SIG Core
SIG Core is a standardized questionnaire used to gather detailed information about a third-party service provider's security and risk controls. It is the more comprehensive version in the SIG family and is typically used for vendors that handle sensitive or regulated information or otherwise pose higher risk. Organizations send it during due diligence to understand how a provider manages risk across many different areas.
SIG Core is a standardized assessment questionnaire maintained under the Shared Assessments program, designed to collect information from third-party service providers across multiple risk domains. It represents the more extensive tier of the SIG questionnaire family (contrasted with the shorter SIG Lite), containing a broad library of questions covering controls and definitions, and is generally recommended for higher-risk third parties, including those that store or manage highly sensitive or regulated information such as personal data. As a self-reported instrument, SIG Core supports information gathering during onboarding and periodic reassessment but does not, on its own, constitute independent verification of a provider's controls, nor does completion confer any certification or compliance guarantee; findings typically require corroboration (for example, through attestations, audit reports, or independent testing). The exact number of risk domains and questions varies by release version, so practitioners should confirm the domain and question counts against the specific SIG content version in use rather than relying on a fixed figure.
Why it matters
Higher-risk third parties, particularly those that store, process, or manage highly sensitive or regulated information such as personal data, often warrant a deeper level of scrutiny than a lightweight screening can provide. SIG Core addresses this need by offering a comprehensive, industry-standard set of questions spanning multiple risk domains, giving assessing organizations a structured and repeatable way to understand how a provider manages its controls. Because it is standardized under the Shared Assessments program, it also reduces the friction of every buyer designing bespoke questionnaires and every provider answering slightly different versions of the same question.
That said, SIG Core's value is bounded by what it actually is: a self-reported information-gathering instrument. Completion does not verify that the described controls exist or operate effectively, nor does it confer any certification or compliance status. Findings typically need corroboration through attestations, independent audit reports, or direct testing before an organization can rely on them for a risk decision. Treating a completed SIG Core as evidence of assurance rather than as a starting point for validation is a common and consequential mistake.
Its usefulness is also time-bound. A SIG Core response captures a point-in-time picture that can become stale as a provider's environment, ownership, subcontractors, or control posture change. In many programs it supports both onboarding due diligence and periodic reassessment, but it is not a substitute for ongoing monitoring, and it primarily illuminates the direct third party rather than fourth-party or Nth-party dependencies further down the chain.
Who it's relevant to
Inside SIG Core
Common questions
Answers to the questions practitioners most commonly ask about SIG Core.
