Answers

What is a security questionnaire?

This page explains what a security questionnaire is, which standard forms show up most, what categories they cover, who owns the answer inside the vendor, and how a modern revenue team keeps the review from stalling a deal. It is a general-purpose explanation, not legal or compliance advice.

Short answer

A security questionnaire is the pre-contract document that a buyer's procurement or security team sends a vendor to assess the vendor's security posture before signing. Standard forms include SIG from Shared Assessments, CAIQ from the Cloud Security Alliance, and VSAQ from Google, alongside custom lists of 100 to 500 questions. It covers encryption, access control, incident response, data residency, and employee screening. Ownership sits with GRC or security, and the completed answer flows back to the account executive and legal.

Key points

What matters most.

Six things every account executive and GRC lead should know about security questionnaires before the next enterprise deal lands in the pipeline.

What it is

A pre-contract security review.

A security questionnaire is a structured document that a buyer's procurement, information security, or vendor-risk team sends a prospective vendor before signing a contract. The vendor answers written questions about controls, policies, and architecture, and the buyer uses the answers to decide whether the vendor meets internal risk thresholds.

Standard forms

SIG, CAIQ, VSAQ, or custom.

Three well-known standard forms cover most reviews: the Standardized Information Gathering (SIG) questionnaire from Shared Assessments, the Consensus Assessments Initiative Questionnaire (CAIQ) from the Cloud Security Alliance, and the Vendor Security Assessment Questionnaire (VSAQ) originated by Google. Many enterprises still send a custom list of 100 to 500 questions on top.

What it covers

Encryption to employee screening.

A typical questionnaire covers encryption at rest and in transit, identity and access management, incident response, backup and recovery, data residency, subprocessor disclosures, change management, employee background checks, vulnerability management, and physical security of hosting facilities. The breadth is wide and the detail runs deep.

Who owns it

GRC or security, not sales.

The authoritative owner inside the vendor is the governance, risk, and compliance (GRC) or information security team. They hold the control narratives, the evidence library, and the audit history that the answers lean on. Sales routes the request in and ships the answer back out, but the facts live with GRC.

Return path

Back to the AE and legal.

The completed questionnaire is returned to the account executive, who routes it back to the buyer's procurement contact, and to legal, who reconciles any contractual overlaps (DPA, MSA, security addendum). A finding in the questionnaire sometimes triggers a redline on the contract, which is why both teams need the full response, not a summary.

Deal impact

A gate, not a formality.

Security questionnaires are not a rubber stamp. A late or incomplete answer can slip a deal by a quarter, and a failed answer can kill it outright. Mature revenue teams treat the questionnaire as a stage gate with named owners, a service-level target, and an evidence repository that keeps the response time measurable.

Standard forms

SIG, CAIQ, VSAQ, and the custom list.

Buyers rarely invent a questionnaire from scratch. They adopt one of the published industry frameworks and adjust it to their risk tolerance, their sector, and the data they plan to share with the vendor. Knowing which form you have been handed is the first clue to how heavy the review will be. SIG tends to signal a formal third-party risk program; CAIQ signals cloud-native scrutiny; VSAQ shows up with technology buyers; a bespoke spreadsheet from the buyer's own security team usually signals the most work.

SIG

Shared Assessments SIG.

The Standardized Information Gathering questionnaire is maintained by Shared Assessments. It ships in two sizes, SIG Lite and SIG Core, with Core running close to 1,000 questions across 18 risk domains. Financial services, healthcare, and large enterprises lean on SIG as the backbone of their third-party risk program. A SIG request implies a formal vendor-risk workflow on the buyer side.

CAIQ

Cloud Security Alliance CAIQ.

The Consensus Assessments Initiative Questionnaire is published by the Cloud Security Alliance and maps to the CSA Cloud Controls Matrix. CAIQ v4 ships with roughly 260 yes-or-no questions covering cloud-specific concerns like multi-tenant isolation, virtualization security, and shared responsibility. It is the common language for cloud-native vendors answering cloud-native buyers.

VSAQ

Vendor Security Assessment Questionnaire.

VSAQ was open-sourced by Google and has been adopted and forked by many technology buyers. It is lighter than SIG and more flexible than CAIQ, with sections covering web application security, infrastructure, data handling, and privacy. VSAQ answers often serve as the starting point for a conversation rather than the full assessment.

Custom lists

100 to 500 bespoke questions.

Many enterprises still send a custom spreadsheet or portal workflow with 100 to 500 questions, often blended from SIG, CAIQ, internal policy, and the specific concerns raised by a sector regulator. These lists are the most labor-intensive to answer because they do not map one-to-one onto an existing control narrative.

