Glossary
Security questionnaire
A security questionnaire is a structured set of questions sent to a vendor to document its security, continuity and compliance practices, and to objectify the gap between those practices and the requirements of the organisation assessing it.
What a questionnaire proves — and does not
A questionnaire is declarative. It establishes what the vendor claims to do, on a given date, and mainly serves to reveal obvious gaps and topics to investigate. Evidential value comes from the attachments — a valid ISO 27001 certificate, a SOC 2 report, a penetration test result, a backup policy — not from ticked boxes.
Hence two rules: always request evidence for structural questions, and date every answer so a three-year-old questionnaire is not replayed indefinitely.
The cost on the vendor side
A SaaS vendor answers dozens of different questionnaires a year asking the same questions in incompatible formats. This fatigue degrades answer quality: copy-paste, approximations, delays. Two remedies: start from a standard baseline (vendor security questionnaire) rather than an in-house format, and accept an up-to-date Trust Center as partial substitution. See also the questionnaire fatigue guide.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours