A security questionnaire is a structured set of questions that one organization sends another, usually a customer to a vendor, to understand how the vendor protects systems and data. Questions cover topics such as access control, encryption, incident response, backups, employee screening, subcontractors and compliance. The answers help the customer decide whether the vendor’s risk is acceptable and what contract terms or controls it should require. Questionnaires range from a few dozen custom questions to long standardized formats.
At a glance
- Questionnaires are a core tool of vendor risk management, used before buying and often again at renewal.
- Formats range from a customer’s own spreadsheet to standardized questionnaires such as the SIG or CAIQ.
- Answers are self-reported, so customers often ask for supporting evidence such as a SOC 2 report or ISO/IEC 27001 certificate.
- For vendors, answering questionnaires can consume significant time and slow sales.
- Answers may be relied on in the contract, so accuracy matters as much as speed.
What problem it solves
Every vendor that handles your data or connects to your systems adds risk. Breaches at suppliers can expose customer data, disrupt operations or provide a route into your own network. Before trusting a vendor, an organization needs a consistent way to learn what it does to protect information.
A questionnaire gives that structure. It turns broad worries into specific questions, records the vendor’s commitments, and highlights gaps that need follow-up, compensating controls or contract terms. For organizations assessing many vendors, a standard questionnaire also makes answers comparable.
How it works
Sending. The customer chooses a questionnaire based on the vendor’s risk: a short one for low-risk tools, a full assessment for vendors handling sensitive data or with privileged access. Many use a standard format or a vendor risk platform that sends, tracks and scores questionnaires.
Answering. The vendor gathers answers from security, IT, legal and operations teams and attaches evidence such as policies, a SOC 2 report, an ISO/IEC 27001 certificate or a penetration testing summary. Many vendors maintain an answer library or a public trust center to reuse approved responses.
Review. The customer’s security or risk team reviews the answers, flags gaps, asks follow-up questions and rates the vendor’s risk, often as part of a broader risk assessment.
Outcome. The result may be approval, approval with conditions (such as contract clauses, additional controls or a remediation plan), or rejection. Findings are recorded and revisited at renewal or when the vendor’s service changes.
When it matters for buyers
- When buying a SaaS, cloud or managed service that will touch your data. Size the questionnaire to the risk.
- When your own customers send you questionnaires. Fast, consistent answers can shorten sales cycles.
- When contracts include security commitments. Answers may be referenced or relied on, so keep them accurate and current.
- When your vendor list grows. A structured process and tooling keep assessments manageable; see governance, risk and compliance (GRC).
- When auditors or regulators ask how you manage third-party risk. Completed questionnaires and reviews are part of the evidence.
Our governance, risk and compliance overview covers platforms and services that manage vendor assessments.
Questions to ask vendors
When assessing vendors:
- Do you have a completed standard questionnaire, such as the SIG or CAIQ, that you can share?
- Which independent reports or certifications support your answers, and what do they cover?
- Who reviewed these answers, and when were they last updated?
- Which answers depend on subcontractors, and how do you assess them?
- Will you notify us if any material answer changes during the contract?
When choosing a tool to manage questionnaires:
- Can it send, track and score questionnaires and store evidence in one place?
- Can it reuse our approved answers when we respond to customers?
How it differs from a SOC 2 report
A security questionnaire records what a vendor says about its own security, in answer to questions the customer chooses. A SOC 2 report is an independent auditor’s examination of the vendor’s controls against defined criteria, with an opinion and, in a Type II report, test results over a period. The report carries more assurance but covers only its stated scope; the questionnaire is flexible but self-reported. Most buyers use both: the report for independent evidence, the questionnaire for topics the report doesn’t address. Both feed into broader data security compliance and vendor risk work.
