What Is a Security Questionnaire?

Also called: Vendor security questionnaire, Vendor security assessment questionnaire

Related problems: A prospect sent a 300-question security spreadsheet and the deal is waiting on it; Answering the same security questions for every customer; No consistent way to assess the security of our own vendors; Not sure how much to trust a vendor's self-reported answers

A security questionnaire is a structured set of questions that one organization sends another, usually a customer to a vendor, to understand how the vendor protects systems and data. Questions cover topics such as access control, encryption, incident response, backups, employee screening, subcontractors and compliance. The answers help the customer decide whether the vendor’s risk is acceptable and what contract terms or controls it should require. Questionnaires range from a few dozen custom questions to long standardized formats.

At a glance

  • Questionnaires are a core tool of vendor risk management, used before buying and often again at renewal.
  • Formats range from a customer’s own spreadsheet to standardized questionnaires such as the SIG or CAIQ.
  • Answers are self-reported, so customers often ask for supporting evidence such as a SOC 2 report or ISO/IEC 27001 certificate.
  • For vendors, answering questionnaires can consume significant time and slow sales.
  • Answers may be relied on in the contract, so accuracy matters as much as speed.

What problem it solves

Every vendor that handles your data or connects to your systems adds risk. Breaches at suppliers can expose customer data, disrupt operations or provide a route into your own network. Before trusting a vendor, an organization needs a consistent way to learn what it does to protect information.

A questionnaire gives that structure. It turns broad worries into specific questions, records the vendor’s commitments, and highlights gaps that need follow-up, compensating controls or contract terms. For organizations assessing many vendors, a standard questionnaire also makes answers comparable.

How it works

Sending. The customer chooses a questionnaire based on the vendor’s risk: a short one for low-risk tools, a full assessment for vendors handling sensitive data or with privileged access. Many use a standard format or a vendor risk platform that sends, tracks and scores questionnaires.

Answering. The vendor gathers answers from security, IT, legal and operations teams and attaches evidence such as policies, a SOC 2 report, an ISO/IEC 27001 certificate or a penetration testing summary. Many vendors maintain an answer library or a public trust center to reuse approved responses.

Review. The customer’s security or risk team reviews the answers, flags gaps, asks follow-up questions and rates the vendor’s risk, often as part of a broader risk assessment.

Outcome. The result may be approval, approval with conditions (such as contract clauses, additional controls or a remediation plan), or rejection. Findings are recorded and revisited at renewal or when the vendor’s service changes.

When it matters for buyers

  • When buying a SaaS, cloud or managed service that will touch your data. Size the questionnaire to the risk.
  • When your own customers send you questionnaires. Fast, consistent answers can shorten sales cycles.
  • When contracts include security commitments. Answers may be referenced or relied on, so keep them accurate and current.
  • When your vendor list grows. A structured process and tooling keep assessments manageable; see governance, risk and compliance (GRC).
  • When auditors or regulators ask how you manage third-party risk. Completed questionnaires and reviews are part of the evidence.

Our governance, risk and compliance overview covers platforms and services that manage vendor assessments.

Questions to ask vendors

When assessing vendors:

  • Do you have a completed standard questionnaire, such as the SIG or CAIQ, that you can share?
  • Which independent reports or certifications support your answers, and what do they cover?
  • Who reviewed these answers, and when were they last updated?
  • Which answers depend on subcontractors, and how do you assess them?
  • Will you notify us if any material answer changes during the contract?

When choosing a tool to manage questionnaires:

  • Can it send, track and score questionnaires and store evidence in one place?
  • Can it reuse our approved answers when we respond to customers?

How it differs from a SOC 2 report

A security questionnaire records what a vendor says about its own security, in answer to questions the customer chooses. A SOC 2 report is an independent auditor’s examination of the vendor’s controls against defined criteria, with an opinion and, in a Type II report, test results over a period. The report carries more assurance but covers only its stated scope; the questionnaire is flexible but self-reported. Most buyers use both: the report for independent evidence, the questionnaire for topics the report doesn’t address. Both feed into broader data security compliance and vendor risk work.

Frequently Asked Questions

What are SIG and CAIQ?
They are widely used standardized questionnaires. The SIG (Standardized Information Gathering) questionnaire comes from Shared Assessments, and the CAIQ (Consensus Assessments Initiative Questionnaire) from the Cloud Security Alliance for cloud providers. Using a standard format lets vendors answer once and reuse the result.
Can a SOC 2 report replace a security questionnaire?
Often in part. Many customers accept a SOC 2 report or ISO/IEC 27001 certificate in place of large sections of their questionnaire, then ask follow-up questions on topics the report does not cover, such as data locations, AI use or specific contract terms.
How should we answer questionnaires efficiently?
Keep a reviewed library of approved answers, policies and evidence, publish what you can in a trust center or security page, and route only new or unusual questions to experts. Make sure answers stay accurate: they can become part of the contract.
How much should we trust a vendor's answers?
Treat them as the vendor's own statements. Weigh them alongside independent evidence such as audit reports, certifications and penetration test summaries, and ask for proof on the controls that matter most to your risk.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.