Home > Glossary > CCSP > Due Diligence

📖 What is Due Diligence?

Due Diligence is the process of investigating and verifying a cloud service provider's security claims, financial stability, and operational capabilities before entering into a contract. It involves reviewing audit reports, certifications, and SLAs to ensure the provider meets the organization's risk appetite.

🥋 Sensei Says:

"Think of this as the 'homework' you do before signing the contract. It is the research and verification phase of vendor management."

📚 Certification: CCSP (CCSP)

🔑 What are the Key Concepts of Due Diligence?

  • Verification of third-party audit reports, such as SOC 2 Type II or ISO 27001, to validate the CSP's security claims independently.
  • Analysis of Service Level Agreements (SLAs) to ensure the provider's uptime and performance guarantees align with business requirements.
  • Evaluation of the provider's financial stability to mitigate the risk of service discontinuation or bankruptcy affecting business continuity.
  • Review of the CSP's shared responsibility model to clearly define which security controls the provider manages versus the customer.
  • Assessment of the provider's compliance with industry-specific regulations, such as HIPAA or GDPR, based on the data being migrated.

🎯 How does Due Diligence appear on the CCSP Exam?

You may be asked to identify the correct phase of vendor management when an organization reviews a CSP's audit reports before signing a contract.

A scenario might describe a company selecting a cloud provider for sensitive data; expect to choose 'due diligence' as the process for verifying security controls.

Expect questions that require you to distinguish between the research phase (due diligence) and the ongoing implementation of security controls (due care).

❓ Frequently Asked Questions

How does due diligence differ from due care in a cloud context?

Due diligence is the research and verification performed before an action, such as signing a contract. Due care is the actual implementation of security controls and the ongoing effort to protect the environment.


Which documents are most critical during the due diligence process?

SOC 2 Type II reports are highly valued because they provide evidence of control effectiveness over a period of time, unlike Type I reports which only show a point-in-time snapshot.


Is due diligence only performed once during the initial procurement phase?

No, it should be a recurring process. Organizations must periodically re-evaluate their CSPs to ensure security postures have not degraded and that regulatory compliance is consistently maintained.

Related Terms from CCSP

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Due Diligence? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium