Security Questionnaire
A security questionnaire is a structured set of questions that an organization sends to a vendor to learn how that vendor protects information and manages security. The vendor's answers help the buyer decide whether the vendor's security practices are acceptable before or during a business relationship. Because responses are typically self-reported by the vendor, a questionnaire reflects what the vendor states rather than what has been independently verified.
A security questionnaire is a standardized instrument used within third-party risk management to elicit a vendor's self-attested description of its security posture, controls, and practices, often as part of onboarding due diligence or periodic reassessment. Its scope is generally limited to information and cybersecurity matters and does not, on its own, address financial, operational, geopolitical, or ESG risk unless explicitly extended. As a self-reported, typically point-in-time artifact, a completed questionnaire constitutes an attestation rather than independent verification; its assurance value depends on corroboration through evidence review, third-party audit reports, or ongoing monitoring, and its accuracy can degrade between assessment cycles. Questionnaires are frequently distributed as a buyer's custom list of questions or via standardized formats, and the depth applied commonly varies by risk tier.
Why it matters
Security questionnaires are one of the most common instruments organizations use to gain visibility into a vendor's security practices before entering or continuing a business relationship. Because most buyers cannot conduct hands-on inspections of every vendor's environment, the questionnaire provides a scalable, structured way to gather information about how a third party protects data and manages security controls. In many programs, questionnaire responses form the initial basis for deciding whether a vendor's posture is acceptable and for tiering vendors according to the sensitivity of the data or systems involved.
The central limitation is that a completed questionnaire is a self-reported attestation, not independent verification. It reflects what the vendor states about its practices rather than what has been observed or tested by an outside party. Its assurance value depends on corroboration through evidence review, third-party audit reports, or ongoing monitoring. Treating a questionnaire response as confirmed fact, rather than as a claim to be validated where risk warrants, is a common source of misplaced confidence.
A further limitation is that questionnaires are typically point-in-time artifacts. A response captured at onboarding describes the vendor's stated posture on the date it was completed, and its accuracy can degrade between assessment cycles as the vendor's environment, controls, or personnel change. In addition, the scope of a security questionnaire is generally confined to information and cybersecurity matters; on its own it does not address financial, operational, geopolitical, or ESG risk unless the instrument is explicitly extended to cover them.
Who it's relevant to
Inside Security Questionnaire
Common questions
Answers to the questions practitioners most commonly ask about Security Questionnaire.