Upcoming Webinars
Access the latest trends and insights shaping the profession—free for members.
Register early—members get 20% off when enrolling 60+ days before courses start.
Boost efficiency, transparency, and accuracy in proposal management to improve contract outcomes.
Charting Your Course to Success
From foundational knowledge to advanced leadership skills, NIGP offers a wealth of tools and resources to help you navigate your professional journey and achieve your leadership goals.
Your step-by-step guide to a successful career in public procurement.
Get 20% off by registering 60 days prior to the course start date.
All the tools to help you successfully prepare for certification.
Closes September 30.
NIGP and Sourcewell are dedicated to lifelong learning and professional development for every member.
Start your job search in the field of Public Procurement.
A Network of 18,000+ Professionals working in the field of Public Procurement.
As volunteers serve the Institute, the Institute serves the profession, and the profession serves society.
Each year, NIGP recognizes members who have achieved hallmark status in the eyes of their peers.
Register early—members get 20% off when enrolling 60+ days before courses start.
Boost efficiency, transparency, and accuracy in proposal management to improve contract outcomes.
Charting Your Course to Success
From foundational knowledge to advanced leadership skills, NIGP offers a wealth of tools and resources to help you navigate your professional journey and achieve your leadership goals.
Your step-by-step guide to a successful career in public procurement.
Get 20% off by registering 60 days prior to the course start date.
All the tools to help you successfully prepare for certification.
Closes September 30.
NIGP and Sourcewell are dedicated to lifelong learning and professional development for every member.
Start your job search in the field of Public Procurement.
A Network of 18,000+ Professionals working in the field of Public Procurement.
As volunteers serve the Institute, the Institute serves the profession, and the profession serves society.
Each year, NIGP recognizes members who have achieved hallmark status in the eyes of their peers.
Kirk Buffington
How can we be more pro-active in managing the risk of our suppliers? In a previous blog post, I had written about Vendor Tiering (see https://www.nigp.org/blog/vendor-tiering ) and how this risk model offers an additional layer of granularity, allowing for more tailored risk management practices based on vendor criticality and risk profile.
If your agency is concerned about the cybersecurity posture of its suppliers, it can strengthen vendor accountability and risk mitigation by requiring a combination of industry-recognized certifications, security assessments, contractual clauses, and attestations. Below is a list of requirements that you may wish to consider:
1. SOC 2 Type II Report (System and Organization Controls)
2. ISO/IEC 27001 Certification
ISO 27001 Information Systems.
3. FedRAMP Authorization (for cloud-based services)
4. Cybersecurity Maturity Model Certification (CMMC)
cybersecurity-maturity-model-certification.
5. State or Local Government Security Standards
1. Written Information Security Policy (WISP)
2. Incident Response Plan (IRP)
3. Annual Risk Assessments
1. Right to Audit
2. Data Breach Notification Clause
3. Data Handling Requirements
4. Flow-Down Requirements
1. Penetration Test Results (Redacted or Summary Reports)
2. Vulnerability Scans
3. Employee Security Awareness Training
Kirk Buffington
Stay Informed, Join our Mailing List
Jul 09, 2025
Jun 18, 2025
May 14, 2025