A sub-processor is a third party engaged by your vendor to process personal data on their behalf — for example their hosting or email provider.
Under GDPR your vendor must disclose its sub-processors and remain liable for them. A published, current sub-processor list is a reasonable minimum expectation from any serious SaaS supplier.