Glossary
What is a security questionnaire?
A security questionnaire is a structured set of questions a prospective or existing customer sends to a vendor to evaluate how that vendor protects data and manages risk. It typically covers access controls, encryption, compliance certifications (like SOC 2 or ISO 27001), incident response, and data handling. Completing one is usually a prerequisite for closing a B2B deal.
Who sends them and why
Security, procurement, and vendor-risk teams send questionnaires as part of third-party risk management — verifying that a new vendor won’t become a weak link in their own security posture. The larger the buyer, the more thorough the questionnaire.
What they contain
Questionnaires range from a handful of questions to several hundred rows. Common formats include the SIG, the CAIQ, and custom spreadsheets or web portals. Questions ask for a yes/no answer, a written explanation, and often a link to supporting evidence such as a policy or audit report.
How teams answer them faster
Because the same questions recur, teams reuse past answers — but reused answers go stale as the underlying program changes. Grounding each answer in live compliance evidence, citing its source, and flagging drift keeps answers both fast and defensible.