We use cookies
We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.

By clicking "Accept", you agree to our use of cookies.

How to Answer a Security Questionnaire (With Template).

A seller's guide to answering vendor security questionnaires: the common formats, an eight-step process, a copyable template and how to keep security review from stalling the deal.

Updated OCT 202613 min read

The demo went well, the champion is on board, and then a spreadsheet arrives from someone you have never met: 200 rows on encryption, access control, sub-processors and incident response, due in ten business days. That is the security questionnaire. Nobody on the buying side will sign until their security team is satisfied, so this file often decides your close date more than the demo did.

This guide is for the seller with the questionnaire open in another tab. It covers the formats you will see, a step-by-step way to answer, a copyable template of the question areas, and how to keep the review from stalling the deal.

What is a security questionnaire?

A security questionnaire is a structured set of questions a buyer sends a vendor to check how the vendor protects data, systems and access before signing. It is part of the buyer's third-party risk process: they are deciding whether letting your product touch their data adds risk they can accept.

Who sends it

  • Information security or GRC (governance, risk and compliance): owns the review and the final risk rating.
  • IT: cares about SSO, provisioning, integrations and where the product sits in their stack.
  • Procurement or vendor management: often the one who actually sends the file and tracks the deadline.
  • Legal and privacy: join when personal data is involved, usually alongside the DPA.

The person who sends it is rarely the person who decides. Find out who signs off on the risk, because that is who your answers are written for.

When it shows up

Most sellers meet it late, after the business decision and right before contract. That timing is the problem. A review that takes three weeks is fine in evaluation and a disaster in the last week of the quarter.

What the buyer is trying to learn

Three things: what data you will hold, how you protect it, and what happens when something goes wrong. Every question on the list is a version of one of those.

Common security questionnaire formats

Most questionnaires are either a standard framework, sometimes trimmed by the buyer, or the buyer's own list. Knowing which one you have tells you how much of your existing work you can reuse.

Format

Publisher

Who uses it

Size

SIG Lite

Shared Assessments

Buyers who need a basic, high-level view of a vendor's controls

Short of the SIG family. The 2023 edition had 126 questions (Shared Assessments).

SIG Core

Shared Assessments

Buyers assessing vendors that hold highly sensitive or regulated data

Long. The 2023 edition had 855 questions (Shared Assessments).

CAIQ

Cloud Security Alliance

Buyers of cloud and SaaS services

Yes/No questions mapped to CSA's Cloud Controls Matrix. Vendors can publish a completed CAIQ to the CSA STAR Registry.

VSA Core / VSA Full

Vendor Security Alliance

Buyers who want a free, standard alternative to a custom list; downloadable from the VSA's site

Core covers the most critical security questions plus privacy; Full is the classic, deeper security questionnaire.

HECVAT

EDUCAUSE

Colleges and universities

HECVAT 4 rolls the old Full, Lite and On-Prem versions into one file, with privacy and AI questions.

Custom spreadsheet

The buyer

Large enterprises with their own risk team

Anywhere from a few dozen rows to several hundred.

Portal-based review

The buyer's risk platform

Companies running third-party risk in dedicated software

Same questions, but you answer inside their portal and upload evidence there.

Two things to know about the standard ones. The SIG is scoped: the buyer picks the risk domains, so two "SIG Core" files can look different. And all of them get revised, so check which edition you were sent before reusing last year's answers.

How to answer a security questionnaire

1. Find the owner on both sides

On your side, one person owns the questionnaire end to end. In a small company that is often the sales engineer or the CTO; in a larger one, a security or trust team. On their side, get the name of the reviewer, not just the procurement contact who forwarded it. Ask your champion: "Who on your security team will review this, and can I have a 15 minute call with them?"

2. Ask for the deadline and the format

Before you answer row one, ask three questions:

  • When do you need it back, and when does your team need to finish its review?
  • Will you accept a completed SIG, CAIQ or our security pack instead of, or alongside, this file?
  • Which sections matter most for how you plan to use the product?

The second question is worth asking every time. Some teams will accept a standard document and skip their own spreadsheet.

