Key takeaways
Collect five things from every vendor on your shortlist, in writing, before you compare features. First, the information security certification with its certificate number, issuing body and scope statement, so you can confirm the platform itself is in scope and not just a corporate office. Second, a signed or signable data processing agreement naming every sub-processor. Third, the hosting region, stated as an actual cloud region rather than a continent. Fourth, the recovery objectives in hours: recovery time objective and recovery point objective, plus backup frequency. Fifth, the access control model: role based permissions, single sign-on support, and whether an audit log records who changed what.
Fabrico answers those five as follows: ISO 27001, ISO 9001 and ISO/IEC 20000-1 certification, a GDPR data processing agreement, hosting in an AWS EU region, a 4 hour recovery time objective and 4 hour recovery point objective with daily backups, and role based access control with SSO and SAML available plus a full audit log. Encryption is applied at rest and in transit, and the platform sits behind Cloudflare DDoS protection.
Most manufacturers use a standard supplier questionnaire that was written for enterprise IT, then hand it to a plant team that has never filled one in. The six areas below are what those forms are really testing, translated into plant language.
1. Certification and scope. The reviewer wants an independent third party to have audited the vendor's security management system. In Europe that is normally ISO/IEC 27001. In North America a SOC 2 Type II report is more common. The two are not equivalent and neither is a substitute for the other, so ask which one a given vendor holds rather than assuming. Crucially, ask for the scope statement. A certificate can legitimately cover a company's development office while excluding a hosted service.
2. Data residency. Your machine data, work orders and employee names are personal and commercial data. The reviewer needs to know which legal jurisdiction physically holds them. "The cloud" and "Europe" are not answers. An AWS, Azure or Google Cloud region name is an answer. If you operate in the EU, this is also the question your data protection officer will ask first, and it is covered in more depth in our GDPR and data protection buyer guide for OEE and CMMS software.
3. Sub-processors. Every SaaS platform uses other vendors: a cloud host, an email service, an error monitoring tool, sometimes an AI provider. Each one is a place your data goes. A vendor that cannot produce a sub-processor list has not thought about this, and you cannot complete your own compliance record without it.
4. Availability and recovery. Two different numbers, routinely confused. Recovery time objective is how long the service can be down before it must be restored. Recovery point objective is how much data you can lose, measured in time. A vendor quoting 99.9 percent uptime has told you nothing about either. Ask for both in hours, and ask how often backups run.
5. Access control and audit. On a shop floor, dozens of people touch the same system, and some of them share a tablet. The reviewer wants role based access control so a technician cannot delete a plant, single sign-on so leavers lose access when HR disables the account, and an audit log so a disputed maintenance record can be traced to a person and a timestamp.
6. Integration surface. Every connection you add is a door. If the platform will sync with SAP PM, an ERP, or a historian, the reviewer wants to know how that connection authenticates and what it can reach. Read-only integrations pass review far faster than bidirectional ones, so know which you actually need before the meeting.
Send these verbatim, to every vendor at once, and ask for written answers. Answers that arrive as a call invitation instead of a document are themselves a data point.
Question 12 is the one buyers forget and the one procurement will insist on. Ask it early, because an unsatisfactory answer is much cheaper to discover in week one than in year three.
"We are ISO 27001 aligned." Aligned is not certified. It means no external auditor has ever tested the claim. Ask for the certificate or treat the vendor as uncertified.
"We cannot share our sub-processor list." Under GDPR your organisation is the controller and remains accountable for where the data goes. A vendor unwilling to name its sub-processors is asking you to accept a liability you cannot quantify.
"We will get you those numbers later." Recovery objectives either exist as tested figures or they do not exist. A vendor that has run a restore test knows its numbers immediately.
Fabrico is a combined CMMS and OEE platform built and hosted in the EU. On the five review items above, the answers are: ISO 27001, ISO 9001 and ISO/IEC 20000-1 certified; a GDPR data processing agreement available; hosting in an AWS EU region; a 4 hour recovery time objective and 4 hour recovery point objective with daily backups; and role based access control with SSO and SAML available for custom configurations, plus an audit log. Encryption covers data at rest and in transit, and Cloudflare provides DDoS protection.
On the operational side, the contractual support response is under 2 hours, and the interface ships in English, Bulgarian, German, French and Polish, which matters when a security review is followed by a works council conversation about who can read what. Integration is available through a REST API, webhooks, Excel import and export, and a bidirectional SAP PM sync including S/4HANA.
Two things Fabrico does not claim, because being straight about them saves everyone a round of clarification: there is no SOC 2 report, and there is no offline mode. If your reviewer's form requires SOC 2 specifically, say so at the start of the evaluation rather than at the end.
Take a supplier running three plants, evaluating a combined CMMS and OEE platform, with a corporate InfoSec form of roughly 40 questions and a data protection officer who must sign off separately.
Run sequentially, the usual shape is six weeks of functional demos, then the security pack goes out, then two to four weeks of back and forth per vendor, then legal review of the data processing agreement. Total elapsed time before a contract can be signed is commonly three to four months, and the plant team spends most of it waiting.
Run in parallel, the 12 questions above go out in week one, alongside the first demo invitations. By the time the functional shortlist is down to two vendors in week four, both security packs are already with InfoSec and the data processing agreement is with legal. The same three to four months compresses to roughly six to eight weeks, and, more importantly, you never discover in month three that your preferred vendor fails a mandatory control.
The cost of the parallel approach is one extra email in week one. The cost of the sequential approach is a rollout that starts a quarter late, which on a plant chasing an availability problem is a quarter of losses you had already agreed to stop.
A security review tests whether a vendor can be trusted with your data. It does not test whether the platform will be used. Those are separate failures with separate causes, and both have to be cleared. If your IT function is small or shared across sites, our guide to choosing OEE and CMMS software without a dedicated IT department covers who actually carries the review work. If your plants sit in Germany, Austria, the Netherlands or France, the works council approval guide for OEE monitoring covers the parallel approval that catches most teams by surprise. For the functional requirements themselves, start from the CMMS software RFP template, and for the metric definitions the platform has to produce, see the OEE for manufacturing guide.
If you want the Fabrico security pack, including the certificate scope statements and the data processing agreement, book a demo and ask for it by name. It is sent as documents, not as a slide.
Neither is better, they answer different questions. ISO 27001 certifies that a management system for information security exists and is audited against a standard. SOC 2 Type II is an attestation report describing how specific controls operated over a period, and it is read as a document rather than checked as a badge. European buyers usually require ISO 27001, North American buyers usually require SOC 2. Ask which one your reviewer's form actually requires before you shortlist, because it can eliminate vendors.
For a CMMS or OEE platform, a recovery time objective and recovery point objective in the range of a few hours is normal, and daily backups are standard. What matters more than the specific figure is that the vendor states it as a number and has tested a restore. Judge the answer by whether it is precise, not by whether it is impressive.
Almost certainly yes. A CMMS holds work orders assigned to named technicians, timestamps of who did what, and often shift patterns. That is personal data under GDPR regardless of how much machine data sits beside it. Assume you need a data processing agreement and confirm the scope with your data protection officer.
Maintenance should send it and IT should score it. The maintenance team knows which integrations are genuinely needed, which is what determines the risk surface, and IT knows which answers are acceptable. When IT owns the whole process the questionnaire often demands controls the plant does not need, and when maintenance owns the whole process the answers get accepted without being checked.
A vendor that has been through enterprise reviews before will return written answers within a few working days, because the documents already exist. Weeks of delay usually means the pack is being written for the first time. That is not automatically disqualifying for a young vendor, but it tells you what to expect from support later.
Last updated: 7 August 2026.