A security questionnaire arrives in the week a customer decides whether to sign: their list of questions about how you protect their data, answered in writing with evidence. The standard forms have names, SIG, CAIQ and the VSA questionnaire, and security questionnaire examples are easier to read once you can tell which one you are holding.
What a security questionnaire is, and what security questionnaire examples have in common
A security questionnaire is a customer’s written list of questions about how a vendor protects their data, sent before or during a contract and answered with evidence. Security questionnaires differ in name and length, but they ask about the same areas: access, data protection, infrastructure, application security, incidents, vendors and privacy.
The form is one request among several that a growing SaaS company gets about the data it holds, and the others belong to the wider job of how to manage SaaS data compliance. Whatever title is on the file, I sort the rows of an information security questionnaire into eight areas. The grouping is mine, not a publisher’s: organization and policy, identity and access, data protection, infrastructure and cloud, application security, incident response and continuity, vendors and subprocessors, and privacy and compliance.
A long form walks through all eight. A short cyber security questionnaire might stop at access control, data protection, incident response and compliance, and still be asking the same things. Read a few security questionnaire examples side by side and the questions repeat under different headings: who can reach the data, whether it is encrypted, what happens after a breach, which providers touch it. They have nothing to do with the security questions a sign-in form asks to recover an account; examples of security questions of that kind belong to account sign-in, a separate topic.
Download an information security assessment questionnaire as a PDF or a spreadsheet template, and what you get is the same areas laid out as rows, one question per line. Any sample security questionnaire you find online is one publisher’s arrangement of them, which is why none is reproduced here. A security questionnaire knowledge base is the same idea as the answer library further down: each section answered once, dated, with its evidence attached. On the customer’s side, the document is filed as a vendor questionnaire, one step in their vendor evaluation.
Answering the one in front of you, row by row, including what to defer and what to send back, is a separate job, and a big customer sent a software security assessment questionnaire works through it.
Why the questionnaire matters to a small SaaS vendor
For a small SaaS team, the security questionnaire may be the first time anyone outside the company reads how the app is protected, in writing, with a name signed under it. That is my framing, and it is also why the honest answers matter more than fast ones.
The SaaS security questions that are hardest to answer honestly sit under four sections of the forms. In the 26 apps I audited in June and July 2026, a selected set rather than a random sample, gaps showed up under each of those four sections:
- Application security, the testing rows: at least 23 of the 26 audited apps had zero working automated tests.
- Secrets and access: 6 of the 21 third-party apps shipped a real secret.
- Data separation: 9 of the 21 third-party apps had row-level security gaps.
- Incident response: 17 of the 21 third-party apps had no error tracking or alerting: when a user hits an error, nothing records it.
None of those counts is a rate for AI-built apps in general, and the denominators differ because one count covers every app in the set while the other three cover only the third-party ones. Which of these rows you can answer today, which need a change first and which can wait for a date is the table in the article on a big customer’s questionnaire, and I won’t repeat it here.
Some rows in a SaaS vendor security assessment are security requirements the customer will not waive, and which ones depends on the customer. Customers call the whole process vendor security review, and the security review questionnaire is one line of it; the rest sits on your first enterprise customer’s requirements list.
The public record shows what can follow an untrue answer about security. On 1 February 2024 the US Federal Trade Commission announced a proposed order against Blackbaud, which provides data services and financial, fundraising and administrative software to companies, nonprofits, healthcare organizations and others. The FTC says that, despite promising customers that it takes “appropriate physical, electronic and procedural safeguards to protect your personal information,” Blackbaud failed to put such safeguards in place; among the examples, it failed to monitor attempts by hackers to breach its networks, adequately implement multifactor authentication, and test, review and assess its security controls. According to the complaint, a hacker accessed a customer’s Blackbaud-hosted database in early 2020, and the breach went undetected for three months. The final order, announced on 20 May 2024, prohibits Blackbaud from misrepresenting its data security and data retention policies.
That case was about promises made to customers, not a questionnaire. The lesson I take from it carries over all the same: a written yes about security can be checked against what was actually running, and acted on, long after the contract is signed.
How the standard forms work, and which control answers each section
The forms share one structure: sections by control area, rows as yes-or-no or short-answer questions, and a request for evidence. Learn which form you hold, map each section to the control and the artifact that answer it, and the questionnaire becomes a mapping exercise.
