Solutions
Preconfigured Vendor Security Questionnaire
Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.
TL;DR
A vendor security questionnaire collects a third party's security practices in a structured way, before or during the contractual relationship. Sent by email as a spreadsheet, it produces answers that cannot be compared or traced. CISAPP turns it into a campaign: preconfigured library, answer reuse on the vendor side, reminder tracking and direct feed into the risk register.
What is a vendor security questionnaire for?
A security questionnaire collects a third party's security practices in a structured way: governance, access, encryption, continuity, subcontracting, compliance. It is the declarative building block of an assessment — necessary, never sufficient on its own.
CISAPP replaces questionnaires sent by email with structured campaigns built on a library of preconfigured templates (ISO 27001, NIS2, DORA, GDPR).
What the questionnaire covers, and what it does not
| Dimension | Questionnaire | External technical score |
|---|---|---|
| Nature | Declarative, a vendor commitment | Observed, measured from outside |
| Coverage | Organisation, processes, contracts | Publicly exposed configuration |
| Freshness | Date of the answer | Date of the last scan |
| Can contradict the other | Yes — and that is the useful signal | Yes |
| Effort for the vendor | High | None |
On the company side and the vendor side
Company side: campaigns launched from the library, real-time tracking of response rates and reminders, complemented by the SecOps score to prioritise reviews.
Vendor side: one workspace to answer from whatever the customer, reuse of answers and evidence already provided, and visibility on the score shared with customers.
See also the vendor security score and the TPRM SaaS platform.
FAQ
It is a structured set of questions sent to a third party to document its security practices: governance, access management, encryption, continuity, subcontracting, compliance. It is the declarative building block of the assessment, to be completed by evidence and technical findings.
Sources
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours