Skip to content
All articles
Blog

Vendor security questionnaire: how to answer and send one

A vendor security questionnaire is a request for evidence, not paperwork. How to answer one without losing weeks, and how to send one that tells you the truth.

By Mahoney IT Security Team 11 min read
Hollow wireframe bars float above seven solid, glowing blocks. Thin lines of light connect most bars to a block below, but several lines dangle into empty darkness, connecting to nothing. One bar, its line and its block glow orange — claims anchored to evidence set against claims that are not.
Key takeaways
  • A vendor security questionnaire is a structured request for evidence about how a third party protects your data. Answer from memory and you're guessing; accept someone else's answers without validating them and you've collected paperwork, not assurance.
  • Standardized question sets (the SIG, the CAIQ, the VSA) exist so answers can be reused instead of rewritten from scratch every time.
  • When you're the one asking: tier vendors by risk, ask for artifacts instead of adjectives, and reassess whenever something material changes.
In this article

A vendor security questionnaire is a request for evidence, not just a request for answers. That distinction decides how the entire exercise goes. Fill one out from memory and you’re describing the security program you believe you have. Accept someone else’s answers without checking them and you’ve collected paperwork, not assurance.

Both sides of a questionnaire fail for the same reason: the answers aren’t tied to anything anyone can show. This guide covers both roles. If one is already sitting in your inbox, skip ahead to how to answer it; if you’re the one sending it, start at how to send one that tells you something true.

What is a vendor security questionnaire?

A vendor security questionnaire is a structured set of questions one company sends to another to assess how that vendor protects data, systems, and access. It’s the working instrument of vendor risk assessment — also called a vendor security assessment — and, more broadly, of third-party risk management.

In practice it arrives as a spreadsheet, a portal invitation, or a PDF, carrying anywhere from twenty to several hundred questions on access control, encryption, incident response, subprocessors, and compliance attestations. The output is a picture of the vendor’s security posture and, usually, a risk rating that decides whether the deal proceeds, proceeds with conditions, or stops.

The questionnaire feeds the assessment; validation is what turns it into one. That means matching each claim against an artifact — an auditor’s report, a policy with a revision date, a coverage view, a penetration test summary.

Why companies send vendor security questionnaires

Companies send vendor security questionnaires because their own cyber risk now includes yours. A data breach at a vendor still lands on the customer’s incident report, their regulator’s desk, and their reputation. That’s why third-party risk moved out of procurement and into the security team.

The rest is external pressure. Vendor management is an explicit control area in the major security frameworks, so an audit wants the register of your third parties plus evidence that you assessed them — and cyber insurance applications and data protection law such as the GDPR expect the same due diligence on anyone handling personal data.

There’s a fourth reason, less often admitted: the questionnaire creates a record of care. That’s also why it degrades so easily into a filing exercise — and why validation is the step worth protecting.

The control areas nearly every questionnaire covers

Most questionnaires converge on the same security controls, whatever their length. Three are sharp only in a vendor context; the rest is the baseline every framework asks for.

  • Subprocessors and fourth parties. Who else touches the data — the question that exposes a supply chain most senders never mapped, and the one most often answered incompletely.
  • Compliance attestations. Which reports exist, what they actually cover, and when the observation period ended. Scope and date matter more than the logo on the cover.
  • Exit and data return. What happens to your data when the contract ends: retention, deletion, and proof that deletion happened.
  • Access control and authentication. MFA coverage, least-privilege access, privileged accounts, and how access is removed when someone leaves.
  • Data protection. Encryption at rest and in transit, data classification, and retention.
  • Incident response. A written and tested plan, plus contractual notification commitments.
  • Resilience and continuity. Backups and tested recovery.
  • Application and personnel security. Secure development, vulnerability management, patch cadence, penetration testing, background checks, and security awareness training.

The last five are the control baseline every framework asks for, covered in our guide to cybersecurity compliance for small business.

Standard questionnaires: the SIG, the CAIQ, and the VSA

Standard questionnaire templates exist so neither side has to invent the questions or rewrite the answers each time. Three recur, alongside the custom template your largest customer built in-house and will not replace.

QuestionnaireWhat it isWhen you will meet it
SIG (Standardized Information Gathering)A licensed question set from Shared Assessments, published in full and abbreviated versions across many risk domainsRegulated industries and mature vendor risk management programs
CAIQ (Consensus Assessments Initiative Questionnaire)The Cloud Security Alliance’s question set mapped to its Cloud Controls Matrix, aimed at cloud securityAssessing SaaS and cloud providers; many publish a completed CAIQ
VSA (Vendor Security Alliance)A free question set published by a coalition of technology companies, in a short Core and a fuller Full versionFaster reviews where a full SIG would be disproportionate — less common in practice than the SIG or CAIQ
Custom questionnaireYour customer’s own spreadsheet, assembled from their framework obligationsAlmost always, and usually the one that takes longest

Underneath all of them sit the same security standards — most often SOC 2, ISO 27001, and the NIST Cybersecurity Framework (CSF). A completed questionnaire is no substitute for a report against those standards, and a report is no substitute for the questionnaire: the report shows an independent party tested the controls, the questionnaire shows how they apply to the service you’re actually buying.

These frameworks describe security objectives an organization may need to meet; certification or attestation against them is awarded by independent auditors, not by any software vendor. Tools can help map and evidence controls, but the audit and the report come from an accredited third party.

How to answer a vendor security questionnaire without losing weeks

Answering is where security teams bleed time, because each questionnaire is treated as a fresh writing project. It should be a retrieval task. These best practices make it one, and all of them happen before the questionnaire arrives.

