GlossaryCompliance operations

Security questionnaire

Short answer

A security questionnaire is a set of questions a company sends to a supplier to assess how it protects data and systems before signing or renewing a contract. Answering them well, quickly and consistently has become part of selling to larger customers.

What they ask

Questions usually cover policies and governance, certifications, access control and MFA, encryption, backups and business continuity, incident response, vulnerability management and penetration testing, employee training, sub processors and data location. They range from a dozen questions to several hundred.

Common formats

Many customers use their own spreadsheets or portals. Standard formats also exist, such as the SIG questionnaire from Shared Assessments and the CAIQ from the Cloud Security Alliance. In some sectors a shared assessment replaces individual questionnaires, as TISAX does in automotive.

Answering efficiently

Companies that receive many questionnaires keep a library of approved answers, a set of evidence ready to share (policies, certificates, pentest summaries) and often a trust center page where customers can find it. Certifications such as ISO 27001 or a SOC 2 report answer many questions at once. Answers must be accurate, because they often become contractual commitments.

The buyer's side

For the company sending them, questionnaires are a core tool of third party risk management. Questions should be proportionate to the supplier's risk, and answers should be checked against evidence, not just filed.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub