Guide · Assessment

The security questionnaire, for both sides of it.

Assessment · 9 min read · Updated July 2026

If you buy software, you send them. If you sell it, you answer them. The security questionnaire is the workhorse of third-party due diligence — and the single biggest source of friction in it. This guide explains what these questionnaires are, the standard formats you'll meet, and how both buyers and vendors can spend far less time on them without learning less.

In one sentence

A security questionnaire is a structured set of questions a buyer sends a vendor to assess how that vendor protects data and manages security and compliance risk — a core step in third-party risk management due diligence.

What a security questionnaire is

When you hand a vendor access to data, systems, or facilities, you need evidence that they'll protect what they hold. The questionnaire is how buyers gather that evidence at scale. A typical one asks about access control and authentication, encryption in transit and at rest, secure development, vulnerability management, incident response, business continuity, personnel security, sub-processors, and certifications such as SOC 2 or ISO 27001.

It sits in the assessment stage of the vendor lifecycle — after you've discovered and tiered a vendor, before you contract. Done well, it produces the facts a risk decision rests on. Done poorly, it produces a 300-row spreadsheet nobody reads and a false sense of assurance.

SIG, CAIQ, and the common formats

You'll meet a mix of standardized and bespoke questionnaires:

  • SIG (Standardized Information Gathering). From Shared Assessments — a broad, configurable question set spanning many risk domains, issued as SIG Core and SIG Lite for different depths. Widely used across industries.
  • CAIQ (Consensus Assessments Initiative Questionnaire). From the Cloud Security Alliance — focused on cloud service providers and mapped to the Cloud Controls Matrix (CCM). If you sell cloud software, you will see this one.
  • Framework-aligned sets. Questionnaires built directly on ISO 27001 Annex A, NIST CSF, or SOC 2 Trust Services Criteria.
  • Bespoke questionnaires. A buyer's own form, often assembled from all of the above plus company-specific and regulatory questions. These are the least predictable and the most time-consuming to answer.

Standardization helps, but it hasn't ended the problem: buyers still customize, regulated industries add their own, and a vendor selling into many sectors ends up answering the same underlying question a dozen different ways.

For buyers: getting a real answer

The instinct is to send every vendor the most thorough questionnaire you have, to be safe. It backfires. A maximal form sent to a low-exposure vendor buries the few answers that matter under hundreds that don't, delays onboarding, and trains vendors to autopilot through your questions.

The better approach is to scope depth to the vendor's tier — which you set by exposure, not by spend. A vendor that holds regulated customer data and has standing network access earns a full-depth questionnaire and evidence review; a print shop with no material access earns a short attestation. This is the core idea behind inside-out classification: let what a vendor holds of yours decide how hard you look. It also means you accept existing evidence — a current SOC 2 report, an ISO certificate, a published trust center — in place of re-asking questions those documents already answer.

Where personal data is involved, the questionnaire also feeds your obligations under GDPR to perform due diligence on processors — so the answers aren't just informative, they're part of your compliance record.

For vendors: answering once

If you're on the receiving end, inbound questionnaires can consume real headcount. Three moves cut the cost dramatically:

  • Build a reusable answer library. Answer each underlying question once, well, and store it. When the next questionnaire arrives — phrased differently — you're mapping, not re-writing. The library becomes an asset that compounds.
  • Publish a trust center. A public (or NDA-gated) page with your certifications, sub-processor list, security documentation, and standard answers lets many buyers self-serve without sending a form at all. It's the highest-leverage way to reduce inbound questionnaires.
  • Lead with evidence. Offer your SOC 2 or ISO report and CAIQ up front. A buyer with strong existing evidence in hand often shortens or skips their bespoke form.
Answer once, keep it
Polestead's Trust Center is free at full depth.

NDA-gated documents, sub-processor lists, a reusable answer library, custom domain, and unlimited imports — with no paid gates. Answer once, and the library is yours to keep.

See the Trust Center →

The questionnaire-fatigue problem

Both sides feel it. Buyers can't read every answer to every form with equal attention, so signal drowns in volume. Vendors face a steady stream of near-identical forms and start pattern-matching answers rather than thinking. The result is a ritual that consumes time on both sides while producing less assurance than either party believes.

The way out isn't a bigger or more standardized form — it's letting context decide depth. When the buyer's own exposure sets the tier, and tier sets how much you ask, the heavy scrutiny lands only where it's warranted and the long tail gets a proportionate check. The questionnaire stops being a tax on every relationship and becomes a targeted instrument again. That shift — from a fixed form for everyone to contextual assurance scaled by risk — is the direction the discipline is moving, and it's the principle Polestead is built on.

FAQ

Common questions.

What is a security questionnaire?+

A structured set of questions a buyer sends a vendor to assess how that vendor protects data and manages security and compliance risk — covering access control, encryption, incident response, certifications, and more. It's a core due-diligence step in TPRM.

What's the difference between SIG and CAIQ?+

SIG (Shared Assessments) is a broad, configurable questionnaire across many risk domains. CAIQ (Cloud Security Alliance) is focused on cloud providers and maps to the Cloud Controls Matrix. SIG is broader; CAIQ is cloud-specific.

How do we reduce questionnaire fatigue?+

Scope depth to the vendor's risk tier instead of sending everyone the same long form, build a reusable answer library, and accept existing evidence like SOC 2 reports or a trust center. Let context decide depth.

Can a trust center replace questionnaires?+

Often, partly. A trust center lets a vendor publish documentation and answers once so many buyers self-serve without sending a form. It cuts inbound questionnaires substantially, though high-tier or regulated buyers may still require a specific one.

Keep reading
Third-party risk management
The full lifecycle this sits inside.
Trust Center →
Answer once, free at full depth.
Inside-out vs outside-in
Why context should set depth.