Vendor security questionnaire template
A free vendor risk assessment questionnaire with 35 questions across 9 areas, from access control and encryption to subprocessors and backups. Each question says what a good answer looks like and which SOC 2 criterion it helps you evidence. Download it as an Excel workbook with space for the vendor’s answers, your notes and a rating, or take the 17-question short version for lower-risk vendors.
Answering one of these instead of sending it? Draft answers to the same 35 questions from your generator answers and policies, free and in your browser.
35 questions, built in your browser. The workbook has Instructions, Questionnaire and Review summary sheets and opens in Excel, Numbers or Google Sheets.
When to send a questionnaire, and when a SOC 2 report is enough
A third party security questionnaire is slow for both sides, so send it where it adds something. For most established vendors the better first step is their independent assurance report: a SOC 2 Type II report or an ISO/IEC 27001 certificate has been tested by someone else, which a self-reported answer has not. See where to get your vendors’ SOC 2 reports for the common ones.
- Report available and in scope. Review the report instead: the period, the scope, any exceptions and the complementary user entity controls you have to operate. Send only the questions the report does not answer, such as your data’s location or the notification timeframe in your contract.
- No report, and the vendor touches customer data. Send the full questionnaire and ask for evidence behind the key answers. This is the case it is built for: smaller vendors, newer startups and specialist contractors.
- Report is old or the scope is narrow. Ask for a bridge letter, then use the questionnaire for the parts of the service the report leaves out.
- Low-risk tool with no confidential data. A short documented review is usually enough; the short version is the most you need.
Tier your vendors first
The depth of the review should follow the risk. The Vendor and Third-Party Risk Management Policy uses three tiers, and the questionnaire maps onto them:
- Tier 1, critical. Stores or processes customer data, or the product depends on it. Ask all 35 questions (or review a report that covers them) and review again at least annually.
- Tier 2, important. Internal confidential data or access to internal systems, but no customer data. The 17 questions marked “All vendors” are usually enough.
- Tier 3, low. No confidential data or system access. Confirm the tier and record it; a questionnaire is rarely worth sending.
Whatever tiers you use, write them down and apply them consistently. The auditor will test CC9.2 against what your own policy says you do.
How to score the answers
Read each answer against the “what a good answer includes” guidance, not against a perfect score. The workbook leaves the Rating column as free text so you can use your own scale; the suggested one is:
- Satisfactory. The answer is complete and supported by evidence or an independent report.
- Follow-up. The answer is incomplete, vague or unsupported. Ask a follow-up question or request evidence.
- Gap. The control is missing or weaker than you need. Record a compensating control, a contract term or a risk acceptance.
- N/A. The question does not apply to this vendor or service. Note why.
The Review summary sheet counts the ratings and leaves space for the decision: approve, approve with conditions, or reject. A few gaps rarely mean rejecting a vendor. More often they mean a contract term, a compensating control on your side, sending less data, or a documented risk acceptance by the person your policy names. What matters for the audit is that the gap was seen and a decision was recorded.
Some answers deserve more weight than others:
- Claims with evidence behind them over claims without.
- Specific answers (a timeframe, a tool, a date) over general ones (“industry best practice”).
- Answers about the controls closest to your data: access to production, encryption, incident notification and deletion at contract end.
The questions
Every question in the download, grouped by area. “Critical / high-risk only” questions are dropped from the short version. The criteria column shows which SOC 2 criteria the answer helps you evidence in your own vendor review; it is not a statement about the vendor.
Company, certifications and reports
Who owns security at the vendor and what independent assurance already exists. A current report can answer much of the rest.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-01 | Do you have a current independent assurance report or certification that covers the service we use, such as a SOC 2 Type II report or an ISO/IEC 27001 certificate? Please share it or tell us how to request it. | A copy of the report or certificate (often under NDA), with a period end or issue date in the last 12 months and a scope that names the service you use. A bridge letter if the report period ended several months ago. | CC9.2 | All vendors |
| VQ-02 | Who is responsible for information security at your company, and how do we report a security concern to you? | A named role (for example CTO or Head of Security) and a monitored contact such as a security@ address or a published vulnerability disclosure page. | CC1.3, CC2.3 | All vendors |
| VQ-03 | Do you maintain documented information security policies that management approves and reviews at least annually? | A list of policies with owners and last review dates. The policies themselves, or a table of contents, if the vendor will share them. | CC5.3, CC9.2 | All vendors |
| VQ-04 | Did your most recent assurance report or audit note any exceptions or qualifications? If so, what has been done about them? | Either no exceptions, or each exception listed with the vendor's management response and the date it was remediated. Check the answer against the report itself. | CC4.2, CC9.2 | Critical / high-risk only |
| VQ-05 | Do you perform and document an information security risk assessment at least annually? | The date of the last assessment and who approved it. A summary of the method (how risks are scored and treated) is enough; the risk register itself is usually confidential. | CC3.2 | Critical / high-risk only |
Access control and authentication
