Security questionnaire
The vendor security review
What it is
A security questionnaire is the list of questions a buyer's security team sends before approving you as a vendor. Standard ones include SIG, CAIQ and HECVAT, and many companies send their own spreadsheet of a few hundred questions. They cover encryption, access control, incident response, subprocessors and more.
It sits between a verbal yes and a signed contract. Slow or inconsistent answers delay deals, and a wrong answer can end up written into the contract.
What it takes
About 2–4 engineer-weeks to build in-house, or 1–2 using Vanta Trust, SafeBase, Conveyor or Loopio.
Answer these first
- Sales: How many questionnaires arrived last quarter, and how long did each take?
- Security: Who is allowed to answer, and who approves the answers?
- Security: Which answers are currently 'no' or 'planned'?
- Engineering: Can we publish a trust page with our policies and reports?
- Legal: What can we share under NDA, and what can be public?
- Product: Which questions keep coming back that a product change would answer?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.