
Third-Party Cyber Risk Management (TPCRM)
Panorays
Know Which Suppliers Can Hurt You — and Fix It Before They Do
- Built-in DORA Register of Information with regulator-mapped templates and a submission-ready export
- Leader in The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026 and Q2 2024
Continuous Third Party Risk Management
Panorays mapping a supplier base end to end — rating each third party's cyber posture from the outside, sending the security questionnaires, and tracking remediation as a rating changes.
Overview
Panorays is a third-party cyber risk management (TPCRM) platform that tells an organisation which of its suppliers put it at risk, and what to do about it. It combines three inputs into one rating per supplier: a non-intrusive assessment of the supplier's external attack surface, AI-assisted security questionnaires whose answers are validated against that scan, and the business context of the relationship — how critical the supplier is and what data and access it has. The result, Risk DNA™, follows each supplier continuously and extends to fourth and Nth parties. Founded in 2016 and headquartered in New York and Tel Aviv, Panorays is ISO/IEC 42001, ISO/IEC 27001 and SOC 2 Type II certified, and was named a Leader in The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026. CRS partners deliver it as a managed service tiered by supplier criticality, so continuous monitoring goes where the risk actually is.
Who It's For
Key Differentiators
- One rating per supplier from three inputs — external attack-surface scan, validated security questionnaire, and business context — instead of separate ratings and questionnaire tools
- Risk DNA™ — each supplier's rating reflects your own risk appetite, the supplier's criticality and the data it holds, not a generic letter grade
- Non-intrusive by design — public data only, no agents, no pen testing, no supplier consent needed to get a cyber posture rating
- Hundreds of tests across three layers, including a Human layer (employee attack surface, security team, responsiveness) that most ratings tools leave out
- Answers are verified, not just collected — questionnaire responses are cross-checked against live scan data and uploaded certifications
- AI that does the paperwork — Smart Match and AI Answer Advisor pre-fill SIG, CAIQ, DORA and custom questionnaires from existing evidence
- Nth-party discovery maps your suppliers' suppliers and Shadow IT, so a zero-day in a fourth party doesn't catch you blind
- Risk Insights & Response Portal shows which suppliers are exposed to a new breach, KEV or zero-day and sends incident questionnaires in bulk
- Cyber Risk Quantification (Open FAIR™) expresses each supplier's exposure as an annualised loss — built for board conversations
- Built-in DORA Register of Information with regulator-mapped templates and a submission-ready export
- Suppliers join free, collaborate in-platform and can dispute findings — Panorays validates disputes within 24 hours
- Leader in The Forrester Wave™: Cybersecurity Risk Ratings Platforms, Q2 2026 and Q2 2024
Competitive Positioning
vs. Bitsight
- ›Panorays delivers the scan and the security assessment from one engine — Bitsight's questionnaire capability came by acquisition and typically runs as a separate workflow
- ›Panorays scores each supplier in the context of your relationship (criticality, data, access) — a stand-alone rating can't tell you which suppliers matter today
- ›Panorays received the highest possible score for Vendor Discovery and Mapping in The Forrester Wave™ Q2 2024
- ›Every Panorays finding is visible and disputable, with disputes validated within 24 hours
vs. SecurityScorecard
- ›Panorays combines ratings, questionnaires and business context natively — SecurityScorecard's questionnaire side came through an acquisition
- ›Panorays runs TPCRM as a process (tiering, assessment, remediation, re-evaluation), not just an outside-in score
- ›Panorays' AI is self-hosted and the platform is ISO/IEC 42001 certified for AI governance
- ›Human-layer testing plus dark-web mentions and compromised credentials in the supplier view
vs. UpGuard
- ›Panorays aggregates scan and questionnaire findings into one bottom-line cyber risk rating per supplier — UpGuard sells vendor risk and attack-surface modules separately
- ›Panorays inspects cloud assets in depth and includes a human-factor layer in its posture rating
- ›Panorays integrates natively with GRC, ITSM and procurement platforms rather than relying on a connector service for many of them
- ›Formal, fast dispute process — findings validated within 24 hours
vs. OneTrust / GRC platforms (ServiceNow VRM, Archer, Diligent)
- ›GRC tools manage the paperwork; Panorays supplies the cyber evidence — a native external attack-surface assessment that GRC platforms only get through integrations
- ›Continuously updated supplier ratings instead of static risk scores set at onboarding
- ›Purpose-built TPCRM that works in days — no heavy configuration or customisation that breaks with each platform update
- ›Position Panorays as the cyber layer feeding the customer's existing GRC workflow, not a replacement for it
vs. Spreadsheets and annual questionnaires
- ›A spreadsheet is out of date the day it's saved — Panorays monitors suppliers continuously and alerts when a rating drops
- ›Questionnaire answers are verified against live scan data and certifications instead of taken on trust
- ›Fourth- and Nth-party visibility that manual programmes can't provide
- ›Panorays customers report large time savings — Taylor Rose cut assessments from 8+ hours to under 2 hours per supplier
Full partner battle cards and objection-handling guides available in the partner portal.