The standard forms by name: SIG, SIG Lite, VSA, CAIQ, VSAQ, DDQ
The standard security questionnaires are the SIG from Shared Assessments, the CAIQ from the Cloud Security Alliance, the Vendor Security Alliance questionnaire and Google’s open-source VSAQ, archived since 2022. A DDQ is a due diligence questionnaire: a wider form in which security can be one section. When a customer sends its own form, check which of these it copies.
| Form | Publisher | What it covers | Published openly? | Who sends it |
|---|---|---|---|---|
| SIG (Standardized Information Gathering) | Shared Assessments | Vendor assessments for managing third-party risk, which organizations can build, customize, analyze and store | Not stated on a reachable page | Organizations managing third-party risk |
| CAIQ (Consensus Assessments Initiative Questionnaire) | Cloud Security Alliance | Yes/no questions to assess cloud providers, built into the Cloud Controls Matrix (197 control objectives in 17 domains) | Downloadable with the CCM; no license needed to use the CCM internally | Customers assessing a cloud provider |
| VSA questionnaire (VSA FULL, VSA CORE) | Vendor Security Alliance | FULL: an in-depth cybersecurity vendor assessment; CORE: the most critical questions on vendor security and data privacy practices | Free, per the VSA’s October 2019 release; current version not stated on a reachable page | Companies assessing a vendor |
| VSAQ (Vendor Security Assessment Questionnaire) | Google-owned open-source code, not an official Google product | An interactive questionnaire application to assess the security programs of third parties | Open source (Apache-2.0); archived and read-only since 25 November 2022 | Questionnaires like the ones in it are used at Google to assess third parties, per its repository |
| DDQ (due diligence questionnaire) | None: a type of form, not one document | A supplier’s overall suitability as a partner, across areas such as financial performance, policies and certifications | Not one published form | A buyer assessing a supplier; in finance, limited partners assessing a fund manager |
| The customer’s own form | The customer | The rows its own reviewers chose | Not published | The customer |
The SIG questionnaire, short for Standardized Information Gathering questionnaire, comes from Shared Assessments, and the description of it in the table above is taken from Google Cloud’s SIG page. You will also meet the SIG Lite questionnaire and SIG Core, with SIG Lite sometimes typed as siglite. Shared Assessments’ own pages sat behind a sign-in when I checked on 3 October 2026, so the sizes, contents, license terms and prices of those versions are not stated here.
The CAIQ is the Cloud Security Alliance Consensus Assessments Initiative Questionnaire, and its home is the Cloud Security Alliance’s Cloud Controls Matrix and CAIQ page, where version 4.1 of the CCM and the CAIQ is combined.
The VSA questionnaire comes from the Vendor Security Alliance, whose site loads its content with JavaScript, and I could not read a current version number from it, so none is stated here. The VSA security questionnaire and Google’s VSAQ are easy to mix up because the names are one letter apart: the first is a form from an industry group, the second the archived Google-owned app in the table’s fourth row.
DDQ means due diligence questionnaire, and the meaning shifts with the sender. In procurement, a DDQ assesses a supplier’s financial stability, legal compliance and overall suitability. In finance, the meaning of DDQ changes: AutoRFP’s blog describes an ESG DDQ that limited partners send fund managers, and a form like that is about the fund, not your software. The same three letters also name a chemistry reagent.
Two more names come up. If a UK buyer asks for an NCSC vendor security assessment, read the NCSC’s supply chain security guidance first: it proposes 12 principles to help an organization establish effective control and oversight of its supply chain. The Qualys Security Assessment Questionnaire is a product a buyer uses to send forms: organizations enter vendor emails and it provisions the surveys.
What each section is really asking, and the control that answers it
Each questionnaire section asks one question in many rows: who can reach the data, how it is protected, where it runs, what the app checks, what happens when it breaks, who else touches it, and what you promise. Each has a control behind it and an artifact that proves it.
