What’s in This Release
- Three new vendor assessment templates for SaaS, privacy, and payment vendors
- Two more national NIS2 frameworks, plus regional scoping in onboarding
- A new Cybersecurity Measures asset type that links security tools to tasks
- Cavelo CIS Benchmarks findings ingested and mapped to remediation tasks
Three New Vendor Assessment Templates
Vendor assessment work often starts with the questionnaire. Every new category of vendor can mean writing one from scratch or adapting a generic template that may not fit the risk profile. Three new templates join the third-party risk management library, each built around a specific risk domain rather than a generic checklist, reducing the need to build these assessments from scratch.
- SaaS & Software Vendor Security Assessment – evaluates cybersecurity posture and secure development practices, covering governance, cloud security, software development lifecycle controls, and operational resilience
- Sensitive Data & Privacy Assessment – for vendors that process sensitive personal information, evaluating security, privacy, and compliance controls in a single framework
- Cardholder Assessment – for vendors that process, transmit, or store payment card data, covering the risks specific to regulated financial information and payment environments
Each template unifies security, privacy, and compliance questions in one pass, so a vendor answers once instead of filling in three overlapping forms. You can scope and send an assessment for a software provider, a data processor, or a payment vendor without building the questionnaire first.
Why this matters
These templates reduce the setup required to add vendor risk assessments for three common vendor categories.
Cover More National NIS2 Rules, and Spot Them Earlier
NIS2 arrives in each country as its own national law, so a client operating in Belgium and a client operating in Croatia face different obligations derived from the same EU directive. Tracking those requirements country by country adds complexity as partners scale across clients. Two more national transpositions join the framework library, and both are assessed through compliance management like any other framework.
- CyFun 2025 (Belgium) – the Cyber Fundamentals baseline, for implementing and assessing the essential controls aligned with Belgium’s NIS2 requirements
- Cybersecurity Act (Croatia) – Croatia’s NIS2 implementation, setting mandatory requirements for regulated entities while staying consistent with wider EU expectations
Onboarding also changed. A new question captures the regions relevant to a client’s organization, and at the end of onboarding a Cynomi agent analyzes that answer alongside the other scoping responses and may suggest additional regulatory or framework scope for consideration. Regional exposure can surface during scoping, reducing the need to revisit framework coverage later in the engagement.
Record the Security Tools Behind Every Task
Most clients already run security tooling, but that information may be spread across individual records, spreadsheets, or prior onboarding materials. A new asset type in the Asset Management module, Cybersecurity Measures, gives those tools a home, with 22 types under it including Identity & Access Management, Endpoint Security, SIEM, Vulnerability Management, and Firewall and Network Segmentation.
Assets added to the category are automatically linked to the relevant implementation tasks, so the record shows which tool supports which piece of work. You can add them one at a time or upload them in bulk with the XLSX template.
One thing to expect during the changeover: Firewalls, currently under Network Infrastructure Type, and SIEM and Security Tools, currently under Application Type, may appear twice until migration into Cybersecurity Measures is complete. The duplicate entries stay until that finishes.
Cavelo CIS Benchmarks Findings, Mapped to Remediation Tasks
Cavelo already scans for endpoint vulnerabilities in Cynomi through the existing Cavelo Endpoint Vulnerability scan integration. A second one now covers Cavelo CIS Benchmarks, connected directly through the API. It evaluates system configurations against industry-recognized CIS benchmarks, identifying misconfigurations and compliance gaps across the environment.
Cavelo CIS Benchmarks findings are ingested into Cynomi automatically and mapped to relevant remediation tasks. Configuration findings arrive mapped to assigned work, giving you scan-based context to validate posture without manually translating a separate report. Both Cavelo scans, and the rest of the connected tooling, are listed on the integrations page.
Also in This Release
- DOCX export now covers the Risk Findings Report and Compliance Reports, so both can be edited before they go into a client deliverable. See dashboards and reporting
- A new user guide for the Cynomi External Scan, setting out the scanner tests and the types of issue each one detects
- Clearer AWS integration guides, with the setup instructions updated
What This Adds Up To
Read together, these changes are about starting engagements faster and finishing them with less rework. Three vendor categories can be assessed without writing a questionnaire, two more national regulations are covered for clients who need them, the tools a client already runs are recorded against the tasks they support, and configuration findings arrive as remediation work rather than as another report. For a partner running vendor risk and compliance across a book of clients, that is fewer setup steps between winning the work and delivering it.