Skip to main content
Category: Assessment and Due Diligence

Security Questionnaire

Also known as: Vendor Security Questionnaire, Security Compliance Questionnaire, Security Assessment Questionnaire
Simply put

A security questionnaire is a structured set of questions that an organization sends to a vendor to learn how that vendor protects information and manages security. The vendor's answers help the buyer decide whether the vendor's security practices are acceptable before or during a business relationship. Because responses are typically self-reported by the vendor, a questionnaire reflects what the vendor states rather than what has been independently verified.

Formal definition

A security questionnaire is a standardized instrument used within third-party risk management to elicit a vendor's self-attested description of its security posture, controls, and practices, often as part of onboarding due diligence or periodic reassessment. Its scope is generally limited to information and cybersecurity matters and does not, on its own, address financial, operational, geopolitical, or ESG risk unless explicitly extended. As a self-reported, typically point-in-time artifact, a completed questionnaire constitutes an attestation rather than independent verification; its assurance value depends on corroboration through evidence review, third-party audit reports, or ongoing monitoring, and its accuracy can degrade between assessment cycles. Questionnaires are frequently distributed as a buyer's custom list of questions or via standardized formats, and the depth applied commonly varies by risk tier.

Why it matters

Security questionnaires are one of the most common instruments organizations use to gain visibility into a vendor's security practices before entering or continuing a business relationship. Because most buyers cannot conduct hands-on inspections of every vendor's environment, the questionnaire provides a scalable, structured way to gather information about how a third party protects data and manages security controls. In many programs, questionnaire responses form the initial basis for deciding whether a vendor's posture is acceptable and for tiering vendors according to the sensitivity of the data or systems involved.

The central limitation is that a completed questionnaire is a self-reported attestation, not independent verification. It reflects what the vendor states about its practices rather than what has been observed or tested by an outside party. Its assurance value depends on corroboration through evidence review, third-party audit reports, or ongoing monitoring. Treating a questionnaire response as confirmed fact, rather than as a claim to be validated where risk warrants, is a common source of misplaced confidence.

A further limitation is that questionnaires are typically point-in-time artifacts. A response captured at onboarding describes the vendor's stated posture on the date it was completed, and its accuracy can degrade between assessment cycles as the vendor's environment, controls, or personnel change. In addition, the scope of a security questionnaire is generally confined to information and cybersecurity matters; on its own it does not address financial, operational, geopolitical, or ESG risk unless the instrument is explicitly extended to cover them.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams typically own the distribution, review, and scoring of security questionnaires as part of onboarding and periodic reassessment. They rely on the responses to tier vendors and inform acceptance decisions, and they are responsible for recognizing that self-reported answers may need corroboration through evidence review or third-party audit reports before being treated as reliable.
Information Security and Cybersecurity Teams
Security teams often design or review the technical questions and interpret vendor responses about controls and practices. Because a questionnaire's scope is generally confined to information and cybersecurity matters, these teams are well positioned to judge whether stated controls are adequate and where independent verification or ongoing monitoring is warranted.
Procurement and Sourcing Professionals
Procurement teams frequently trigger questionnaires as part of the sourcing and onboarding process and coordinate the vendor's completion of them. They benefit from understanding that a completed questionnaire is a point-in-time attestation rather than a confirmed assurance, and that it does not, on its own, address financial, operational, geopolitical, or ESG risk unless explicitly extended.
Vendors and Service Providers Responding to Assessments
Vendors on the receiving end complete these questionnaires to demonstrate their security practices to prospective and existing clients. They should be aware that their responses constitute attestations that buyers may seek to corroborate, and that they may face varying custom and standardized formats with differing depth depending on how the buyer tiers the engagement.
Compliance and Audit Functions
Compliance and audit personnel use questionnaire results as one input into due diligence records and may reconcile stated practices against supporting evidence or third-party audit reports. They play a role in distinguishing what a vendor has attested from what has been independently verified, and in ensuring responses do not become stale between assessment cycles.

Inside Security Questionnaire

Information Security Control Domains
Structured sections covering areas such as access management, data protection, network security, encryption, incident response, and vulnerability management, typically mapped to a recognized control set. These domains address information security posture but generally do not extend to financial, operational, geopolitical, or ESG risk unless supplemented by additional modules.
Standardized Question Sets
Reusable question banks such as those found in shared assessment approaches (for example SIG questionnaires), often tiered by depth so that a shorter set applies to lower-risk relationships and a fuller set applies to higher-risk ones. The specific scope varies by version and by how the sourcing organization tailors it.
Self-Attested Responses
Answers provided by the vendor about its own controls, typically in the form of yes/no confirmations, narrative explanations, or references to supporting evidence. These are self-reported assertions and, absent independent validation, are not equivalent to verified findings.
Evidence and Documentation Requests
Fields prompting the respondent to attach or reference supporting artifacts such as policies, prior audit reports, or third-party assurance documents. The presence of a referenced document does not by itself confirm that the referenced control operates effectively.
Scoping and Applicability Metadata
Contextual information such as the nature of the service, the data types involved, and the risk tier assigned to the relationship, which determines which questions apply and how responses are weighted or scored within a broader assessment process.