A vendor security assessment is the customer’s name for the review that reads your answers, section by section. The control and artifact columns below are my reading of what each section is after, not any publisher’s answer key.
| Section | The question behind the rows | The control | The artifact that proves it | Where the control is covered |
|---|---|---|---|---|
| Organization and policy | Who is responsible, and is it written down? | A controls checklist with evidence | The checklist, each control linked to its evidence | the MVSP controls checklist |
| Identity and access | Who can reach the data? | Session checks, roles, MFA for admins | The role matrix and a screenshot of the enforced setting | authentication checklist |
| Data protection | How is it protected? | Encryption at rest by the provider, row-level rules, backups that restore, retention | The policy list and a restore record | data consistency checklist for SaaS |
| Infrastructure and cloud | Where does it run? | The provider’s shared responsibility, separate environments, a deploy gate | The environment list | DevOps for startups |
| Application security | What does the app check? | Validation, headers, rate limits, a dependency scan, a security test | The test record | SaaS security checklist |
| Incident response and continuity | What happens when it breaks? | Error tracking, alerts, a restore drill | An alert that fired, and the drill record | logging and monitoring |
| Vendors and subprocessors | Who else touches it? | A subprocessor list | The published list, with the agreement for each provider | The answer library below |
| Privacy and compliance | What do you promise? | The personal-data inventory, export and deletion, the privacy policy | The inventory and the published policy | privacy policy for SaaS; the GDPR compliance checklist |
The map holds whatever the form calls itself. An information security audit questionnaire fits the same eight sections, even when its headings say audit instead of review. An information security due diligence questionnaire asks the same things as one part of a wider diligence form. A vendor security and privacy assessment leans harder on the last two rows, and a data security questionnaire is mostly the data protection row asked in more detail. A sample vendor risk assessment questionnaire you find online is written for the buyer, yet its rows still land in these sections.
The variants: vendor, buyer, cloud, AI, M&A, RFP, and the big-name forms
The vendor form is the one you receive: an information security questionnaire for vendors, sent by a customer about your app. The buyer form is the one you send to your own providers, and your subprocessor list is the answer sheet for it. An enterprise vendor security questionnaire is the vendor form from a larger customer, with the same sections.
A cloud security questionnaire is either the CAIQ or a cloud section of the customer’s own form: which provider, which region, how the data is encrypted and who can reach it. Your half of a cloud vendor security questionnaire is the checklist of what you set up on top of the provider: regions, encryption settings and who holds admin access. For the provider’s half of a cloud security assessment questionnaire, point to what the provider publishes; Google Cloud, for one, says it regularly updates and publishes a completed CAIQ, so for that layer the cloud service provider security questionnaire is already filled in, but the rows about your app are still yours.
An AI security questionnaire adds newer rows: which model provider you use, what customer data is sent to it, how long the provider keeps it, and how prompts are handled. The prompt rows of an AI vendor security questionnaire come down to one question, what is prompt injection, and how the app defends against it.
A merger and acquisition security questionnaire is a buyer’s technical due diligence: the same evidence plus the code itself, which is where due diligence of code when selling a business starts. An RFP security questionnaire is the security section of a procurement bid. A pre-screening security questionnaire is a short form that comes before the long one. Email, financial and supply chain security questionnaires are sector versions of the same structure.
Google and Plaid come up by name. For Google’s vendor security assessment, one public source is the VSAQ repository, which says that at Google, questionnaires like the ones in it are used to assess the security programs of third parties. Whether Google sends a different security questionnaire today is not stated in that repository. If you build on Plaid, read the requirement in Plaid’s launch checklist rather than on Reddit: the Plaid security questionnaire is required to access certain US institutions that use OAuth-based connections.
The tools that fill them in, and what they get wrong
Questionnaire automation tools keep an answer library and draft responses from it. They make the same answer consistent and traceable; they also make a yes with no control behind it consistent. Build the controls and the evidence first, then the library, then the tool if the volume justifies it.
Three names come up: Conveyor, Vanta and Drata. Conveyor describes its security questionnaire software in one line: “ConveyorAI ingests security questionnaires and fills them out for you.” Vanta’s Questionnaire Automation page puts its job as “Automate security questionnaire responses.” Drata’s site blocked my request when I checked on 3 October 2026, so I make no claim about its security questionnaire automation.
