You are not going to audit three hundred suppliers. You are going to choose which ones.

Supplier questionnaires depend on who answers, arrive months later, and describe stated intent. Public signals depend on no one's cooperation, arrive in the same window for the whole portfolio, and describe what is exposed. Neither replaces the other — but only one of them can order the queue.

01The problem

Deciding where to spend limited deep-dive capacity — audit, detailed questionnaire, contractual clause — inside a supplier portfolio too large to treat in full.

What is at stake

  • Without a ranking criterion, the queue follows contract size, not the exposure it carries.
  • Questionnaires come back answered by the party with an interest in the answer.
  • Small suppliers with critical dependency go unnoticed because they lack commercial relevance.
  • Exposure arriving through the chain appears in no one's internal inventory.
02Evidence

Collection observes only what an external actor would also observe: no credentials, no installed agent, and no change to the supplier's environment. That is why it can be applied to an entire portfolio in the same window — none of those assessed needs to agree, be notified, or cooperate for the readout to exist.

Collection observes only what an external actor would also observe: no credentials, no installed agent, and no change to the supplier's environment. That is why it can be applied to an entire portfolio in the same window — none of those assessed needs to agree, be notified, or cooperate for the readout to exist.

Source
GWK public collection infrastructure
Date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies in the operational base
Coverage
Public layer only: DNS, TLS, PQC readiness, headers, infrastructure, and observable subdomains.

Limitation: A supplier's public surface neither proves nor disproves its internal posture. A high result indicates where to look, not what to conclude.

03What applies

The useful capability here is scale and uniformity: the same readout, applied identically across the whole portfolio, in the same window.

Unauthenticated collection

In production

Public signals for any domain, with no dependency on access or cooperation.

Public score per entity

In production

The same ruler applied to every supplier in the portfolio.

Grouping and comparison

In production

Ranking, grouping by band, and identification of outliers in the portfolio.

Continuous third-party management

On the roadmap

Recurring monitoring of the portfolio over time. Product direction, not contractable scope.

04What comes out

A ranked queue with a justification per position — which is what lets you defend why supplier number forty was not audited this cycle.

  • A public score for each supplier in the portfolio, in the same window.
  • Ranking by exposure, with the contributors behind each position.
  • Grouping by band, to handle the portfolio in blocks.
  • Comparison of each supplier against its own sector cohort.
  • A prioritized list of who deserves a deeper look, and why.
  • Coverage per supplier: where the readout was blind.

What it depends on

  • A supplier list with the corresponding domains.
  • Authorization or a legal basis to assess third-party domains — collection is external, but the decision to assess is yours.
  • An internal criticality criterion, to cross exposure with contract importance.
05What a third party's surface tells you

This is the most important limit on this page, and the easiest to forget when a result is high: an external readout prioritizes investigation, it does not produce a conclusion about the supplier.

Observed

Public collection saw

  • Cryptographic configuration exposed by the supplier.
  • Surface of reachable domains and services.
  • Announced post-quantum readiness signals.

Calculated

The IEQ engine derived

  • Structural exposure per supplier, on the same scale.
  • Each supplier's position within the portfolio and the sector.

Inferred

The model estimated

  • The supplier's sector, when not declared.
  • Shelf-life prior applicable to the kind of data it processes.

Out of scope

Other evidence decides

  • The supplier's internal security posture.
  • Whether a migration program is under way inside or not.
  • That the supplier poses contractual risk or should be replaced.
  • Any conclusion about data it processes that is not exposed.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • A deep-dive queue ordered by observable exposure.
  • A justification per position, with contributors and coverage.
  • A uniform readout of the entire portfolio, in the same window.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Start from a real portfolio

Bring the supplier list and the criticality criterion you already use. The exposure readout enters as a second dimension of the queue, not as a replacement for the first.