Industry overlays

HECVAT, HITRUST, and friends.

Vertical-specific overlays show up alongside the general-purpose forms. HECVAT is the Higher Education Community Vendor Assessment Toolkit. HITRUST CSF is heavily used in healthcare. Public-sector buyers may send questionnaires derived from FedRAMP or StateRAMP. The vertical sometimes dictates the form more than the deal size.

Portal workflows

OneTrust, ProcessUnity, SecurityScorecard.

Larger buyers increasingly send the questionnaire through a vendor-risk portal rather than a spreadsheet. OneTrust, ProcessUnity, SecurityScorecard, and Panorays are common. The content is similar, but the vendor logs in to a portal, answers in a web form, and uploads evidence. Portals log timestamps, which makes response-time commitments literal.

What it covers

The categories that appear every time.

Across SIG, CAIQ, VSAQ, and the custom lists, the same control categories show up over and over. Prepare answers for these in advance and the first-pass response time drops from weeks to days. The specific wording varies, but the question behind the question stays the same: does the vendor have a documented control, is it operating, and is there evidence that an auditor has reviewed it recently.

Encryption

At rest, in transit, key management.

Cipher suites in use, TLS versions enforced, data-at-rest encryption on primary databases and backups, where keys are generated and rotated, who holds split knowledge, and whether customer-managed keys are supported. Expect follow-ups about disk-level versus field-level encryption and about key custody when a cloud provider holds the hardware.

Access control

Identity, authentication, authorization.

Single sign-on support, multi-factor authentication for employees and customers, role-based access, least-privilege enforcement, joiner-mover-leaver processes, privileged access management, and audit logs on administrative actions. Buyers also probe how often access reviews run and whether terminated-employee access is revoked within hours, not days.

Incident response

Detection, response, notification.

Documented incident response plan, named owners, tabletop exercises, 24x7 monitoring, mean-time-to-detect and mean-time-to-respond, breach notification obligations by jurisdiction, and the vendor's experience with real incidents in the past 24 months. The follow-up question is always whether the plan has been rehearsed, not just written.

Data residency

Where the data lives.

The regions and data centers where customer data is stored and processed, support for region pinning, cross-border transfer mechanisms (Standard Contractual Clauses, adequacy decisions), and the lineage of any backups or disaster recovery copies in secondary regions. Buyers in EU, UK, Canada, and Australia tend to lean hardest on these questions.

Employee screening

Background checks and training.

Pre-hire background checks, criminal and reference checks for staff with access to customer data, security awareness training on hire and annually, phishing simulations, acceptable-use policy acknowledgements, and separation procedures. Several SIG and HITRUST sections drill specifically into whether screening is renewed on role change.

Subprocessors

The vendor's own vendor list.

A current list of subprocessors (the hosting provider, the email delivery vendor, the error-monitoring tool, the AI inference provider), the data each one touches, and the notification process when the vendor adds a new one. GDPR and DPA obligations map directly onto this answer, which is why legal reviews it alongside security.

The response workflow

How a mature vendor actually answers.

A security questionnaire is as much a workflow problem as a security problem. The answers do not usually require new engineering; they require fast assembly of material that already exists, routed through the right owners, and returned on a schedule the deal can tolerate. The best revenue teams treat the questionnaire like a stage of the sales process with named owners, templates, and a service-level target. The worst treat each one as an unexpected emergency.

Intake

The AE logs the request.

The account executive receives the questionnaire from the buyer's procurement or security team and logs it against the opportunity in the CRM, with the format (SIG, CAIQ, custom), the expected turnaround, and the stage of the deal. Routing without logging is the fastest way to lose track of a 300-question spreadsheet.

Triage

GRC maps questions to controls.

The GRC owner opens the questionnaire, maps each question to an existing control narrative in the evidence library, and flags the questions that do not have a canned answer. The flagged ones go to the subject-matter expert (engineering, HR, legal, DPO). This triage pass is where the review time is won or lost.

Evidence library

Reuse what you already wrote.

A control narrative library, written once and kept current, is the backbone of fast responses. It holds the standard answer for every recurring question: how data is encrypted, how access is granted, how backups are tested, how incidents are handled. Each entry links to the primary evidence (policy document, audit report, screenshot) that supports it.

SME review

Experts answer novel questions.

Novel questions go to a named subject-matter expert with a deadline. The SME writes an answer in plain language, grounded in current practice, and the GRC owner edits it into the questionnaire's required format (yes-no, free-text, multiple choice). The SME names the primary evidence that supports the answer, not just the answer itself.

Legal sign-off

Reconcile with the contract.

Legal reviews the completed questionnaire for anything that could conflict with the MSA, DPA, or security addendum already in flight. A questionnaire answer is a representation; if it goes further than the contract, that gap gets reconciled before the response ships back to the buyer. The AE loops legal in before, not after.

Return and track

Back to the AE and the buyer.

The completed questionnaire returns to the AE, who sends it to the buyer's procurement contact (or completes the portal workflow) and records the turnaround time in the CRM. Mature teams review response-time metrics quarterly to spot questionnaires that chronically bottleneck and the categories where the evidence library needs more depth.

A CRM that keeps the security review on the opportunity.

Strkr tracks the questionnaire as a stage task on the deal, with named owners, due dates, and a place to attach the completed response. Role-based access, audit logs, a published DPA, and SOC-ready evidence export mean the GRC team is not fighting the CRM while they fight the questionnaire.

People also ask

Related questions.

What is the difference between SIG and CAIQ?

SIG, the Standardized Information Gathering questionnaire from Shared Assessments, is a general-purpose third-party risk form used heavily in financial services, healthcare, and large enterprises. It ships in SIG Lite and SIG Core sizes, with Core reaching close to 1,000 questions across 18 risk domains. CAIQ, the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance, is narrower and cloud-focused. CAIQ v4 has roughly 260 yes-or-no questions mapped to the CSA Cloud Controls Matrix, aimed at cloud-service providers answering cloud-native buyers. Mature vendors keep answers ready for both.

Who inside a vendor owns the security questionnaire?

The authoritative owner is the governance, risk, and compliance (GRC) team or the information security team, depending on how the vendor is structured. They hold the control narratives, the evidence library, and the audit history that the answers draw on. Sales owns intake and return (routing the request from the buyer and sending the response back), legal reconciles the answers with the contract, and subject-matter experts in engineering, HR, and operations answer the questions outside the library. The AE is the project manager, not the author.

How long does a security questionnaire usually take to complete?

It varies by form, by preparation, and by how many novel questions the buyer sends. A well-prepared vendor with a current evidence library can turn a CAIQ in a day or two, a SIG Lite in two to five days, and a full SIG Core or a 500-question custom list in one to three weeks. Vendors without a library often spend four to eight weeks on the same request, because every question becomes an original research project. Response time is a real deal variable, not a back-office metric.

Can a SOC 2 report replace a security questionnaire?

Sometimes, rarely in full. A current SOC 2 Type II report (plus a bridge letter for any gap) answers many of the control questions a buyer would otherwise ask, and mature buyers accept the report in lieu of large sections of their questionnaire. But most buyers still send a questionnaire alongside the report, both to cover controls the SOC 2 scope did not include and to get vendor-specific answers on data residency, subprocessors, and incident history. A SOC 2 is leverage, not an exemption.

What is a vendor security assessment versus a security questionnaire?

A security questionnaire is one piece of a broader vendor security assessment. The assessment is the full pre-contract review process a buyer runs on a prospective vendor: it typically includes the questionnaire, a review of audit reports (SOC 2, ISO 27001), a privacy review and DPA, sometimes a penetration-test summary or an architecture call, and increasingly a continuous-monitoring rating from a third party like SecurityScorecard or BitSight. The questionnaire is the structured document; the assessment is the end-to-end workflow.

What happens if a vendor fails a security questionnaire?

The outcomes range from a redline on the contract to a dead deal, depending on the finding. A missing control that the vendor can commit to adding within a defined window often turns into a contractual security addendum with milestones and reporting obligations. A material gap (no encryption on primary data, no incident response plan, no SOC 2 or equivalent) usually kills the deal or sends the buyer back to shortlist alternatives. A buyer will almost always disclose which answer triggered the escalation, which is useful intelligence for the vendor's roadmap.

Do small B2B vendors have to answer security questionnaires?

Any vendor selling to a buyer with a vendor-risk program is likely to see one, regardless of size. The threshold is usually set by data sensitivity and spend, not by vendor headcount. A ten-person SaaS startup selling into a Fortune 500 buyer will see the full SIG. The pragmatic answer for small vendors is to invest early in the control narratives and evidence library (and ideally a SOC 2 Type II), because the first enterprise questionnaire shows up long before the team feels ready for one.

How should the CRM support security questionnaire workflow?

A CRM supports the workflow by letting the AE log the questionnaire against the opportunity, route the task to GRC with a due date, attach the completed response and supporting evidence to the record, and track response-time metrics across all open requests. The questionnaire does not live in the CRM as a document editor; it lives in an evidence tool or portal. But the status, the owner, the deadline, and the final response belong on the opportunity so the deal and the review stay synchronized.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.