A cloud backup vendor due diligence checklist should confirm what data the provider will hold, how it is encrypted and isolated, whether backups can be restored after ransomware, what independent security evidence exists, and what the contract requires if the service changes or suffers an incident. For a small business, the goal is not to conduct a full enterprise audit; it is to make a documented, risk-based decision and revisit it regularly. This supports ISO 27001 control 5.22, which requires organizations to monitor, review, evaluate, and manage changes in supplier information security practices and service delivery.
How should you assign vendor risk tiers?
Not every supplier deserves the same level of review. A free file-sharing tool used by one employee is not equivalent to the backup provider holding copies of your accounting records, customer data, and employee files. Assigning a tier lets an SMB spend its limited time on the vendors that could cause the most harm.
| Tier | When it applies | Cloud backup example | Review frequency |
|---|---|---|---|
| Tier 1: Critical | The vendor stores sensitive, regulated, financial, or business-essential data, and an outage or failed restore could stop operations. | A managed backup provider protecting Microsoft 365, servers, customer databases, and financial records. | Before contract signature, annually, and after material changes. |
| Tier 2: Important | The vendor stores internal business data or supports a useful service, but failure would be disruptive rather than existential. | A cloud storage provider used for departmental project archives. | Before use and every two years, or after a material change. |
| Tier 3: Low | The vendor has no access to sensitive data and does not affect critical operations. | A vendor providing public documentation or non-sensitive software training. | Basic approval and renewal review. |
Most cloud backup providers will be Tier 1 because backup systems commonly contain the same sensitive information as production systems. They also become a ransomware target: an attacker who can delete backup copies can turn a manageable incident into a business-stopping event.
What belongs on a cloud backup vendor due diligence checklist?
Use the questions below according to the vendor’s tier. For a Tier 1 provider, require written answers and evidence for every applicable item. For Tier 2, focus on the items marked essential. For Tier 3, document why the vendor does not handle sensitive or critical data.
| Review area | Tier 1 checklist | Tier 2 checklist | What a practical answer looks like |
|---|---|---|---|
| Data scope and location | Identify every data type, data owner, storage country, retention period, and subcontractor location. | Confirm data types and primary hosting region. | “Microsoft 365 backups are stored in AWS eu-west-1; no production data is stored outside the EU without written approval.” |
| Encryption and key management | Confirm encryption in transit and at rest, key-management responsibility, and separation between customer tenants. | Confirm encryption in transit and at rest. | TLS 1.2 or higher in transit; AES-256 at rest; keys managed through AWS KMS, Azure Key Vault, or an equivalent managed key service. |
| Identity and administrator access | Require MFA, role-based access control, named administrator accounts, audit logs, and prompt removal of departing staff. | Require MFA for customer administrators and role-based permissions. | Microsoft Entra ID SSO with MFA; separate backup administrator role; no shared admin accounts; audit logs retained for at least 12 months. |
| Ransomware resilience | Confirm immutable backups, deletion protection, separate credentials, restore testing, and recovery time commitments. | Confirm retained versions and documented restore steps. | AWS S3 Object Lock in Compliance mode or Azure immutable blob storage; 30-day minimum immutable retention; deletion requires a separate privileged role. |
| Backup and restoration | Review backup frequency, retention, recovery point objective, recovery time objective, and test results. | Confirm backup frequency and retention. | Daily backup for endpoints, four-hour backup for critical servers, 90-day operational retention, and quarterly restore tests of representative files and systems. |
| Incident response | Review incident process, notification time, customer contacts, forensic support, and evidence preservation. | Confirm the vendor has an incident process and customer notification commitment. | Security incidents affecting your data are reported within 24 hours of confirmation, with updates at least every 24 hours until containment. |
| Service availability | Review SLA, support hours, service-status history, disaster recovery plan, and escalation path. | Review SLA and support contact method. | 99.9% monthly service availability; 24/7 support for Severity 1 restoration failures; documented escalation to a named account contact. |
| Subprocessors | Obtain the current subprocessor list, countries, services provided, and change-notice process. | Confirm whether subprocessors are used. | Provider publishes subprocessors and gives 30 days’ notice before adding a new one that will process customer backup data. |
| Exit and deletion | Confirm export formats, migration support, data-return time, deletion certification, and fees. | Confirm you can retrieve your data before termination. | Backups can be exported in standard formats; data is available for 30 days after termination; secure deletion certificate is provided on request. |
A useful backup vendor review checklist also asks one operational question that sales documentation may not answer: who in your company can perform a restore? Keep at least two authorized people, use MFA on their accounts, and make sure they know where recovery instructions and vendor support details are stored.
