Answers

What is a vendor security review?

This page explains what the reviewing team is actually looking for, how a vendor security review differs from a one-off questionnaire, and the artifacts a vendor needs on hand to clear procurement. It is a general-purpose explanation for revenue teams, not legal advice.

Short answer

A vendor security review is the enterprise procurement step that evaluates a SaaS vendor's security, privacy, and resilience posture before a purchase is approved. The reviewing team collects artifacts like a SOC 2 Type II report, pen test summary, Data Processing Agreement, sub-processor list, incident response plan, cyber insurance certificate, and SLA, then compares them to internal risk standards. A typical review takes two to six weeks and can block the deal entirely if the vendor cannot produce the required evidence.

Key points

What matters most.

Six things every revenue leader should know about the vendor security review before an enterprise deal reaches late stage.

What it is

A procurement gate, not a formality.

A vendor security review is a formal evaluation run by the buyer's security, privacy, and procurement functions to decide whether a vendor is safe to onboard. It happens before contract signature and after commercial terms are usually agreed. Deals that cannot clear the review get paused or killed, no matter how strong the business case.

The artifact bundle

Eight documents do most of the work.

The reviewing team expects a predictable set of artifacts: SOC 2 Type II report, independent penetration test summary, completed security questionnaire, Data Processing Agreement, sub-processor list, incident response plan, cyber insurance certificate, and the SLA. Missing or stale artifacts stretch the timeline and raise the risk score.

Who runs it

Security, privacy, legal, procurement.

A full review usually involves four internal functions on the buyer side: information security (controls and architecture), privacy (data flows and subject rights), legal (contract and liability), and procurement (process owner). Each function has its own checklist, and the review is not complete until all four sign off.

Timeline

Two to six weeks is normal.

A well-prepared vendor with current artifacts can clear a straightforward review in two weeks. Complex deals, regulated industries, or missing documents stretch to six weeks or more. The timeline is often the single biggest driver of a slipped close date, and it is not something sales can shorten by escalating.

Different from a questionnaire

A review is broader than one form.

A one-off security questionnaire (CAIQ, SIG, custom spreadsheet) is one input to the review. The review itself also includes artifact inspection, architecture discussions, contract redlines, risk scoring, and sign-off from multiple functions. Teams that only prepare the questionnaire are usually surprised by the rest of the process.

Prepared vendors win

A trust center shortens every deal.

Vendors that publish a trust center with current SOC 2, pen test summary, DPA template, and sub-processor list behind an NDA click-through consistently clear review faster than vendors that scramble per deal. The prep work pays off every time the review runs, which on the enterprise side is every single deal.

The artifact bundle

The documents a reviewer actually asks for.

A vendor security review is driven by artifacts. The reviewing team wants documents it can read, forward to colleagues, and attach to an internal risk record. Verbal reassurance does not clear the gate. Every artifact below shows up on nearly every enterprise review, and vendors that have them current and easy to share are already most of the way to approval. Vendors that have to generate the artifacts after the request lands are already behind.

SOC 2 Type II

The security baseline for SaaS.

A SOC 2 Type II report is an independent auditor's evaluation of a vendor's security controls over a period of time, usually six to twelve months. It is the single most-requested artifact in enterprise review and the one most reviewers read first. Type I (point in time) is not an acceptable substitute at the enterprise tier.

Pen test summary

Independent attack testing.

An executive summary from a recent third-party penetration test, usually within the past twelve months. Reviewers want to see scope, methodology, severity counts, and remediation status. The full report is almost never shared, but the summary and remediation attestation together clear the question.

Security questionnaire

The buyer's custom checklist.

A completed security questionnaire tailored to the buyer's risk program. Common standards include CAIQ (Cloud Security Alliance) and SIG (Shared Assessments), but most large buyers overlay their own custom questions. Questionnaires run anywhere from fifty to five hundred items, and completion speed is a visible signal of maturity.

DPA

Data Processing Agreement signed.

A Data Processing Agreement defines how the vendor will handle personal data on the buyer's behalf. It is required under GDPR and most privacy laws, and every reviewer expects a template vendors can execute without a bespoke negotiation. Vendors that insist on their own paper and refuse the buyer's redlines stall at this stage.

Sub-processor list

Every downstream vendor named.

A current, published list of every sub-processor the vendor uses to deliver the service: hosting, email, analytics, support tooling, enrichment, telemetry. GDPR requires it, and reviewers compare the list to their own approved-vendor registry. A short, clear list usually clears faster than a long one with vague descriptions.

