Multi-CloudHow-To & HardeningRetrospectives

How to Assess SaaS Vendors' Security Before You Sign

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign — proportionate to risk.

Step 1: Tier vendors by risk

Classify each vendor by:

  • Data sensitivity: what data will they hold (none, internal, personal, regulated)?
  • Access: will they integrate with Microsoft 365, Entra ID or your cloud accounts?
  • Criticality: what happens if they're unavailable for a week?

High-tier vendors get a full review; low-tier vendors a light one.

Step 2: Request evidence

For high-tier vendors:

  • SOC 2 Type II report (or ISO 27001 certificate and statement of applicability).
  • Recent penetration test summary.
  • Incident history and how incidents were disclosed.
  • Data location, retention and deletion practices.
  • Sub-processor list.

Step 3: Ask targeted questions

  • Do they support SSO with your identity provider and enforce MFA for their own staff?
  • How is customer data segregated and encrypted?
  • What OAuth permissions does their integration request in Microsoft 365?
  • How quickly will they notify you of an incident?

Step 4: Review integrations

Check the permissions their app requests in Entra ID. Prefer least-privilege scopes and integrations that can be restricted to specific mailboxes or sites.

Step 5: Contract

Include security requirements, notification timelines, audit rights, data return and deletion.

Step 6: Monitor

Reassess high-tier vendors annually and monitor news and threat intelligence for incidents.

saas vendor security assessmentBlackbaud2020

More on this story