New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

Questionnaire (Security Questionnaire)

A security questionnaire is a structured set of questions sent to a vendor to collect self-reported information about their security controls, compliance status, and risk practices. Security questionnaires are a foundational tool in vendor due diligence, though their accuracy depends on honest and complete vendor responses. Common frameworks include the Standardized Information Gathering questionnaire (SIG) and the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ). Best practice combines questionnaire evidence with outside-in technical ratings for a complete, independently verified picture.

A security questionnaire is a structured set of questions an organization sends a vendor to document how that vendor protects data and systems. It's a core step in third-party risk management, giving a company a written record of a supplier's security controls, policies, and compliance before and during the relationship.

Security questionnaires are how most third-party risk programs open a vendor relationship. They go by other names too, including vendor security assessments and due diligence questionnaires. The format ranges from a handful of questions to a spreadsheet of several hundred, depending on how critical the vendor is and what data it will touch. Whatever the length, the underlying purpose is the same, to replace a leap of faith with a documented answer.

What Does a Security Questionnaire Cover?

A security questionnaire covers the controls that decide whether a vendor can be trusted with your data. The exact questions vary, but they cluster around a familiar set of domains:

  • Access control and authentication, including multi-factor and privileged access.
  • Data protection, including encryption in transit and at rest.
  • Incident response and breach notification commitments.
  • Compliance with the standards a vendor claims to meet, from SOC 2 to GDPR.
  • Business continuity and subcontractor risk, since a vendor's vendors become yours.

A questionnaire for a vendor handling health records runs far longer than one for a marketing tool. Criticality drives depth, which is why most programs tier their vendors before a single questionnaire goes out.

Depth Scales With Vendor Criticality

A vendor that touches regulated data or connects into core systems earns a long, detailed questionnaire. A short one won't do. A low-risk vendor with no access to anything sensitive can clear a lightweight set of questions. Sending the same three-hundred-question form to every supplier wastes everyone's time and trains vendors to answer on autopilot, which is how real gaps get buried under boilerplate.

What Are the Standard Security Questionnaire Frameworks?

Most organizations start from a standardized questionnaire rather than writing one from scratch. Standard formats save both sides time and make answers comparable across vendors:

  • SIG: the Standardized Information Gathering questionnaire, a broad industry standard from Shared Assessments.
  • CAIQ: the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance, aimed at cloud providers.
  • Cyber Essentials and bespoke sets: government schemes or a company's own control list.

Teams often adapt a standard rather than adopt it whole. Black Kite's custom cyber risk assessment frameworks support that, letting a program map its own questions and controls instead of forcing a generic set on every vendor.

How Are Security Questionnaires Used in Third-Party Risk Management?

In third-party risk management, a security questionnaire is the evidence a program collects before trusting a vendor with access. It usually enters at onboarding, when a company needs a documented view of a supplier's security before signing. From there it feeds tiering, contract terms, and the vendor risk assessment that follows. The questionnaire is one input into the broader third party risk management process, sitting alongside monitoring and due diligence rather than standing on its own. Treated as the whole program, it gives a dangerous sense of completion. Treated as one signal among several, it does real work. Black Kite's guide to building a third-party risk program puts the questionnaire in that wider context.

How Is a Security Questionnaire Different From an Attestation?

A security questionnaire and an attestation are both vendor-supplied, but they differ in whether an outside party tests the claim before it reaches you:

  • Self-reported vs. audited: a questionnaire captures what a vendor says about its own controls, unverified until someone checks it. An attestation, such as a SOC 2 report, captures what an independent auditor tested against a defined standard.
  • Still vendor's evidence: an attestation carries more weight for that reason, but it's still the vendor's own evidence to produce and share, not a platform's own outside-in observation.
  • Different tradeoffs: the questionnaire is flexible and cheap to send, while the attestation is credible but narrow and periodic.
  • Neither is final proof: treating either one as continuously verified proof is one of the most common errors in vendor risk.

That's where due diligence has to go beyond the paperwork itself.

Where Do Security Questionnaires Fall Short?

A security questionnaire tells you what a vendor claims, not what's true, and the gap between the two is where breaches live. The format has real, well-known limits:

  • The answers are self-reported, and nobody fails their own exam on purpose.
  • It's a snapshot. A vendor accurate in January can be exposed by March.
  • It doesn't scale. Sending and chasing hundreds by spreadsheet buries a small team.
  • It rarely gets verified. Most answers are filed, not checked against reality.

Self-Reported Answers Usually Go Unverified

The quiet problem isn't that vendors lie. It's that almost nobody checks. A completed questionnaire lands in a folder, gets a rubber-stamp review, and becomes the record of record until next year, even though not one answer was tested against reality. A vendor can claim it enforces multi-factor authentication everywhere and still leave an admin portal wide open, and the questionnaire would never catch it.

Outside-in data shows the gap plainly. Black Kite's 2026 Wholesale & Retail Cyber Risk Report found 70.36% of major retailers and 59.29% of wholesalers with corporate mail credentials already circulating on dark web marketplaces, and 76% of retail and 77% of wholesale firms carrying at least one critical-level patch management vulnerability. These are large enterprises with mature programs, the kind that complete questionnaires thoroughly and on time.

None of this means questionnaires are useless. It means they're a claim to be verified, not an answer to be trusted. The strongest programs pair the questionnaire with outside-in evidence, so a vendor's stated security posture can be checked against what an attacker would actually see from the outside.

How Do Teams Handle Security Questionnaires at Scale?

At scale, the bottleneck isn't writing the questionnaire, it's sending, chasing, and verifying hundreds of them. A program covering four hundred vendors can't run each one by hand and still watch for change in between.

Reserve the Questionnaire for the Real Gaps

That constraint is what a vendor security assessment questionnaire platform is built to relieve, by mapping available evidence to the controls in question and reserving the actual questionnaire for the genuine gaps that evidence can't answer. The goal isn't to abandon the questionnaire. It's to stop treating an unverified spreadsheet as the finish line for vendor trust, and to spend a team's limited hours on the vendors and questions that truly need a human. A questionnaire that arrives already half-answered by evidence, with only the real unknowns left blank, is a far better use of everyone's time than a blank form mailed to four hundred inboxes.

See also: How to Accelerate Vendor Vetting Without Questionnaires