IRP + insurance + SLA

Response plan, policy, uptime.

Three closing artifacts round out the bundle: a written incident response plan with notification timelines, a cyber liability insurance certificate from a recognized carrier, and a service level agreement defining uptime commitments and credits. These three together let a reviewer answer "what happens when things go wrong?" without a follow-up call.

Review vs. questionnaire

Why a full review is bigger than one form.

Teams that have cleared a few mid-market deals often think the vendor security review is the questionnaire. It is not. The questionnaire is one artifact among eight or more, and the review itself is a process with four internal reviewers, risk scoring, and sign-off at each stage. Treating the review as "answer the SIG" is one of the most common ways enterprise deals slip past their original close date, because the questionnaire is often the easiest part to finish and the artifact inspection and contract redlines take longer.

Questionnaire alone

One form, one owner, days.

A one-off questionnaire request is a single document the buyer sends over, usually completed by the vendor's security or GRC function in a few business days. It is common in mid-market deals and in pre-sales discovery. The buyer may or may not read the full response, and a signed contract often follows without further review.

Full review

Multiple artifacts, multiple owners.

A full vendor security review is a cross-functional process. Security reviews controls, privacy reviews data flows, legal reviews contract terms and liability caps, and procurement owns the process end to end. Each function produces its own findings, and the review is not complete until each has signed off against its own standard.

Risk tiering

Not every vendor gets the full review.

Mature buyers tier vendors by risk: a background-check tool and a payments processor do not get the same scrutiny. Factors include data classification (does it touch customer PII, financial data, source code?), access scope, criticality to the business, and regulatory exposure. CRMs, email tools, and anything processing contact data usually land in a higher tier.

Artifact inspection

Reviewers actually read the reports.

Beyond collecting documents, reviewers read the SOC 2 for exceptions, the pen test for unresolved criticals, and the sub-processor list for known-bad vendors. A vendor that treats the artifacts as proof-by-existence rather than evidence-to-be-read often gets caught on a follow-up question that could have been answered proactively.

Contract redlines

Legal is part of the review.

The MSA, DPA, and sub-processor terms get redlined during the review period, not after. Common sticking points include liability caps, data breach obligations, audit rights, and sub-processor change notice. Vendors with pre-negotiated enterprise paper and a published fallback DPA clear this faster than vendors that start from scratch per deal.

Risk score + sign-off

Someone owns the yes or no.

The review ends with a documented risk score and a formal sign-off from each function. In some programs the sign-off is advisory and the business owner can accept risk; in others it is binding. Either way, the audit trail becomes part of the vendor record and gets revisited at annual re-review and whenever something material changes.

Timeline and failure modes

Where reviews stall, slip, or die.

A vendor security review has predictable failure modes. The deal rarely dies on one dramatic finding; it slips on a cascade of small ones, each adding days to the clock. Revenue leaders who understand the timeline mechanics can set accurate close dates and preempt the common blockers. The six failures below are the ones most frequently cited by enterprise procurement teams when a deal slides past its original target quarter.

Missing SOC 2

No report, no deal.

The absence of a SOC 2 Type II is the single most common hard block at the enterprise tier. Reviewers cannot approve a vendor whose controls have never been independently audited. SOC 2 Type I is sometimes accepted in mid-market but almost never above. A vendor that cannot produce a current Type II report typically fails the review on day one.

Stale artifacts

Last year's report does not count.

SOC 2 reports older than fifteen months, pen tests older than twelve months, and sub-processor lists more than six months out of date all raise flags. Reviewers want to see that the vendor runs the audit cadence, not that it did it once. Stale artifacts often add a two-week pause while the vendor refreshes the document.

Sub-processor surprises

A banned vendor on the list.

Buyers often maintain their own banned or restricted sub-processor lists (jurisdictions, specific vendors, specific hosting regions). A vendor that routes data through a disallowed sub-processor fails the review until the architecture changes or the buyer grants an explicit exception. Both outcomes take weeks.

Weak IRP

No written plan, no sign-off.

A vendor without a written incident response plan, with no breach notification timeline, or with notification windows longer than the buyer's own requirement (often forty-eight to seventy-two hours) will stall. "We would handle it" is not an incident response plan. The reviewer wants a document with named roles and clock-time commitments.

Insurance gaps

Policy limits below the threshold.

Many enterprise buyers require specific cyber liability coverage, often five to ten million per occurrence depending on data volume. Vendors with lower limits, or policies that exclude a key risk category, often need to raise coverage before the deal clears. New policies can take weeks to bind.

