- Most security vendor evaluations test for credentials and price, not for whether the work actually holds up.
- Ask for evidence: written findings from past engagements, named practitioner qualifications, and a documented methodology, not marketing language.
- Independent third-party validation exists precisely because a vendor’s own assurances are not evidence.
Procurement teams are good at evaluating vendors whose work produces a measurable output. You can inspect a delivered product. You can audit a software implementation. You can check a financial deliverable against a specification.
Physical security is harder to evaluate, because the deliverable is the absence of an incident. A program can look thorough and still leave the gaps that matter open. A vendor can be confident, credentialed, and wrong. The evaluation process most organizations use was built for vendors whose quality is visible, and it does not protect you here.
The problem with evaluating security vendors
A typical security vendor evaluation checks three things: does the vendor hold the right certifications, does the vendor have relevant experience, and is the price competitive. All three are reasonable. None of them tells you whether the work is good.
Certifications confirm that a vendor met a standard at a point in time. Experience confirms that a vendor has done similar work, not that the work was effective. Price tells you what you will pay, not what you will get. An organization can satisfy all three criteria and still hire a vendor whose assessments are checklists and whose findings never get tested against reality.
What documentation should actually prove
Ask a prospective vendor to show you the documentation from a past engagement, with the client details redacted. What you are looking for is specific:
- Written findings that name the actual gap, not a category. "Propped service door on the east loading dock, observed open for 40 minutes during the assessment" tells you something. "Access control deficiencies" does not.
- Severity and exposure ratings that explain how each finding was prioritized, not a flat list.
- A remediation path tied to each finding, with enough detail that someone could act on it.
- Evidence the vendor returned to confirm the fix, or a clear statement that verification was out of scope.
A vendor that produces this kind of documentation routinely will have it ready. A vendor that cannot produce it is asking you to take its competence on faith.
Questions that separate practitioners from packagers
Two questions tend to reveal the difference quickly. First: who specifically will do the work, and what is their background? Some firms sell on the strength of a senior name and staff the engagement with junior personnel. You want the qualifications of the person who will actually walk your site.
Second: what is your methodology, and what happens when you find something serious mid-assessment? A practitioner has a clear answer. A packager describes a process that sounds rigorous but never quite explains how a finding becomes a fix.
A vendor that cannot show you its written findings from past work is asking you to take its competence on faith.
Why independent validation matters
The reason third-party validation exists is simple. A vendor assessing its own quality has an interest in the answer. An independent standard does not. When a security organization holds a credential that required verified remediation rather than a submitted plan, the credential is doing work that a sales conversation cannot.
This is the function of a certification like WorldSafe Certified. It is not a marketing badge. It is a way for a buyer to know that an independent practitioner assessed the organization, that critical findings were fixed, and that the fix was confirmed. For a procurement team, that is the difference between a claim and a record.
The audit trail you should expect
Whatever vendor you select, the engagement should leave a documented trail. Scope, findings, severity, remediation, and verification should all be written down and retained. This is not bureaucracy. It is the evidence you will need if a board member, a regulator, or an insurer asks what you did and why.
A vendor that resists documentation is telling you something. A vendor that produces it without being asked is telling you something too.
Sources and further reading
Vet your security partner against real criteria.
WorldSafe assessments produce written, scored findings with verified remediation, and the documented audit trail your risk review needs.
Book a consultation