← Back to blog
21 August 20268 min read

What is a supplier assessment? Definition, criteria and a complete example

Supplier assessments determine, in practice, who you keep doing business with — yet in many SMEs they still happen on gut feeling: a regular supplier who "always does fine," without anyone ever writing down objectively why. This article explains what a supplier assessment actually is, which criteria to use, and gives a concrete example — including a free, interactive scorecard you can fill in right now.

Whether you want to review a single critical supplier or set up a structured procurement process, the same basic principles apply.

What is a supplier assessment?

A supplier assessment is a structured, repeatable evaluation of a supplier against predefined criteria — as opposed to a one-off, informal impression. The goal is to compare a supplier objectively against alternatives, and to flag risks (quality, continuity, compliance) early rather than only once a problem has already occurred.

In practice, a supplier assessment happens at two points: when selecting a new supplier (upfront, to make an informed choice) and periodically for existing suppliers (after the fact, to check the relationship still meets requirements). Both typically use the same criteria — a new supplier just usually lacks historical performance data.

Supplier assessment or vendor evaluation: is there a difference?

In practice the terms overlap: supplier assessment, vendor evaluation, supplier evaluation, vendor assessment. They describe the same underlying process — structurally establishing how well a supplier performs against relevant criteria.

There is a slight nuance in usage: "assessment" tends to appear more for the ongoing, periodic review of an existing supplier, while "evaluation" appears slightly more often for the one-off selection of a new supplier. In practice that distinction isn't strict — most procurement teams use the terms interchangeably, and that's no problem for your process either: the same criteria and the same scorecard work for both moments.

Why is a supplier assessment necessary?

A structured assessment delivers a concrete advantage over a gut-feeling decision, for five reasons:

1. Quality assurance. You catch declining delivery quality early, before it reaches your own customers.

2. Risk spreading and continuity. A supplier going bankrupt or suddenly failing is an operational risk. An assessment surfaces dependency (single-source risk) before it becomes a problem.

3. Negotiating position. Objective scores give you a factual basis in price and contract discussions, instead of a vague "we're not entirely happy."

4. Compliance. More and more regulation requires buyers to assess their supply chain: the CSRD for scope 3 emissions, NIS2 Art. 21(2)(d) for the cybersecurity of critical suppliers, and the CSDDD / EU Forced Labour Regulation for human rights. A supplier assessment is, in that sense, no longer just a procurement tool but part of your own reporting obligation.

5. Procurement strategy. Aggregated across all your suppliers, an assessment shows where risk is concentrated — and where diversification would pay off.

Which criteria do you use in a supplier assessment?

A good supplier assessment combines commercial, operational and compliance criteria. These seven are the most commonly used in practice:

Quality & delivery — does the supplier meet specifications and agreed delivery times?

Price & terms — is pricing competitive and are commercial terms transparent?

Sustainability data — can the supplier demonstrate scope 1 and scope 2 emissions, for example via a VS profile?

Cybersecurity — are baseline measures such as access management and incident reporting in place (relevant under NIS2 Art. 21)?

Financial stability — is there sufficient visibility into this supplier's continuity risk?

Compliance & certifications — are relevant certifications (ISO, industry-specific) present and valid?

Dependency & continuity — how large is the risk if this supplier fails (single-source)?

Not every criterion carries the same weight for every supplier: for a critical, hard-to-replace supplier, continuity matters more; for a supplier of commodity products with many alternatives, price dominates.

Example of a supplier assessment: the scorecard

A supplier assessment is easiest to understand through a concrete example. Say you're comparing two packaging suppliers. Supplier A always delivers on time, has a VS profile with scope 1+2 data, but is 8% more expensive. Supplier B is cheaper, but failed to deliver on time twice last year and has no sustainability data available.

Against the seven criteria above, Supplier A scores higher on quality, sustainability and likely compliance, and lower on price. By giving each criterion a score from 1 to 5 and averaging, you get a percentage that makes the two suppliers directly comparable — instead of a vague impression.

Want to try this yourself right now? Use our free, interactive supplier assessment scorecard — score the seven criteria and see the result instantly, no registration required.

How often do you carry out a supplier assessment?

For a new supplier: always before the first contract, as part of selection. For existing suppliers: at least annually for critical suppliers (ones you're heavily dependent on, or that represent a large share of your purchasing volume), and additionally at every contract renewal or at any sign of declining quality.

For suppliers subject to a compliance obligation — CSRD scope 3, NIS2 Art. 21, or the CSDDD — annual reassessment is, in practice, mandatory: your own reporting requires current data, not a three-year-old snapshot.

Subject to the CSRD? Here is the deeper dive

This article covers supplier assessment in the broad sense. If you're specifically subject to the CSRD and need to collect supplier data for your scope 3 reporting — including exactly what data you may request within the VS (Voluntary Standard) value chain cap, and how to process it into your ESRS E1 disclosure — see our in-depth article on supplier assessment and collecting CSRD data from suppliers.

Do you also need a cybersecurity assessment of your critical suppliers alongside sustainability data — mandatory under NIS2 Art. 21(2)(d) for NIS2-obligated companies? See our NIS2 supply chain assessment step-by-step guide for the ten CY assessment areas.

verified.supply lets your suppliers fill in their own VS profile, cybersecurity assessment and compliance data — structured, traceable and directly comparable across suppliers. Sign up as an enterprise buyer via verified.supply.

Frequently asked questions

What is a supplier assessment?
A supplier assessment (also called a vendor evaluation) is a structured, repeatable evaluation of a supplier against predefined criteria such as quality, price, sustainability and compliance. The goal is to compare suppliers objectively and flag risks early, instead of deciding on gut feeling.
What is the difference between a supplier assessment and a vendor evaluation?
Nothing in substance — both terms describe the same process. "Assessment" is used slightly more for the periodic review of an existing supplier, "evaluation" slightly more for the one-off selection of a new one, but in practice they're used interchangeably.
What does an example of a supplier assessment look like?
An example: you score a supplier on seven criteria (quality, price, sustainability, cybersecurity, financial stability, compliance, dependency) from 1 to 5, and average the scores into a percentage. That makes a supplier who delivers on time but costs more directly comparable to a cheaper supplier with less reliable delivery. Use our free scorecard to try this yourself.
Which criteria do you use in a supplier assessment?
The seven most commonly used criteria are: quality and delivery, price and terms, sustainability data, cybersecurity, financial stability, compliance and certifications, and dependency/continuity. Not every criterion carries the same weight for every supplier.

Read also

Build your VS profile (formerly VSME) once

Create an account and get started today.

No password needed — we email you a login link.