How the vendor controls who can reach the systems that hold your data, and how your own users sign in.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-06 | Is multi-factor authentication required for all of your staff's access to systems that store or process our data? | Yes, enforced through the identity provider for every user, including administrators and contractors, with any exceptions named and justified. | CC6.1 | All vendors |
| VQ-07 | Can our users sign in with single sign-on (SAML or OIDC), and can we require multi-factor authentication for our accounts? | Documentation of SSO and MFA settings, and which plan they are available on. Note whether local passwords can be disabled once SSO is on. | CC6.1 | All vendors |
| VQ-08 | How is access granted, changed and removed when your staff join, change roles or leave, and how quickly is access removed on departure? | A ticketed or HR-driven process with approval before access is granted and a defined removal timeframe, for example within one business day of departure. | CC6.2 | All vendors |
| VQ-09 | Is access to production systems and customer data restricted by role to the staff who need it? Roughly how many people have it? | Role-based access with a small, named group holding production or administrative access, and separate privileged accounts or just-in-time elevation for administrative tasks. | CC6.3 | Critical / high-risk only |
| VQ-10 | How often do you review user and administrator access to production systems and customer data? | A review at least quarterly for production and customer data systems, with the reviewer, date and any removals recorded. | CC6.2, CC6.3 | Critical / high-risk only |
| VQ-11 | When your staff access our data, for example to resolve a support request, how is that access approved and logged? | Access only for a stated purpose, ideally with customer consent or a ticket reference, and logged so it can be reviewed afterwards. | CC6.3, C1.1 | Critical / high-risk only |
Data protection and encryption
What data the vendor holds, where it lives, how it is protected and what happens to it at the end of the contract.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-12 | What of our data will you store or process, and in which countries, regions and hosting providers? | A clear list of data categories and the regions and providers where they are stored, matching your data processing agreement. Options to choose a region if you need one. | C1.1, CC9.2 | All vendors |
| VQ-13 | Is our data encrypted in transit over public networks, and which protocol versions do you accept? | TLS 1.2 or later on every external endpoint, with older protocol versions disabled. | CC6.7 | All vendors |
| VQ-14 | Is our data encrypted at rest, including in databases, file storage and backups? | Yes, for every store that holds customer data, including backups, typically using the cloud provider's managed encryption. | CC6.1, C1.1 | All vendors |
| VQ-15 | How are encryption keys managed, and who can access them? | Keys held in a managed key service, with access restricted to a small group, key use logged and a rotation schedule. Customer-managed keys if your risk needs them. | CC6.1 | Critical / high-risk only |
| VQ-16 | How is our data kept separate from other customers' data? | A description of tenant isolation (separate databases, schemas or enforced tenant identifiers) and how it is tested. | CC6.1 | All vendors |
| VQ-17 | When our contract ends, how and when is our data returned and deleted, including from backups? Can you confirm deletion in writing? | An export option, a stated deletion timeframe for live data and for backups, and written confirmation on request. | C1.2 | All vendors |
Infrastructure and vulnerability management
How the vendor finds and fixes weaknesses in its systems, network and endpoints.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-18 | How do you identify and remediate vulnerabilities in your systems, and what are your remediation timeframes by severity? | Regular automated scanning of infrastructure and dependencies, with defined timeframes such as critical within days and high within weeks, and tracking of overdue items. | CC7.1 | All vendors |
| VQ-19 | Do you have an independent penetration test at least annually? Can you share a summary of the latest results? | The test date, the firm or team that ran it, the scope, and a summary or attestation letter showing high-severity findings were fixed. | CC7.1, CC4.1 | Critical / high-risk only |
| VQ-20 | How are your production networks protected from external threats? | Default-deny network rules, only required ports exposed, administrative access through a VPN, bastion or identity-aware proxy, and DDoS or web application firewall protection where relevant. | CC6.6 | Critical / high-risk only |
| VQ-21 | Are company laptops and other endpoints managed, with disk encryption, automatic updates and malware protection? | Device management covering every device that accesses company systems, with disk encryption, screen lock, OS updates and endpoint protection enforced. | CC6.8 | Critical / high-risk only |
Logging and incident response
Whether the vendor would notice a security event, and how and when it would tell you.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-22 | If a security incident affects our data, how and within what timeframe will you notify us? | A defined notification timeframe that matches or is stricter than your contract or data processing agreement, and the contact or channel the notice will come through. | CC7.4, CC2.3 | All vendors |
| VQ-23 | Do you log access and administrative activity on production systems? How long are logs kept, and are they monitored with alerting? | Centralised logs for authentication, administrative actions and data access, kept for a defined period (often a year), with alerts on suspicious activity routed to someone on call. | CC7.2 | Critical / high-risk only |
| VQ-24 | Do you have a documented incident response plan, and when was it last tested? | A plan with roles, severity levels and communication steps, and the date of the last tabletop exercise or real incident review. | CC7.3, CC7.4 | Critical / high-risk only |
| VQ-25 | In the last 24 months, have you had a security incident that required notifying customers or regulators? If so, what changed afterwards? | A direct answer. If yes, a short description of the incident, the root cause and the changes made. Weigh a clear, candid answer above an unexplained no. | CC7.4, CC7.5 | Critical / high-risk only |
