Third-party risk tools in SOC 2 platforms: what each vendor now lists

Short answer

Third-party risk management is now listed by six of the eight platforms: Scytale (AI Third-Party Risk Management, launched 15 September 2026), Vanta (a TPRM agent), Drata (a new TPRM product and Agentic TPRM Assessment), Sprinto (Autonomous TPRM), Secureframe (advanced TPRM on Complete) and Scrut (a Vendor Risk Analyst Teammate). It is not described on the Thoropass or Comp AI pages we read.

Tags: TPRM, News · 3 min read

Vendor risk has moved from a spreadsheet next to the compliance platform to a product inside it. For a team switching platforms, that matters in two ways: you may gain a TPRM tool you did not have, and you may need to move vendor assessments you already keep. This post lists what each platform describes, from pages read on 21 September 2026, and covers one dated announcement from September 2026.

What changed in September 2026?

Scytale's news list shows an AI Third-Party Risk Management launch dated 15 September 2026. We report the launch date and name from its news list; the product page itself was not in our source set.

Source: Scytale security page and news list · read 2026-09-21

What does each platform list for vendor risk?

Why does this matter for a switch?

Vendor assessments are evidence too. SOC 2 and ISO 27001 both expect you to manage the risks from suppliers, and auditors will ask for your vendor list, your assessments and your reviews. If your current platform holds them, export them with the rest of your evidence. If they live in a spreadsheet today, a switch is a natural time to move them into a tool.

Which plan includes it?

This varies, and most vendors do not publish it in detail. Drata places Agentic TPRM Assessment on GRC Enterprise. Secureframe places advanced TPRM on Complete. Sprinto lists vendor risk on Foundation. Vanta, Scytale and Scrut do not tie their TPRM features to a named plan on the pages we read; ask which plan includes them.

What should you ask?

  • Can we import our existing vendor list and past assessments?
  • Who sends and chases vendor questionnaires: the tool, your team or ours?
  • Which plan includes TPRM, and is there a limit on vendors assessed?

How do you move existing vendor assessments?

Treat them like any other evidence. Export the vendor list with owners, risk ratings and review dates, and the completed assessments with the date each was finished. Import the list into the new tool, attach the past assessments as records, and set the next review dates from the original ones rather than from the import day. That keeps the review cycle your auditor has already seen.

TPRM is not one of our seven scored criteria, so it does not change the rankings. It is worth a line in your shortlist if you manage many suppliers.

Who owns vendor risk after the switch?

Name one owner for the vendor list and the review calendar before changeover day. Vendor reviews tend to be the first task dropped during a platform move, because they sit between security, procurement and legal. A named owner and a date for the first review in the new tool keep the cycle unbroken.