Security Basics

What Is a Security Questionnaire?

A security questionnaire is a standardized list of questions that an organization sends to a vendor — or completes about itself — to evaluate security practices before doing business together. If you sell software or services to larger companies, receiving one is not a sign of distrust; it's standard procurement hygiene.

Why You Get One

When your product touches a customer's data or systems, their security team inherits part of your risk. Regulators and insurers increasingly require documented vendor due diligence. The questionnaire is how they document it.

Common triggers: a new enterprise contract, annual vendor reviews, onboarding to a procurement platform, or an audit of the buyer's own compliance program.

What's Usually Inside

Length varies from 20 questions to 300+, but the themes are remarkably consistent:

Company & Compliance Basics

Legal entity, headquarters, employee count, and whether you hold certifications like ISO 27001 or SOC 2.

Policies & Governance

Do you have written information security policies? Who owns security? How often are policies reviewed?

Access Control

How is access to customer data granted, reviewed, and revoked? Is MFA enforced?

Data Handling

Where is data stored? Is it encrypted in transit and at rest? How is it backed up and deleted?

Infrastructure & Development

How do you patch systems, manage vulnerabilities, and test code before release?

Incident Response

Do you have an incident response plan? What do you notify customers about, and how fast?

Questionnaires vs. Assessments vs. Audits

These three words get mixed up constantly:

  • Questionnaire — questions someone else asks you (or you ask vendors) to describe practices on paper.
  • Self-assessment — you systematically evaluate your own controls against a framework, producing scores and gap analysis. See the detailed comparison.
  • Audit — an independent third party examines evidence and issues a formal opinion (e.g., ISO 27001 certification).

The Fastest Way to Be Ready

Teams that scramble on every questionnaire have one thing in common: no internal baseline. When you already know your control gaps — because you've run a structured self-assessment against ISO 27001 — most questionnaire answers write themselves, and the honest ones ("we know, it's on our roadmap") build more trust than bluffing.

Build Your Baseline First

Run a free structured self-assessment mapped to ISO/IEC 27001:2022 and get your score, gaps, and remediation plan in about 30 minutes.

Start Free Assessment
    Feedback
    Back to Top