Security Qualifications


Security Qualifications


At NRG, protecting our systems, data, and customers is a top priority. Suppliers providing technology, IT, or cybersecurity-related services may be required to meet security qualifications before engaging with NRG.

To streamline this process, NRG partners with Whistic, a trusted third-party platform for assessing supplier security practices. Through Whistic, suppliers can demonstrate compliance with cybersecurity standards, share documentation securely, and maintain qualifications required to work with sensitive systems or data.

Who needs security qualification?

Suppliers may need to meet security qualifications if they:

  • Provide IT services, software, or technology solutions
  • Handle sensitive or confidential data
  • Integrate with NRG systems or access secure networks

Note: Suppliers providing non-IT goods or administrative services typically do not require security qualification through Whistic.

How to get qualified

Suppliers required to meet security standards can:

  1. Complete the security assessment or questionnaire provided by NRG.
  2. Upload necessary documentation, such as:
  • Cybersecurity policies and procedures
  • Data handling and privacy standards
  • Access controls or certifications
  1. Maintain up-to-date security qualifications to remain eligible for engagements involving secure systems or data.
Helpful links:
 
Why it matters

Meeting security qualifications ensures:

  • Compliance with NRG’s IT and cybersecurity standards
  • Secure handling of sensitive information
  • Eligibility to work on projects involving NRG systems or data

Partnering through Whistic helps simplify the security review process, ensures consistency across suppliers, and supports NRG’s commitment to safeguarding data and technology resources.

STAGE