Partner Use Cases
Launching a Managed Third-Party Risk Service
An MSSP partner packages Panorays as a managed TPCRM service for mid-market financial services clients. The partner's analysts tier each client's suppliers by criticality, send and chase the security questionnaires, and deliver a monthly supplier-risk report plus a board summary — work the client has no headcount to do in-house. The client gets a running programme in weeks rather than hiring for it, and the partner adds a recurring service line that grows with every supplier the client onboards.
Replacing a Spreadsheet Supplier-Assessment Process
A reseller's enterprise customer assesses its suppliers with a spreadsheet questionnaire once a year and has no way of checking the answers. The partner runs a Panorays proof of concept on five critical suppliers: each gets a cyber posture rating within hours from nothing more than a company name and domain, and questionnaire answers are cross-checked against the scan. The customer sees which suppliers actually need attention — and that the spreadsheet had marked two of them as low risk.
Adding the Cyber Layer to an Existing GRC Platform
A customer already runs vendor management in ServiceNow, Archer or OneTrust, but the supplier records carry no live cyber data. The partner connects Panorays so every supplier record is enriched with a continuously updated cyber risk rating, alerts flow into the existing workflow when a rating drops, and remediation plans are sent from one place — without replacing the GRC investment.
Responding to a Zero-Day Across the Supply Chain
When a widely exploited vulnerability hits the news, a partner's client needs to know within hours which suppliers — and which of their suppliers — are exposed. Using the Panorays Risk Insights & Response Portal, the partner identifies affected direct and fourth-party suppliers, bulk-sends an incident questionnaire, and tracks responses to closure, turning a week of phone calls into a same-day response.
Want to walk through one of these scenarios against your own environment? Request a demo or speak to a CRS specialist.
Webinars & Articles
Go deeper on Panorays with sessions and write-ups from the CRS team.
Frequently Asked Questions
What is Panorays?
Panorays is a third-party cyber risk management (TPCRM) platform. It rates each of an organisation's suppliers by combining three inputs: a non-intrusive assessment of the supplier's external attack surface, an AI-assisted security questionnaire whose answers are validated against that assessment, and the business context of the relationship — how critical the supplier is and what data and access it has. Panorays calls the result Risk DNA™. CRS distributes Panorays across Africa through its partner network.
Is the Panorays assessment intrusive? Do suppliers need to agree to it?
No. The cyber posture rating is built from hundreds of non-intrusive tests using publicly available information — there are no agents, no penetration testing and no exploitation, so no supplier consent is needed. All that is required to rate a supplier is its name and domain. Suppliers can see their findings, collaborate in the platform free of charge, and dispute any finding; Panorays says disputes are validated within 24 hours.
How accurate is the Panorays rating?
Panorays reports 99.4% rating accuracy with a 0.6% false-positive rate in its published Cyber Posture Rating methodology. Every test and finding is visible, so a supplier or customer can see exactly why a score is what it is. The overall cyber posture rating is calculated directly from the individual test results, and is combined with questionnaire answers and business context to produce a supplier's cyber risk rating.
Does Panorays help with DORA, NIS2 and other regulations?
Yes. Panorays includes a DORA Register of Information capability with regulator-mapped templates and a submission-ready export, and supports questionnaires aligned to frameworks such as NIST CSF, ISO 27001, SOC 2, DORA and NIS2. In CRS's view it is equally relevant to South African organisations with third-party obligations under POPIA and the Prudential Authority and FSCA Joint Standards on IT governance and cybersecurity — customers should confirm their specific obligations with their compliance advisers.
How is Panorays packaged?
Panorays mixes three evaluation types so effort follows risk: Inventory to centralise and track the long tail of low-risk suppliers, Assessment for periodic evaluation, and Monitoring for continuous oversight of critical suppliers. CRS partners typically deliver it as a managed service — tiering suppliers by criticality, running the questionnaires and reporting to the board — and scope each engagement to the customer's supplier base.
How do we get started with a Panorays proof of concept?
Request a demo through CRS. A Panorays proof of concept typically covers up to five of the customer's critical suppliers, which get a cyber posture rating as soon as their names and domains are loaded. Panorays is SaaS, so there is nothing to install. CRS partners can also book a session with the CRS Panorays lead and complete the Panorays Sales and Technical Sales certifications in CRS University.
Partner Intelligence Available
Detailed battle cards, partner collateral, certification courses, and full sales enablement content for Panorays are available exclusively to authorized CRS partners.
Your Panorays lead
Drystan GovenderChief Technology Officer
Best for: CISOs and enterprise teams evaluating multi-vendor strategies and high-value, complex security investments.
Book a meeting with Drystan
Opens Drystan's calendar in a new tab.
Request a DemoBecome a CRS Partner
Get exclusive sales tools, and enablement resources for Panorays.
Apply for Access Partner Sign InBuild the Skills
Equip your team to deploy and manage Panorayswith CRS authorized IBM, Red Hat, SUSE & CompTIA technical training.
Explore CRS technical trainingVendor Website
panorays.comRequest a Demo of Panorays
Tell us what you need and when works for you — a member of the CRS team will confirm your session directly.
More in Risk & Compliance
Products CRS partners commonly position alongside Panorays.







