The vendor security questionnaire, and who gets one
Twenty four questions, grouped and numbered, with the rule that decides who receives them and the reason the rest of your vendor list should never see a form.
A vendor security assessment questionnaire template is below, printed in full, 24 questions in six sections. Send the whole set to a vendor that can reach your customer data or your production systems. Send nothing at all to the ones that cannot.
Tier first, then ask. The rule below keys off what a vendor can reach rather than what you pay them.
The register behind it is the part an auditor asks for. Requests 17 through 19 on a SOC 2 evidence request list are all vendor questions: the listing, the assurance you obtained, and the risk assessment you ran before data started flowing. Answering those later is archaeology. Answering them as you onboard is a spreadsheet.
Tier by what the vendor can reach
Spend is the wrong axis. A logging tool you barely notice on the invoice holds every request header your application emits, while a large contract for office furniture reaches nothing. Rank vendors by reach. Three tiers is enough, and the tier sets the questionnaire length and the clock on the next review.
| Tier | What the vendor can reach | What you send | Re-assess |
|---|---|---|---|
| 1, critical | Customer data, production, your identity provider, or your source code | All 24 questions, and their report | Every 12 months |
| 2, limited | Internal company data only, no production access | Sections A, B and C | Every 24 months |
| 3, peripheral | No company data, no access to any system you operate | A register row, no questionnaire | Only when reach changes |
The 24 questions
Grouped by section, numbered straight through, so you can paste the whole set into one email or split the sections across owners. Every question is answerable in a sentence or with a document name. None asks a vendor to describe a philosophy.
A. Company and scope
- What is your legal entity name, and where is the company registered?
- Which of your products will we use, and what does it do with our data?
- Who is the named security contact, and what is the escalation address?
B. Assurance
- Do you hold a current SOC 2 Type 2 report, and what period does it cover?
- Which criteria are in scope, and which subservice organizations are carved out?
- If that period ended over three months ago, can you send a bridge letter?
- When was your last penetration test, and can we see the summary?
C. Our data
- What categories of our data will you store, and in which countries?
- Is our data encrypted in transit and at rest, and with what?
- How is our data separated from another customer’s inside your systems?
- What is your retention period after termination, and how is deletion confirmed?
- Which of your staff can read our production data, and who approves that?
D. Access and change
- Is multi factor authentication enforced for every employee on your production console?
- Do you offer single sign on to our users, and at which plan level?
- How is access removed when an employee leaves, and within how long?
- How are production changes reviewed and approved before they ship?
E. Incidents and people
- Have you had a security incident affecting customer data in the last 24 months?
- How fast do you notify us after confirming a breach, in hours or days?
- Do you run background checks on staff with production access?
- Do staff complete security training, and how often?
F. Subprocessors and continuity
- Which subprocessors handle our data, and where is that list published?
- How much notice do we get before a new subprocessor is added?
- What are your recovery time and recovery point targets, and when was the last restore test?
- Do you carry cyber liability insurance, and at what limit?
The questions that waste both sides’ time
Cut these three. Each reliably produces an answer, and the answer changes nothing you would then do.
- Do you have an information security policy?
- The answer is yes, and it costs four seconds to give. Ask for the specific control you care about, which is question 15.
- Describe your security culture.
- Nothing in the answer can later turn out to have been wrong. A question you cannot be lied to on carries no information.
- Anything the report they already sent you answers.
- Read it first. Making a vendor retype their own Section 4 into your form buys you nothing the PDF already said.
When the vendor sends a report instead of answering
This is the good outcome. A report carries evidence a licensed CPA firm tested against stated criteria.1 A questionnaire carries what the vendor says about itself. Take the report, then do three things with it.
- Check that it is real and current. Signature, period, scope, exceptions. How to verify a SOC 2 report you were sent is the read order.
- Read the complementary user entity controls. That section is a list of jobs assigned to you.2 If the vendor assumes you rotate the key and you never do, neither control holds. Complementary user entity controls covers the rest.
- Ask only what the report leaves open. It describes the vendor system, not your contract, so questions 8, 11, 14, 21 and 24 stay on your list.
Record the review as a dated note naming who read it and what they concluded. A report in a folder is not evidence that anyone read it.
When a critical vendor has no report
No report is not a veto. It is a reason to get the same assurance elsewhere, and to write down exactly what you accepted and why.
- Get all 24 answers in writing, from a named person, dated. An email thread counts. A call does not.
- Ask for what they do have. A penetration test summary, an ISO 27001 certificate.
- Move the rest into the contract. A breach notification window in hours, a deletion duty on termination, subprocessor notice, and the right to re-assess.
- Write the exception down and date it. Name the vendor, the gap, who accepted it, and when you will look again.
Your own examination looks at your vendor management, not at your vendor. The artifact that matters is your record of the decision, not the paperwork the vendor never had.
How often to re-assess
Cadence by tier, and the table above sets the interval. What a table cannot show is timing: land the Tier 1 review after the vendor report period ends, or you spend it reading last year’s coverage.
Four events beat any schedule: the product you bought starts touching customer data and moves the vendor up a tier, their report period lapses with no bridge letter, they announce a breach, or they add a subprocessor that handles data you gave them. Any of those pulls the review forward, whatever the register says.
Vendor management sits inside the common criteria,2 so the register and the dated review notes above are evidence your own examination asks for. Polara G.R.C. scopes Security only. A Type 1 is $4,000 one time, with the first examination and the independent partner auditor fee included.
Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
How should you tier vendors for a security assessment?
What should a vendor security questionnaire ask?
What do you do when a vendor sends a SOC 2 report instead of answering your questionnaire?
What do you do when a critical vendor has no SOC 2 report at all?
How often should you re-assess a vendor?
Sources
Get audit-ready without a compliance team.
$4,000 one time for SOC 2 Type 1, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Get startedPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.