Common questions

Answers to the questions practitioners most commonly ask about Security Questionnaire.

Does a completed security questionnaire verify a vendor's actual security posture?
No. A security questionnaire is typically a self-reported attestation, not an independent verification. The responses reflect what the vendor asserts about its controls, but they are not validated by an external party unless paired with independent evidence such as an audit report, penetration test results, or on-site assessment. Treating questionnaire responses as verified fact is a common mistake; in many programs they serve as a starting point for risk-tiering and follow-up rather than as proof of control effectiveness.
Is a security questionnaire the same thing as a risk assessment?
No. A questionnaire is one input into a risk assessment, not the assessment itself. The risk assessment is the broader analytical process of evaluating inherent risk, weighing the evidence gathered (including but not limited to questionnaire responses), and determining residual risk relative to the organization's risk appetite. A questionnaire that is scored and filed without that analysis has collected information but has not produced an assessment.
When in the vendor lifecycle should a security questionnaire be issued?
Questionnaires are most commonly issued during onboarding or pre-contract due diligence, but a point-in-time questionnaire becomes stale as a vendor's environment changes. Many programs reissue questionnaires on a cadence tied to the vendor's risk tier, or trigger reassessment on events such as a material change in services, a reported incident, or contract renewal. On its own, an onboarding questionnaire does not cover ongoing monitoring.
Should the same questionnaire be sent to every vendor?
Not typically. A single exhaustive questionnaire sent to all vendors tends to burden low-risk suppliers while under-scoping high-risk ones. Many programs tier questionnaires by inherent risk, data sensitivity, or the nature of the service, using a shorter set for lower-tier vendors and a more detailed set for those handling sensitive data or critical functions. Standardized questionnaire sets, such as tiered SIG offerings, are often used to align scope with risk.
How should questionnaire responses be paired with supporting evidence?
Because responses are self-reported, many programs request corroborating artifacts for higher-risk domains or higher-tier vendors, such as SOC 2 reports, certification documentation, policy excerpts, or test results. A SOC 2 report is an attestation report rather than a certification, so it should be read for scope and findings rather than treated as a pass mark. Requiring evidence for the assertions that matter most helps close the gap between what is claimed and what can be substantiated.
What are the practical limitations to plan for when relying on questionnaires?
Key limitations include the point-in-time nature of responses, reliance on vendor self-reporting without independent validation, and limited visibility beyond the direct third party into fourth-party or Nth-party dependencies. Questionnaires also tend to focus on information security and may not address financial, operational, geopolitical, or ESG risk unless expanded. Programs often mitigate these gaps by combining questionnaires with continuous monitoring, contractual requirements, and evidence review rather than relying on the questionnaire alone.

Common misconceptions

A completed security questionnaire is the same as a risk assessment.
A questionnaire is an input to a risk assessment, not the assessment itself. The assessment is the analytical process of evaluating the responses, evidence, and context to reach a risk conclusion; the questionnaire only gathers self-reported information that feeds that process.
Questionnaire responses provide independent verification of a vendor's controls.
Responses are typically self-attested by the vendor and represent assertions rather than independently validated facts. An attestation is not verification, and confirming control effectiveness generally requires corroborating evidence, independent testing, or third-party assurance.
A questionnaire captures a vendor's overall risk profile.
Most security questionnaires are scoped to information security controls and do not, on their own, address financial, operational, geopolitical, or ESG risk. They also reflect a point in time and can become stale as the vendor's environment changes.

Best practices

Tier questionnaires by the risk level of the relationship, using shorter sets for lower-risk vendors and fuller sets for higher-risk ones, rather than applying a single template universally.
Treat questionnaire responses as self-attested assertions and validate high-impact answers through supporting evidence, independent assurance reports, or targeted testing where the risk tier warrants it.
Use the questionnaire as one input to the broader risk assessment rather than as the assessment itself, combining it with other sources and analytical judgment.
Recognize the point-in-time nature of questionnaire responses and pair onboarding questionnaires with ongoing monitoring so conclusions do not become stale.
Clearly document the scope covered, noting where the questionnaire addresses information security but not financial, operational, geopolitical, or ESG dimensions, so gaps are visible and can be addressed separately.
Where relevant, align question sets to recognized frameworks or shared assessment approaches, while avoiding any implication that a completed questionnaire confers certification or compliance guarantees.
Promotional banner for the Penetration Report Template Kit