21 of the NIS2 directive, to the objectives of the draft 2024 ANSSI framework, to the DORA pillars and its RTS articles, and to the controls of ISO 27001 version 2022 Annex A.
In other words, the file you build for your customer is also a NIS2 gap analysis and an ISO 27001 starting baseline. If NIS2 reaches you, and most suppliers to large groups are reached by cascade, you are doing the work twice by treating the two subjects separately.
That is the argument that unlocks internal budget: this is not a customer compliance expense, it is the company's regulatory baseline.
A supplier we supported reached 959 out of 1000, Platinum level, rated Mature, on a CyberVadis certificate valid for twelve months.
We publish neither their name nor their gap detail: that is their security file, not our sales material.
Six weeks from signature to submission. Prioritised gap diagnostic in week one, documentation baseline and priority remediations next, evidence kit assembled and pre-submission review, then submission and readout.
You write nothing: policies, procedures, registers and evidence are prepared for you, you validate. One contact on your side is enough.
The target score is agreed together after the diagnostic, and we work until it is reached, at no extra cost.
How long does it take?
Six weeks from signature to submission, with a first gap readout within seven days. The calendar is built backwards from your customer's campaign date, not the platform's.
What score should I aim for?
The one your buyer gave you. If they have not, ask before anything else. For reference, the average across assessed companies is 670 out of 1000.
Can I reuse the assessment for another customer?
That is one of the benefits: the evidence file you build serves the next questionnaires. Sharing the scorecard itself depends on your account terms.
I already submitted and the score is too low. Is it over?
No. A reassessment is possible, but your customer's campaign has a deadline. That is the first thing to check before deciding anything.
Does an ISO 27001 certification exempt me?
Not automatically, each buyer decides. Its real value is a single baseline that answers every questionnaire.
Three minutes to see where you stand, no email required.
Check my readiness