  • Build an answer library. Keep reviewed answers, with evidence attached to each, in one place — versioned, owned, and dated. Most incoming questions are the same questions in different words, so a maintained library turns a long spreadsheet into a review pass rather than a rewrite.
  • Answer from evidence, not from memory. If the honest answer is “we believe so,” it isn’t ready. Pull the coverage view, the log, the policy. It’s the same discipline that carries a SOC 2 readiness program, and the evidence you build for one answers the other.
  • Never overclaim. Questionnaire responses are frequently incorporated into the contract or backed by a warranty of accuracy, so an inflated answer can carry contractual consequences rather than being a rounding error. “Not applicable, because…” and “planned, with a target date” are legitimate. A confident yes you can’t evidence isn’t.
  • Use automation with a reviewer attached. AI drafts well when it retrieves from your approved answer library and the evidence behind it; it must not invent security measures you don’t run. Every AI-drafted response needs a named human owner before it goes back to the customer.

How to send one that tells you something true

On the other side of the exchange, the failure mode is different: questionnaires grow every year, get read once, and change nothing. That’s theater with a paper trail. A vendor security questionnaire earns its cost only when the answers can change a decision.

  • Tier your vendors first. A third party holding customer records deserves a different depth of review than one selling office supplies. Classify by data sensitivity, access level, and the damage their downtime does, then match the questionnaire to the risk level. Sending the full set to everyone guarantees rushed answers — including from the vendors that matter.
  • Ask for artifacts, not adjectives. A shorter questionnaire backed by evidence requests is worth more than a long one answered from memory, and far easier to validate.
The questionAn answer that doesn’t hold upAn answer that does
Do you have an incident response plan?”Yes.”The plan itself, plus the date and record of the last test
Is data encrypted at rest?”All sensitive data is encrypted.”The encryption standard, the systems in scope, and an inventory of what is not covered
Do you enforce MFA?”MFA is enabled.”A coverage view showing every account, including admin and legacy consoles
Who are your subprocessors?”We use trusted providers.”The current subprocessor list, what data each one touches, and when it was last reviewed
  • Validate the responses. Check dates and scope on every report — an attestation covering a different product line, or one whose observation period ended more than a year ago, is a common and easily missed gap. Where a claim matters and cannot be evidenced, treat it as unproven and negotiate: compensating controls, contractual commitments, or a narrower scope of data.
  • Reassess on the vendor’s triggers, not the calendar. A breach, an acquisition, a new subprocessor, or an expanded scope of data should each start a fresh review — annual cycles alone let the picture age quietly.

How Mahoney Control turns evidence into answers

Our position is straightforward: for most teams, the hardest part of a vendor security questionnaire isn’t knowing the answers. It’s finding the proof — assembling evidence by hand, every time somebody asks, when it already exists somewhere in the environment.

Mahoney Control, by Mahoney IT, runs the questionnaire the other way round. Its intake questionnaire captures your posture across control domains and correlates the responses with live device data, so the system validates your answers against your actual infrastructure rather than accepting self-reported claims at face value. That’s the same test a customer’s questionnaire applies to you — run continuously, and in advance. The governance module maps those controls against the frameworks your customers hold you to — including SOC 2, ISO 27001, and NIST CSF — from a single control baseline. This is mapping and evidence, not certification: certification itself is awarded by independent auditors. Mahoney Control prepares your organization for that audit. (The only formal certification Mahoney IT itself holds is ISO 9001:2015, certified by DEKRA (Germany).)

You can read more on our Governance overview.

Frequently asked questions

What is a vendor security questionnaire? A vendor security questionnaire is a structured set of questions a company sends to a third party to evaluate how that vendor protects data, systems, and access. It typically covers access control, encryption, incident response, subprocessors, and compliance attestations.

What is the difference between a vendor security questionnaire and a vendor risk assessment? The questionnaire is one input; the vendor risk assessment is the conclusion. The assessment combines vendor responses with validation against artifacts and the business context — how sensitive the data is, how deep the access goes — and ends in a risk rating and a decision. A questionnaire filed without that analysis is documentation, not vendor risk management.

How often should vendor security assessments be conducted? Reassess high-risk vendors at least annually, lower-risk ones on a longer cycle, and any vendor immediately after a material change such as a security incident, an acquisition, or an expanded scope of data. Between formal reviews, continuous risk monitoring keeps the picture current — a point-in-time review starts aging the day it’s filed.

What should I do if a vendor has no SOC 2 report? Treat it as missing evidence, not an automatic disqualification: smaller vendors often run sound security practices without having commissioned an examination. Ask for what does exist — policies, a penetration test summary, a completed CAIQ — and weigh it against the data and access at stake. A SOC 2 report is issued by an independent auditor, never by the vendor or its own tooling, so a vendor claiming to certify itself is the real warning sign.

Can AI answer security questionnaires? AI is genuinely useful for drafting responses from an approved answer library and for matching incoming questions to answers you’ve already validated. What it must not do is generate claims about security controls you don’t run. Keep a named human owner accountable for every response before it’s returned, because the answers become commitments.

If you’d like to see what evidence-backed questionnaire responses would look like for your organization, request a no-obligation consultation.

This article is general information on vendor risk practice and does not constitute legal advice.

#vendor risk #third-party risk #questionnaires #governance

Let's talk about your security

Mahoney Control — by Mahoney IT — unifies risk, operations, and growth on a single surface. Book a no-obligation conversation.

Contact us