Enquirer Consulting Group

Reachable Buyer Map

Prepared for Stephen Puma · Exiger · United States · August 2026
In this market, first contact usually happens inside the networks a compliance or procurement function already sits in: analyst shortlists, industry events, and referrals from counsel. That reaches the companies already looking. This map is the layer underneath, counted across the United States only. The segments where third party and supply chain risk is a standing obligation, who signs inside each one, and roughly how many companies sit there.
Defense, aerospace and the federal supply base
The segment where supplier screening is written into the contract rather than chosen, so the question is never whether to do it, only who does it and how fast the evidence can be produced.
Who signs: chief compliance officer, head of supplier risk, director of government compliance, chief procurement officer.
5,500 to 6,000
US employers registered across defense, aerospace and related contract manufacturing, of which roughly 2,400 carry 20 or more people on the plan
Banks, credit unions and financial institutions
The oldest buyer of vendor due diligence and the one with the most examiner pressure behind it. Review cycles here are annual and documented, which makes the entry point a date rather than an argument.
Who signs: chief risk officer, head of third party risk management, financial crime compliance officer, general counsel.
7,000 to 7,500
US employers registered across depository institutions, credit unions and related financial services, of which roughly 4,600 carry 20 or more
Pharmaceutical, biotech and medical device makers
Supplier qualification here is a regulated activity with an audit trail attached, and the ingredient and component chains run several tiers deep, which is usually where visibility stops.
Who signs: head of supplier quality, VP of external manufacturing, chief compliance officer, head of global sourcing.
5,000 to 5,500
US employers registered across pharmaceutical, biological product and medical device production, of which roughly 2,300 carry 20 or more
Telecommunications, software and technology vendors
The segment where the supply chain in question is software rather than parts. Component provenance is now something customers and agencies ask for in writing, so the requirement arrives through the sales cycle.
Who signs: chief information security officer, head of product security, VP of engineering, head of vendor risk.
6,500 to 7,000
US employers registered across telecommunications, software publishing and computer services, of which roughly 2,600 carry 20 or more
Automotive and heavy industrial manufacturers
Multi tier component chains with real concentration risk inside them. The trigger tends to be a disruption or a forced substitution rather than a policy decision, so the buying window opens without warning.
Who signs: chief procurement officer, VP of supply chain, director of supplier development, head of enterprise risk.
4,500 to 5,000
US employers registered across motor vehicle, machinery and heavy industrial production, of which roughly 2,200 carry 20 or more
Energy, utilities and pipeline operators
Critical infrastructure, so the obligation arrives from more than one regulator at once and the evidence has to satisfy all of them. Small by count and unusually concentrated by ownership.
Who signs: chief compliance officer, head of supply chain, director of infrastructure protection, general counsel.
3,000 to 3,400
US employers registered across electric power, gas distribution and pipeline transportation, of which roughly 1,500 carry 20 or more

Where the openings are

1
The segments above come to roughly 31,500 to 34,400 registered US employers. About 15,600 of them carry 20 or more people on the plan, which is the band that can fund a platform decision rather than a spreadsheet. Referral and event contact reaches whichever slice of that already overlaps an existing network. The rest is not unqualified, it is simply unaware.
2
Your own site counts 150 Fortune 500 companies and more than 60 federal agencies. That named tier is finite, and by now it is well covered by everyone selling into it. The count above sits almost entirely beneath it, in companies carrying the same obligation with a fraction of the staff to meet it, and they do not turn up at the same events.
3
The buyer here is a role, not a company. Chief compliance officer, head of third party risk, chief procurement officer, chief information security officer. Those seats turn over often, and a new one almost always reopens the vendor question inside the first two quarters. A channel built on named roles catches that moment. A referral channel hears about it once the decision is made.
4
These problems do not share one buyer. Third party risk sits with compliance, supply chain risk sits with procurement and operations, software supply chain security sits with the security team, and due diligence sits with counsel and the deal side. One channel tends to keep returning to the same door. Four named audiences is a different reach problem, and a solvable one.
Built from public federal registry data covering US employers that file a benefit plan, current to the 2024 filing year. Counts are banded deliberately. Workforce bands use plan participants as a headcount proxy, so they indicate scale rather than an exact staff count. Owner-only and very small employers are not published in this data. Sector codes are self-reported by the companies themselves. It describes the market rather than your business, and there is nothing to buy at the end of it.
ENQUIRER CONSULTING GROUP