Business continuity and backups
Whether the service and your data survive an outage, a deletion or a regional failure.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-26 | Do you back up the data you hold for us? How often, for how long, and are backups encrypted and stored separately from production? | Automated backups at a stated frequency and retention, encrypted, and stored in a separate account or region from the primary data. | A1.2 | All vendors |
| VQ-27 | How often do you test restoring from backup, and when was the last successful test? | Restore tests at least annually, with the date of the last one and whether it met the recovery objectives. | A1.3 | Critical / high-risk only |
| VQ-28 | Do you have a business continuity and disaster recovery plan with defined recovery time and recovery point objectives? When was it last tested? | Stated RTO and RPO for the service you use, a plan covering loss of a region or key provider, and the date of the last exercise. | CC9.1, A1.3 | Critical / high-risk only |
Subprocessors
Which other companies the vendor passes your data to, and how it manages them.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-29 | Which subprocessors will have access to our data? Please list each one with its purpose and location. | A current subprocessor list (often a public page) with purpose and location for each, consistent with your data processing agreement. | CC9.2 | All vendors |
| VQ-30 | How do you assess the security of your own vendors and subprocessors, and how will you notify us of changes to the list? | A vendor review process (assurance reports, contract terms, periodic review) and advance notice of new subprocessors with a way to object, as your agreement requires. | CC9.2 | Critical / high-risk only |
HR security
Whether the people with access to your data are trained and bound to keep it confidential.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-31 | Do your staff and contractors complete security awareness training at onboarding and at least annually? | Training at hire and annually, with completion tracked. Additional role-specific training for engineers and anyone with production access is a plus. | CC1.4, CC2.2 | All vendors |
| VQ-32 | Do staff and contractors sign confidentiality agreements, and do you perform background checks where local law permits? | Confidentiality or NDA terms signed before access is granted, and background checks proportionate to the role where permitted. | CC1.1, CC1.4 | Critical / high-risk only |
Secure development
How changes to the vendor's product are reviewed, tested and kept away from production data.
| ID | Question | What a good answer includes | Criteria | Asked of |
|---|---|---|---|---|
| VQ-33 | Are code and infrastructure changes peer reviewed and tested before they reach production? | Branch protection or an equivalent control that requires review and passing checks before merge, with emergency changes reviewed after the fact. | CC8.1 | All vendors |
| VQ-34 | Do you use automated security testing in development, such as dependency scanning, static analysis or secret scanning? | Named tools running on every change or on a schedule, with findings triaged into the same remediation process as other vulnerabilities. | CC8.1, CC7.1 | Critical / high-risk only |
| VQ-35 | Is production customer data kept out of development and test environments? | Yes, with synthetic or masked data in non-production environments and production access separated from development access. | CC8.1, C1.1 | Critical / high-risk only |
After the review
File the completed workbook with the vendor’s entry in your vendor inventory, along with the report you reviewed and the contract. Record the next review date from your policy’s cadence. For a Type II audit, the evidence is the trail: the inventory, the tier, the review and the decision, dated inside the audit period. The SOC 2 evidence checklist lists what else the auditor will ask for under CC9.2.
35 questions, built in your browser. The workbook has Instructions, Questionnaire and Review summary sheets and opens in Excel, Numbers or Google Sheets.
Frequently asked questions
- Is a vendor security questionnaire required for SOC 2?
- Not by name. SOC 2 criterion CC9.2 expects you to assess and manage the risk from vendors and business partners, and your vendor policy says how. For most vendors a current SOC 2 Type II or ISO/IEC 27001 report is the main evidence; a questionnaire is how you cover vendors without one, or gaps the report leaves open. The auditor tests that you followed your own policy.
- What is the difference between a vendor risk assessment and a security questionnaire?
- The questionnaire is one input. The vendor risk assessment is your conclusion: what the vendor does for you, what data it holds, which tier it is in, what evidence you reviewed (report, questionnaire, contract terms), what gaps remain and who accepted the residual risk. The Review summary sheet in the workbook is a place to record that conclusion.
- Should I use a standard questionnaire such as SIG or CAIQ instead?
- Large standard questionnaires are useful when the vendor already has one completed and can share it, and some customers will require a specific one. For a small company reviewing its own vendors, a short questionnaire focused on the data and access the vendor actually has tends to get answered faster and more carefully. If a vendor offers a completed standard questionnaire, accept it and map it to your questions rather than asking them to start again.
- How often should vendors fill in the questionnaire?
- Follow the review cadence in your vendor policy. A common pattern is at onboarding and then annually for critical vendors, and every one to two years or on a change of use for lower tiers. In between, a new incident, a new subprocessor or a significant change to the service is a reason to ask again.
- What if a vendor refuses to answer?
- Record the refusal, the questions left open and what else you relied on, such as a public trust center, contract terms or limiting the data you send. Then decide, and document, whether to accept the risk, restrict how you use the vendor or look for an alternative. A refusal is a finding, not a blank.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.