How often does procurement include cyber risk assessment requirements in their engagement requests?
Always25%
Often36%
Sometimes24%
Rarely12%
Never1%
Not sure
426 PARTICIPANTS
Always25%
Often36%
Sometimes24%
Rarely12%
Never1%
Not sure
Much more difficult2%
Somewhat more difficult42%
Slightly more difficult22%
No difference17%
Slightly less difficult13%
Somewhat less difficult1%
Much less difficult
Unsure
Strongly agree18%
Agree66%
Neutral11%
Disagree3%
Strongly disagree
No selling.
No recruiting.
No self promotion.
Rules of EngagementFAQsPrivacy
© 2025 Gartner, Inc. and/or its affiliates. All rights reserved.
It depends on the size of the business. In my experience, most of the publicly listed companies' procurement team will have this requirement as part of due diligence of vendor onboarding process.
For private companies, it depends on the size and agility of the business that matters the most.
Another driver for this requirement comes from regulatory compliance side and that too depends on which sector the company is operating.