Solutions

Preconfigured Vendor Security Questionnaire

Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.

TL;DR

A vendor security questionnaire collects a third party's security practices in a structured way, before or during the contractual relationship. Sent by email as a spreadsheet, it produces answers that cannot be compared or traced. CISAPP turns it into a campaign: preconfigured library, answer reuse on the vendor side, reminder tracking and direct feed into the risk register.

What is a vendor security questionnaire for?

A security questionnaire collects a third party's security practices in a structured way: governance, access, encryption, continuity, subcontracting, compliance. It is the declarative building block of an assessment — necessary, never sufficient on its own.

CISAPP replaces questionnaires sent by email with structured campaigns built on a library of preconfigured templates (ISO 27001, NIS2, DORA, GDPR).

What the questionnaire covers, and what it does not

How declarative questionnaires and technical findings complement each other
DimensionQuestionnaireExternal technical score
NatureDeclarative, a vendor commitmentObserved, measured from outside
CoverageOrganisation, processes, contractsPublicly exposed configuration
FreshnessDate of the answerDate of the last scan
Can contradict the otherYes — and that is the useful signalYes
Effort for the vendorHighNone

On the company side and the vendor side

Company side: campaigns launched from the library, real-time tracking of response rates and reminders, complemented by the SecOps score to prioritise reviews.

Vendor side: one workspace to answer from whatever the customer, reuse of answers and evidence already provided, and visibility on the score shared with customers.

See also the vendor security score and the TPRM SaaS platform.

FAQ

It is a structured set of questions sent to a third party to document its security practices: governance, access management, encryption, continuity, subcontracting, compliance. It is the declarative building block of the assessment, to be completed by evidence and technical findings.

Sources

  1. ISO/IEC 27001:2022, control A.5.20 — security requirements in supplier agreements — ISO, 2022-10-25

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account