Pick how the product gets installed, let an agent handle setup, have the vendor close whatever it can't, then run the live product against a real attack scenario. Same four steps for every vendor in that category.
An IaC template plus its test definition, bundled as one deployable artifact. It answers where the product runs — SaaS, on-prem agent, appliance, or cloud-native — not what gets installed or what it's tested against.
The agent runs the standard install against the harness. Whatever it can't resolve becomes a short punch list the vendor closes directly, in exchange for a ProofStamp listing rather than a bespoke build.