3. Start from your answer library

Do not start from a blank sheet. Pull the closest previous questionnaire, your last SIG or CAIQ, your policies and your SOC 2 report, and answer from those. If you do not have a library yet, this questionnaire is the first entry in it (see the answer library section below).

4. Answer the question asked

Security reviewers read hundreds of these. They want a direct answer, the control that backs it, and where to verify it. They do not want marketing copy.

  • Weak: "We take security seriously and use industry-leading encryption."
  • Strong: "Yes. Customer data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. See section 3 of our Information Security Policy."

Keep answers consistent. Reviewers compare your answer on access reviews in section 4 with your answer in section 11.

5. Attach evidence

Answers carry more weight with proof behind them. The usual evidence pack:

  • SOC 2 Type II report or ISO 27001 certificate, if you have one, shared under NDA
  • Summary letter from your most recent penetration test
  • Information security, access control, incident response and business continuity policies
  • Sub-processor list and data processing agreement
  • Architecture or data flow diagram

6. Flag partial answers honestly

You will hit questions where the true answer is "not yet" or "partly". Do not round up to "Yes". Write what you do today, the compensating control, and a date for the gap.

Example: "Partial. We do not yet run a formal annual access review. Today, access to production is limited to four named engineers through SSO with MFA, and every grant is logged. A quarterly access review starts in Q1 2027."

An honest partial with a plan passes more reviews than a "Yes" that falls apart on the follow-up call.

7. Have one reviewer read it all

One person who knows the product reads every answer before it goes out. They catch contradictions, outdated claims and answers that promise more than you do.

8. Send it back with a cover note

Do not just attach the file. Send a short note: what is attached, which answers are partial and why, what evidence is shared under NDA, and an offer of a call with your security lead. Then ask when they expect to finish the review.

Security questionnaire template

Most questionnaires, standard or custom, come back to the same areas. Use this table to build your first answer set or to check a draft before it goes out.

Question area

Typical questions

What a good answer includes

Access control

Who can access customer data? Is MFA enforced? How often are access rights reviewed?

Role-based access, SSO with MFA for staff, least privilege, how access is granted and revoked, review frequency

Data encryption

Is data encrypted at rest and in transit? Who manages the keys?

Algorithms and protocol versions, key management approach, whether backups are encrypted

Data residency

Where is customer data stored and processed? Can we choose a region?

Hosting provider and regions, whether data leaves that region, any region options for customers

Sub-processors

Which third parties process our data? How do you vet them?

A current sub-processor list with purpose and location, how customers are notified of changes, link to the DPA

Incident response

Do you have an incident response plan? How fast will you notify us of a breach?

A documented plan, named roles, notification commitment as written in your contract, when the plan was last tested

Business continuity

What are your backup, RPO and RTO? Have you tested disaster recovery?

Backup frequency and retention, recovery targets, date of the last restore or DR test

Vulnerability management

Do you run penetration tests? How do you patch?

Pen test frequency and who runs it, scanning tools, patch timelines by severity, how findings are tracked to close

SSO and SCIM

Do you support SAML or OIDC SSO? Can we provision users with SCIM?

Supported protocols and identity providers, which plans include them, how deprovisioning works

AI and data use

Do you use AI? Is our data used to train models? Which AI providers process it?

Which features use AI, which providers, whether customer data trains any model, retention, how customers can opt out

Keep the third column honest. If an answer depends on the plan the buyer is on, say which plan.

How to keep security review from stalling the deal

Security review stalls deals for one reason: it starts too late and nobody on the buying side owns its date. Fix both.

Start it at evaluation, not at contract

As soon as a technical evaluation starts, ask your champion: "Does a vendor like us go through security review here? Can we start it now, in parallel?" Every week the review runs alongside the evaluation is a week it does not add to the end.

Put it on the mutual action plan

Make security review a line on your mutual action plan with a buyer-side owner and a date: "Security questionnaire returned by vendor: Oct 14. Security review complete: Oct 28 (owner: Priya Shah, Security)." A step with a name and a date gets done. A step called "security" with no owner sits in a queue.

