[{"data":1,"prerenderedAt":314},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"solution-en-vendor-security-questionnaire":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":31,"entities":264,"extension":267,"faq":268,"keywords":287,"meta":292,"navigation":293,"ogImage":294,"path":30,"persona":295,"publishedAt":294,"regulation":294,"relatedFeatures":296,"relatedPages":299,"seo":302,"shortTitle":29,"slug":303,"sources":304,"stem":310,"tldr":311,"updatedAt":312,"__hash__":313},"solutions_en\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire.md","Preconfigured Vendor Security Questionnaire | CISAPP","CISAPP",{"type":108,"value":109,"toc":257},"minimark",[110,115,129,132,151,155,237,241,244,247],[111,112,114],"h2",{"id":113},"what-is-a-vendor-security-questionnaire-for","What is a vendor security questionnaire for?",[116,117,118,128],"p",{},[119,120,121,122,127],"strong",{},"A ",[123,124,126],"a",{"href":125},"\u002Fen\u002Fglossary\u002Fsecurity-questionnaire","security questionnaire"," collects a third party's security practices in a structured way: governance, access, encryption, continuity, subcontracting, compliance."," It is the declarative building block of an assessment — necessary, never sufficient on its own.",[116,130,131],{},"CISAPP replaces questionnaires sent by email with structured campaigns built on a library of preconfigured templates (ISO 27001, NIS2, DORA, GDPR).",[133,134,135],"key-takeaways",{},[136,137,138,142,145,148],"ul",{},[139,140,141],"li",{},"Questionnaire length should follow the criticality of the third party, not the reverse.",[139,143,144],{},"Existing evidence (certification, audit report, Trust Center) can replace whole blocks of questions.",[139,146,147],{},"A missing answer is a finding, not a gap to ignore.",[139,149,150],{},"Declarative answers must be cross-checked against external technical findings.",[111,152,154],{"id":153},"what-the-questionnaire-covers-and-what-it-does-not","What the questionnaire covers, and what it does not",[156,157,159],"comparison-table",{"caption":158},"How declarative questionnaires and technical findings complement each other",[160,161,162,178],"table",{},[163,164,165],"thead",{},[166,167,168,172,175],"tr",{},[169,170,171],"th",{},"Dimension",[169,173,174],{},"Questionnaire",[169,176,177],{},"External technical score",[179,180,181,193,204,215,226],"tbody",{},[166,182,183,187,190],{},[184,185,186],"td",{},"Nature",[184,188,189],{},"Declarative, a vendor commitment",[184,191,192],{},"Observed, measured from outside",[166,194,195,198,201],{},[184,196,197],{},"Coverage",[184,199,200],{},"Organisation, processes, contracts",[184,202,203],{},"Publicly exposed configuration",[166,205,206,209,212],{},[184,207,208],{},"Freshness",[184,210,211],{},"Date of the answer",[184,213,214],{},"Date of the last scan",[166,216,217,220,223],{},[184,218,219],{},"Can contradict the other",[184,221,222],{},"Yes — and that is the useful signal",[184,224,225],{},"Yes",[166,227,228,231,234],{},[184,229,230],{},"Effort for the vendor",[184,232,233],{},"High",[184,235,236],{},"None",[111,238,240],{"id":239},"on-the-company-side-and-the-vendor-side","On the company side and the vendor side",[116,242,243],{},"Company side: campaigns launched from the library, real-time tracking of response rates and reminders, complemented by the SecOps score to prioritise reviews.",[116,245,246],{},"Vendor side: one workspace to answer from whatever the customer, reuse of answers and evidence already provided, and visibility on the score shared with customers.",[116,248,249,250,253,254,256],{},"See also the ",[123,251,252],{"href":34},"vendor security score"," and the ",[123,255,21],{"href":22}," platform.",{"title":258,"searchDepth":259,"depth":259,"links":260},"",2,[261,262,263],{"id":113,"depth":259,"text":114},{"id":153,"depth":259,"text":154},{"id":239,"depth":259,"text":240},[265,266],"Security questionnaire","Trust Center","md",[269,272,275,278,281,284],{"q":270,"a":271},"What is a vendor security questionnaire?","It is a structured set of questions sent to a third party to document its security practices: governance, access management, encryption, continuity, subcontracting, compliance. It is the declarative building block of the assessment, to be completed by evidence and technical findings.",{"q":273,"a":274},"Are the questionnaires customisable?","You start from a preconfigured library (ISO 27001, NIS2, DORA, GDPR) and adapt it to each vendor's risk profile — questionnaire length should follow the third party's criticality.",{"q":276,"a":277},"How does the vendor respond?","The vendor answers from its own CISAPP workspace, can reuse previous answers from one customer to the next and share certifications directly, instead of starting from a blank file.",{"q":279,"a":280},"How do you reduce questionnaire fatigue?","By sizing length to criticality, accepting existing evidence (certification, audit report, [Trust Center](\u002Fen\u002Fglossary\u002Ftrust-center)) in place of questions, and letting vendors reuse answers. See the guide on [security questionnaire fatigue](\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue).",{"q":282,"a":283},"Is a declarative questionnaire enough?","No. It documents what the vendor states it does. It must be cross-checked against evidence (certificates, reports) and external findings — that is the role of the technical [posture score](\u002Fen\u002Fglossary\u002Fsecurity-posture-score).",{"q":285,"a":286},"What do you do with incomplete answers?","Unanswered questions are findings in their own right: they feed the risk register and trigger a reminder or an evidence request, rather than being ignored when the campaign closes.",[288,289,290,291],"vendor security questionnaire","vendor cybersecurity questionnaire","vendor assessment campaign","vendor security audit",{},true,null,"both",[297,298,33],"Assessment campaigns","Questionnaire library",[300,301],"vendor-security-score","tprm-saas",{"title":105,"description":31},"vendor-security-questionnaire",[305],{"label":306,"url":307,"publisher":308,"date":309},"ISO\u002FIEC 27001:2022, control A.5.20 — security requirements in supplier agreements","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fsolutions\u002Fvendor-security-questionnaire","A vendor security questionnaire collects a third party's security practices in a structured way, before or during the contractual relationship. Sent by email as a spreadsheet, it produces answers that cannot be compared or traced. CISAPP turns it into a campaign: preconfigured library, answer reuse on the vendor side, reminder tracking and direct feed into the risk register.","2026-08-16","uLyTiBoPIYUXEE0-b8Nu8L8UdxHzUXGY-WGNCC95CnU",1791391139157]