Legal deadlock

Non-negotiable paper.

A vendor that refuses to touch the buyer's DPA, insists on arbitration in an unusual jurisdiction, or caps liability at an unacceptably low multiple will deadlock in legal review. These are often the slowest failures to unwind because they require executive air cover on both sides. Vendors with a published enterprise DPA avoid most of them.

A CRM that is ready for enterprise procurement, not scrambling for it.

Strkr publishes a trust center with current SOC 2, pen test summary, DPA, sub-processor list, incident response plan, and SLA. Pricing is public, and the feature pages show exactly what ships today. Procurement teams can self-serve the artifact bundle on day one of the review.

People also ask

Related questions.

How long does a vendor security review typically take?

Two to six weeks is the normal range. A well-prepared vendor with current SOC 2 Type II, pen test summary, DPA, and sub-processor list can clear a straightforward review in two weeks. Complex deals in regulated industries (financial services, healthcare, government) or reviews with missing artifacts routinely stretch to six weeks or more. The timeline is driven by the slowest internal reviewer on the buyer's side, not by the vendor, so escalations from sales rarely compress it.

Who runs a vendor security review on the buyer side?

Four internal functions are typically involved: information security (reviews controls and architecture), privacy or data protection (reviews data flows and subject rights handling), legal (reviews contracts, liability, and indemnification), and procurement (owns the process end to end). Each function uses its own checklist and signs off against its own standard. The business owner (the stakeholder who wants to buy) usually cannot override a security or legal objection without executive approval.

What is the difference between a security review and a security questionnaire?

A security questionnaire is a single document, usually completed by the vendor's security or GRC function, that answers the buyer's risk questions. A full vendor security review is a cross-functional process that includes the questionnaire plus artifact inspection (SOC 2, pen test, DPA, sub-processor list, incident response plan, insurance, SLA), contract redlines, risk scoring, and formal sign-off from multiple functions. The questionnaire is one input to the review, not the entire review.

Why does a buyer want a SOC 2 Type II report specifically?

SOC 2 Type II evaluates security controls over a period of time (typically six to twelve months) and includes evidence that the controls actually operated as designed. Type I only tests the design of controls at a single point in time, which is a much weaker signal. Enterprise buyers want Type II because they want evidence that the vendor runs the controls as a day-to-day program, not that it set them up for the audit. Many enterprise programs reject Type I outright.

What goes in a sub-processor list and why does it matter?

A sub-processor list names every downstream vendor the primary vendor uses to deliver the service: cloud hosting, email delivery, analytics, customer support tooling, data enrichment, telemetry, backups. GDPR requires it, and most buyers compare the list to their own approved-vendor registry. A banned sub-processor, a disallowed hosting region, or a vague "various third parties" entry will stall the review. Published, specific lists clear faster than lists disclosed only under NDA.

What is a DPA and when is one required?

A Data Processing Agreement is a contract between the buyer (the data controller) and the vendor (the data processor) that defines how personal data will be handled, protected, and returned or deleted at the end of the relationship. It is required under GDPR, UK GDPR, and most modern privacy laws whenever a vendor processes personal data on behalf of a buyer. Vendors with a published enterprise DPA that the buyer can execute without a bespoke negotiation clear this stage substantially faster.

What is a vendor trust center and does it help clear reviews faster?

A trust center is a public (sometimes NDA-gated) page where a vendor publishes its security and compliance artifacts: SOC 2 report request, pen test summary, DPA template, sub-processor list, security whitepaper, uptime history, policy documents. Yes, it helps clear reviews faster. The reviewing team can self-serve the baseline evidence instead of waiting for the vendor to pull documents together per deal, which can save a week or more off the review timeline.

What happens if a vendor fails the security review?

Three outcomes are typical. The vendor is asked to remediate specific findings (new pen test, raised insurance limits, revised DPA, added control) and resubmit, which adds weeks to the deal. The buyer accepts a documented risk exception with executive sign-off, usually with compensating controls like reduced data scope or shorter contract term. Or the deal is killed. Which outcome happens depends on the severity of the findings, how badly the business owner wants the tool, and how senior the risk-acceptance authority is.

Try it free. Bring your team next week.

No sales call, no migration consultant, no four-month implementation. Enter your card, get 14 days of the full Pro tier, cancel any time before day 14 with zero charge. Spin up a workspace, import your CSV, and have something useful before lunch.