Send a trust page or security pack before they ask

A security pack sent proactively (your policies, SOC 2 report under NDA, pen test summary, sub-processor list and a completed standard questionnaire) answers most questions before the custom spreadsheet arrives. Some reviewers will accept it in place of their own file.

Introduce your security lead to theirs

Security people trust security people. A 20 minute call between your security lead and their reviewer clears questions that would otherwise take four rounds of email. It also turns the reviewer from a gate into one more person on the buying committee who knows you.

Keep the economic buyer informed

If the review slips, the economic buyer should hear it from your champion, with the reason and the new date, not discover it at signature. Our stakeholder email templates include a procurement outreach email that bundles the security pack with the contract documents.

Answer library: build it once

The second questionnaire should take a fraction of the first. That only happens if you keep what you wrote.

Store every answer in one place

A shared spreadsheet or document is enough to start. One row per question: the question, the approved answer, the evidence link, the owner and the date last reviewed. Do not let answers live in old email threads.

Tag answers by area

Tag each row with the question area from the template above (access control, encryption, sub-processors and so on) and by framework when it maps to one (SIG, CAIQ, HECVAT). When a new questionnaire arrives, you search by area instead of reading every old file.

Version answers when the truth changes

When you add a region, change a sub-processor or pass an audit, update the library the same week. An outdated answer is worse than no answer because it is confidently wrong. Keep the old version with its date so you know what you told which buyer.

Review it on a schedule

Have the security owner review the whole library every quarter and after any major change. Check that every answer still matches what the product and the company do today.

Write answers that travel

Write each answer so it reads correctly on its own, without "as mentioned above". Questionnaires reorder questions, and your answer will be pasted into a different file next time.

FAQ

How long does a security questionnaire take?

It depends on the format and on what you already have. A short standard questionnaire answered from an up-to-date answer library can take a few hours to a couple of days. A long custom spreadsheet answered from scratch can take weeks, mostly spent finding the right person for each answer. Then add the buyer's review time on top, which you should ask about up front.

What is a SIG questionnaire?

The SIG (Standardized Information Gathering questionnaire) is a vendor risk questionnaire published by Shared Assessments. It comes in two main sizes: SIG Lite for a high-level view of a vendor's controls and SIG Core for vendors handling highly sensitive or regulated data. It is updated every year and buyers scope it to the risk areas they care about.

Do I need SOC 2 to pass a security review?

Not always, but many enterprise buyers ask for a SOC 2 Type II report or ISO 27001 certificate, and without one you should expect more questions and a longer review. If you do not have one, send your policies, a pen test summary and a completed standard questionnaire, and tell the buyer if and when an audit is planned. Be specific and honest about the date.

Who should fill out a security questionnaire?

One owner on the vendor side, usually the sales engineer, the security lead or the CTO, with input from engineering, legal and operations for their sections. The salesperson should not answer technical questions alone. They should own the timeline, the relationship with the buyer's reviewer and the cover note.

What if we can't answer yes?

Answer truthfully. State what you do today, the compensating control that reduces the risk, and the date you will close the gap. Reviewers expect some partial answers, and an honest "partial, here is the plan" holds up better than a "yes" that a follow-up question disproves.

How demoshake helps

demoshake is a digital sales room, so the security step lives in the same place as the rest of the deal instead of in an email thread.

A Stakeholder Role for security. Add a "Security" Stakeholder Role to the Deal Room. Its sections hold the security pack, your standard answers and the evidence list, written for the buyer's security team. Their reviewer sees what they need without scrolling past the ROI case, and the economic buyer does not have to read your encryption policy.

The review on the Action Plan. Put the security step in the Deal Room's Action Plan as a Milestone, with Action Items such as "Questionnaire returned" and "Review complete", each assigned to a named person on your side or theirs. Everyone sees who owns the next step.

Know when they opened it. Engagement analytics show when the security team opened their sections, so you know the review has started before you chase it.

demoshake does not fill in questionnaires for you. It gives the review an owner, a date and a home.

That deal you’re thinking about right now. The one with 4 people who need to say yes.

What if you could send them one link tonight?

Free while your first deals close · no credit card