Which security artifacts should you request?
Artifacts turn vendor promises into reviewable evidence. A Tier 1 provider should be able to provide current documents under a nondisclosure agreement if necessary. A lack of a particular certification does not automatically disqualify a smaller provider, but it should increase the questions you ask and may affect its risk tier.
- SOC 2 Type II report: Request the complete report, not only a marketing bridge letter. Check the reporting period, auditor opinion, exceptions, services covered, and whether security, availability, and confidentiality criteria are included.
- ISO 27001 certificate: Confirm the certificate is current, issued by an accredited certification body, and covers the actual backup service and relevant hosting operations rather than only a parent company.
- Penetration-test summary: Request a recent independent test summary, ideally completed within the past 12 months. Ask whether critical and high findings were remediated and retested.
- Security questionnaire: Obtain answers covering MFA, encryption, logging, vulnerability management, incident response, employee screening, and secure development practices.
- Business continuity and disaster recovery evidence: Ask for a summary of disaster recovery testing, restoration test results, recovery objectives, and the most recent test date.
- Privacy and data-processing documents: Obtain the data processing agreement, privacy notice, list of subprocessors, and cross-border transfer terms where relevant.
- Cyber insurance confirmation: For a critical provider, ask whether the vendor maintains cyber liability coverage appropriate to the data and service involved.
Record the artifact date, reviewer, key findings, and decision in a simple supplier register. For example, a spreadsheet can track the vendor name, tier, contract renewal date, SOC 2 period, next review date, open issues, and the business owner responsible for follow-up.
How should you perform an annual vendor reassessment?
ISO 27001 control 5.22 is ongoing, not a one-time procurement task. Your annual cloud backup due-diligence review should be short, scheduled, and tied to contract renewal so that you can negotiate improvements before renewal rather than after an incident.
- Start 60 to 90 days before renewal. Assign a business owner, usually the person responsible for operations, finance, or technology, even if they are not a security specialist.
- Confirm the service has not expanded. Ask whether new systems, data types, integrations, administrators, or regions have been added since the previous review.
- Collect updated evidence. Request the newest SOC 2 report, ISO certificate, penetration-test summary, subprocessor list, and policy updates.
- Review service performance. Check outages, support tickets, missed backup jobs, restore-test results, and any incidents involving your account.
- Ask about material changes. Changes in ownership, hosting provider, backup architecture, encryption approach, data location, or subcontractors can change your risk decision.
- Record exceptions and actions. If the vendor cannot meet a requirement, document the risk, compensating control, owner, and deadline. For example, you may reduce risk by keeping a separate immutable copy with another provider.
- Approve, conditionally approve, or replace. Keep the decision with the evidence. Conditional approval should include a dated remediation commitment.
Do not wait for the annual date if a trigger occurs. Reassess after a security incident, a significant outage, a merger or acquisition, a major contract change, a new subprocessor, or a decision to back up a new category of sensitive data.
What contractual flow-down clauses protect your business?
Your due-diligence findings should appear in the contract, order form, data processing agreement, or security addendum. A contract cannot prevent a breach, but it can require the vendor to maintain the controls that influenced your decision and give you a remedy if it does not.
| Contract clause | What to require |
|---|---|
| Security controls | Require reasonable administrative, technical, and physical safeguards, including encryption, MFA for privileged access, logging, and vulnerability management. |
| Incident notification | Require notification within a defined period, such as 24 hours after confirmed unauthorized access to your data, plus ongoing status updates and cooperation. |
| Subprocessor flow-down | Require the vendor to impose equivalent security, confidentiality, and data-protection obligations on subcontractors that process your backup data. |
| Change notification | Require advance notice of material changes to hosting locations, subprocessors, security controls, or service architecture, with a right to object or terminate where appropriate. |
| Audit and evidence rights | Require annual access to relevant SOC 2, ISO 27001, penetration-test, and compliance evidence, rather than relying on unrestricted onsite audit rights that small vendors may reject. |
| Data return and deletion | Require usable data export on termination, a clear retention window, secure deletion after the window closes, and deletion confirmation on request. | Recovery commitments | Document backup frequency, retention, restoration support, and any agreed recovery time and recovery point objectives. | </tr>
Start by tiering your current backup provider, request its most recent security evidence, and schedule a 30-minute review before your next renewal date.