Glossary

Security questionnaire

A security questionnaire is a structured set of questions sent to a vendor to document its security, continuity and compliance practices, and to objectify the gap between those practices and the requirements of the organisation assessing it.

What a questionnaire proves — and does not

A questionnaire is declarative. It establishes what the vendor claims to do, on a given date, and mainly serves to reveal obvious gaps and topics to investigate. Evidential value comes from the attachments — a valid ISO 27001 certificate, a SOC 2 report, a penetration test result, a backup policy — not from ticked boxes.

Hence two rules: always request evidence for structural questions, and date every answer so a three-year-old questionnaire is not replayed indefinitely.

The cost on the vendor side

A SaaS vendor answers dozens of different questionnaires a year asking the same questions in incompatible formats. This fatigue degrades answer quality: copy-paste, approximations, delays. Two remedies: start from a standard baseline (vendor security questionnaire) rather than an in-house format, and accept an up-to-date Trust Center as partial substitution. See also the questionnaire fatigue guide.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account