What Is a Security Questionnaire?
A security questionnaire is a standardized list of questions that an organization sends to a vendor — or completes about itself — to evaluate security practices before doing business together. If you sell software or services to larger companies, receiving one is not a sign of distrust; it's standard procurement hygiene.
Why You Get One
When your product touches a customer's data or systems, their security team inherits part of your risk. Regulators and insurers increasingly require documented vendor due diligence. The questionnaire is how they document it.
Common triggers: a new enterprise contract, annual vendor reviews, onboarding to a procurement platform, or an audit of the buyer's own compliance program.
What's Usually Inside
Length varies from 20 questions to 300+, but the themes are remarkably consistent:
Company & Compliance Basics
Legal entity, headquarters, employee count, and whether you hold certifications like ISO 27001 or SOC 2.
Policies & Governance
Do you have written information security policies? Who owns security? How often are policies reviewed?
Access Control
How is access to customer data granted, reviewed, and revoked? Is MFA enforced?
Data Handling
Where is data stored? Is it encrypted in transit and at rest? How is it backed up and deleted?
Infrastructure & Development
How do you patch systems, manage vulnerabilities, and test code before release?
Incident Response
Do you have an incident response plan? What do you notify customers about, and how fast?
Questionnaires vs. Assessments vs. Audits
These three words get mixed up constantly:
- Questionnaire — questions someone else asks you (or you ask vendors) to describe practices on paper.
- Self-assessment — you systematically evaluate your own controls against a framework, producing scores and gap analysis. See the detailed comparison.
- Audit — an independent third party examines evidence and issues a formal opinion (e.g., ISO 27001 certification).
The Fastest Way to Be Ready
Teams that scramble on every questionnaire have one thing in common: no internal baseline. When you already know your control gaps — because you've run a structured self-assessment against ISO 27001 — most questionnaire answers write themselves, and the honest ones ("we know, it's on our roadmap") build more trust than bluffing.
Build Your Baseline First
Run a free structured self-assessment mapped to ISO/IEC 27001:2022 and get your score, gaps, and remediation plan in about 30 minutes.
Start Free Assessment