What they get right and wrong is my reading. They give the same answer to the same row every time, and they can show where the answer came from, which is what you want when the answer is true. They give the same yes with no control behind it to every customer who asks, too. Buying a security questionnaire tool or paying for a security questionnaire service changes who types; the answers still come from your controls and your evidence. Whether a tool-written answer is still yours is a question the questionnaire article takes up in its FAQ.
How to check your own app: build the answer library once
Build the answer library once: list the controls with their evidence, write the subprocessor list and the personal-data inventory, answer each section once with a date and a link to its evidence, and mark every no with the date it becomes a yes.
Each security questionnaire response then becomes a lookup: find the section, copy the dated answer, attach the evidence link. The same library answers security review questions that arrive by email instead of on a form. As a security checklist for the questionnaire, each step leaves you with something to keep:
- 01 List your controls with their evidence: the build-side items from the SaaS security checklist and the policy items from the MVSP controls checklist. You keep the controls list.
- 02 Write the subprocessor list: each provider that touches customer data, with the agreement you have in place with it. You keep the list.
- 03 Write the personal-data inventory: what is stored, where, why, and who can reach it. You keep the inventory.
- 04 Answer each of the eight sections once, dating each answer and linking it to its evidence. You keep the answer document.
- 05 Give every open no the day you expect it to turn into a yes. How to word that row for the customer is the questionnaire article section on deferring without lying. You keep the dated list of open items.
- 06 Keep it all in one document the team can edit, and re-date it after each release. You keep the library itself.
In the Production Hardening Sprint, deliverable 12.6 is a technical controls checklist with supporting evidence organized for enterprise security review. We verify it by linking each documented control to its owner, configuration, or test evidence, and this deliverable is not a SOC 2 audit report.
SOC 2 is a separate decision, and the questions around it, from SOC 2 with no security team and whether to hire SOC 2 compliance consultants to SOC 2 certification itself, have their own answers.
Where the sprint does this
The other parts of the answer library map to four more deliverables: 12.8 publishes the list of vendors that process customer data, with the agreement in place for each ; 12.1 documents what personal data is stored, where it lives, why it is collected, and who can access it ; 12.2 implements authenticated export and deletion workflows ; and for an AI app, 12.7 inventories the user data that reaches AI providers. The results go into the production readiness report, deliverable 13.1, which accounts for all 123 IDs, keeps failures visible until resolved and explains genuine non-applicable items. Formal third-party certifications and independent audit opinions are separate from these engineering deliverables. Every item is listed in the published scope.
Common questions about SIG, CAIQ and vendor questionnaires
What is a vendor security questionnaire?
A vendor security questionnaire is a security questionnaire seen from the side that receives it: a customer is assessing you as a vendor, and you answer each row in writing, with evidence where the row asks for it. The standard forms it may copy, and the eight sections it asks about, are in the two tables above.
What is a CAIQ questionnaire?
The CAIQ is the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire, a yes-or-no questionnaire for assessing cloud providers. It sits inside the CSA’s Cloud Controls Matrix, a cybersecurity control framework for cloud computing, and the current version, 4.1, ships the two together.
What are the key differences between the SIG and CAIQ security questionnaires?
The SIG comes from Shared Assessments and is built for vendor assessments in third-party risk management generally; the CAIQ comes from the Cloud Security Alliance and is aimed at cloud providers. They overlap: Google Cloud’s SIG page states that the CSA’s Cloud Controls Matrix maps to the Shared Assessments SIG v6.0.
What is a VSA questionnaire?
The VSA questionnaire is the Vendor Security Alliance’s standard vendor questionnaire, received the way the other standard forms are. The VSA’s own October 2019 release announced two free versions, VSA FULL and VSA CORE, and said the questionnaire is updated annually; I could not read its current version from the VSA’s site. It is a different thing from VSAQ, Google’s archived questionnaire app.
If this checklist left you with more open items than you expected, the sprint below works through all of them in ten working days.
Built it with AI. Now it has to hold up for real customers.
The Production Hardening Sprint takes the app you already have and builds the production foundation underneath it. Authentication and access rules, payments that stay consistent, error handling, monitoring, backups, automated tests and a documented handover. Our engineers work inside your existing codebase for ten working days. All 123 deliverables are included, and you get the evidence for each one.
See the Production Hardening Sprint →
$2,500 fixed price · 10 working days · One codebase