Vendor assessment against 27018 is mostly a discipline of refusing summaries. The trust page says certified; the certificate says which entity, which services, which controls. The certificate says 27018; the SoA says whether the annex was adopted. The SoA says instructions-only and no advertising use; the DPA says whether any of it binds. Each layer is one request away, and vendors with real programs produce them without friction, which makes the assessment process itself a screening mechanism. Under Article 28 the diligence is not optional courtesy; choosing the processor is your regulated act, and the file you build here is your defense when their incident becomes your inquiry.
| Verify | Certificate scope names 27018 + your services; CB accredited |
|---|---|
| Test | Six annex commitments against DPA + product docs |
| Probe | Subprocessor list, change notices, deletion windows, breach SLA |
| Legal driver | GDPR Art. 28 ‘sufficient guarantees’ is the controller’s duty |
| Red flags | Contract-trust divergence, scope evasion, deletion vagueness |
| Standard | ISO/IEC 27018 |
Running the assessment
Chase paper, not badges. Certificate, scope, SoA excerpt, DPA; the provider-side view shows what a real program produces.
Make the DPA mirror the annex. Verified commitments become exhibits; gaps become redlines or compensating controls.
File the diligence. Assessment records in the vendor register are your Article 28 defense.
Slot other artifacts into one checklist. 27701 certificates and SOC 2 reports are evidence for the same six commitments, not separate tracks.
Vendor flows are half the picture: see what your own site sends to third parties with a free scan.