Release 3.28.1

New Vendor Assessments and Wider NIS2 Coverage

Third-party risk and regulatory compliance work covers more ground every year, and keeping pace with new vendor types and country-specific frameworks takes real effort. This release expands coverage on both fronts: new vendor assessment templates, two additional national NIS2 frameworks, and a direct integration with Cavelo's CIS Benchmarks scanner.

TPRM Integrations Compliance

What’s in This Release

  • Three new vendor assessment templates for SaaS, privacy, and payment vendors
  • Two more national NIS2 frameworks, plus regional scoping in onboarding
  • A new Cybersecurity Measures asset type that links security tools to tasks
  • Cavelo CIS Benchmarks findings ingested and mapped to remediation tasks

Three New Vendor Assessment Templates

Vendor assessment work often starts with the questionnaire. Every new category of vendor can mean writing one from scratch or adapting a generic template that may not fit the risk profile. Three new templates join the third-party risk management library, each built around a specific risk domain rather than a generic checklist, reducing the need to build these assessments from scratch.

  • SaaS & Software Vendor Security Assessment – evaluates cybersecurity posture and secure development practices, covering governance, cloud security, software development lifecycle controls, and operational resilience
  • Sensitive Data & Privacy Assessment – for vendors that process sensitive personal information, evaluating security, privacy, and compliance controls in a single framework
  • Cardholder Assessment – for vendors that process, transmit, or store payment card data, covering the risks specific to regulated financial information and payment environments

Each template unifies security, privacy, and compliance questions in one pass, so a vendor answers once instead of filling in three overlapping forms. You can scope and send an assessment for a software provider, a data processor, or a payment vendor without building the questionnaire first.

Why this matters

These templates reduce the setup required to add vendor risk assessments for three common vendor categories.

Cover More National NIS2 Rules, and Spot Them Earlier

NIS2 arrives in each country as its own national law, so a client operating in Belgium and a client operating in Croatia face different obligations derived from the same EU directive. Tracking those requirements country by country adds complexity as partners scale across clients. Two more national transpositions join the framework library, and both are assessed through compliance management like any other framework.

  • CyFun 2025 (Belgium) – the Cyber Fundamentals baseline, for implementing and assessing the essential controls aligned with Belgium’s NIS2 requirements
  • Cybersecurity Act (Croatia) – Croatia’s NIS2 implementation, setting mandatory requirements for regulated entities while staying consistent with wider EU expectations

Onboarding also changed. A new question captures the regions relevant to a client’s organization, and at the end of onboarding a Cynomi agent analyzes that answer alongside the other scoping responses and may suggest additional regulatory or framework scope for consideration. Regional exposure can surface during scoping, reducing the need to revisit framework coverage later in the engagement.

Record the Security Tools Behind Every Task

Most clients already run security tooling, but that information may be spread across individual records, spreadsheets, or prior onboarding materials. A new asset type in the Asset Management module, Cybersecurity Measures, gives those tools a home, with 22 types under it including Identity & Access Management, Endpoint Security, SIEM, Vulnerability Management, and Firewall and Network Segmentation.

Assets added to the category are automatically linked to the relevant implementation tasks, so the record shows which tool supports which piece of work. You can add them one at a time or upload them in bulk with the XLSX template.

One thing to expect during the changeover: Firewalls, currently under Network Infrastructure Type, and SIEM and Security Tools, currently under Application Type, may appear twice until migration into Cybersecurity Measures is complete. The duplicate entries stay until that finishes.

Cavelo CIS Benchmarks Findings, Mapped to Remediation Tasks

Cavelo already scans for endpoint vulnerabilities in Cynomi through the existing Cavelo Endpoint Vulnerability scan integration. A second one now covers Cavelo CIS Benchmarks, connected directly through the API. It evaluates system configurations against industry-recognized CIS benchmarks, identifying misconfigurations and compliance gaps across the environment.

Cavelo CIS Benchmarks findings are ingested into Cynomi automatically and mapped to relevant remediation tasks. Configuration findings arrive mapped to assigned work, giving you scan-based context to validate posture without manually translating a separate report. Both Cavelo scans, and the rest of the connected tooling, are listed on the integrations page.

Also in This Release

  • DOCX export now covers the Risk Findings Report and Compliance Reports, so both can be edited before they go into a client deliverable. See dashboards and reporting
  • A new user guide for the Cynomi External Scan, setting out the scanner tests and the types of issue each one detects
  • Clearer AWS integration guides, with the setup instructions updated

What This Adds Up To

Read together, these changes are about starting engagements faster and finishing them with less rework. Three vendor categories can be assessed without writing a questionnaire, two more national regulations are covered for clients who need them, the tools a client already runs are recorded against the tasks they support, and configuration findings arrive as remediation work rather than as another report. For a partner running vendor risk and compliance across a book of clients, that is fewer setup steps between winning the work and delivering it.

Frequently Asked Questions

Which vendor assessment templates are new?

Three: the SaaS & Software Vendor Security Assessment, the Sensitive Data & Privacy Assessment, and the Cardholder Assessment. Each sits in the TPRM template library alongside the existing ones.

Which NIS2 national frameworks were added?

CyFun 2025 for Belgium and the Cybersecurity Act for Croatia. Both are national implementations of the EU NIS2 Directive, so they carry country-specific requirements.

Do I have to re-enter my clients' security tools?

You can add them manually or upload them in bulk using the XLSX template. During the transition, Firewalls and SIEM and Security Tools may appear both in their existing categories and under Cybersecurity Measures until migration completes.

What does the Cavelo CIS Benchmarks integration bring in?

Cavelo CIS Benchmarks findings, ingested automatically through a direct API integration and mapped to relevant remediation tasks. It runs alongside the existing Cavelo Endpoint Vulnerability scan integration rather than replacing it.

Which reports can now be exported as DOCX?

The Risk Findings Report and Compliance Reports. The editable format is intended for sharing, customization, and building into external documentation and client deliverables.

Which Cynomi release do these changes ship in?

Release 3.28.1, March 2026. It covers third-party risk management, framework coverage, asset management, integrations, reporting, and onboarding scoping.

The Security Growth Platform
for Service Providers

Discover how Cynomi can help you standardize delivery, accelerate onboarding, and scale your CISO advisory services.