Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Third-Party & Vendor

Vendor Security Questionnaire

Also known as: VSQ, Security Questionnaire, Vendor Risk Assessment Questionnaire (VRAQ), Vendor Security Alliance Questionnaire (VSAQ)
Simply put

A vendor security questionnaire is a structured set of questions an organization sends to a supplier or service provider to learn how that vendor protects data and manages security. It typically asks about the vendor's security certifications, controls, and practices so the organization can decide whether working with that vendor poses acceptable risk. It is one tool used within a broader effort to manage risks from third parties, not a certification or a guarantee of security.

Formal definition

A vendor security questionnaire is a due-diligence instrument used in third-party risk management to gather self-reported information about a prospective or existing vendor's security posture, covering areas such as security certifications and standards adhered to, technical and organizational controls, and operational practices. It generally functions as a point-in-time evaluation of a supplier's security controls and should be distinguished from ongoing vendor risk management, which is a continuous program rather than a single assessment. Questionnaires vary widely in scope and length, ranging from standardized industry templates (for example, the Vendor Security Alliance Questionnaire) to bespoke instruments that may contain a hundred or more items; because responses are self-attested, they are typically corroborated with independent evidence such as audit reports or certifications rather than relied upon alone. A questionnaire is not itself a regulation, standard, or certification, and its use, format, and required contents depend on the organization's risk appetite and any applicable contractual or sector-specific obligations. Readers should verify specific questionnaire standards and templates against current authoritative sources, as these evolve over time.

Why it matters

Organizations increasingly depend on third-party suppliers to process, store, or transmit sensitive data, and a weakness in a vendor's security posture can become a weakness in the organization's own. A vendor security questionnaire is one of the primary due-diligence tools used to surface those risks before a contract is signed and to monitor them afterward, giving the organization a structured basis on which to decide whether a given vendor poses acceptable risk. Without such an instrument, an organization has little visibility into how a supplier protects data, which certifications it holds, or which controls it actually operates.

The value of a questionnaire, however, is bounded by an important limitation: responses are self-attested. Because a vendor reports on its own security posture, the answers reflect what the vendor claims rather than independently verified fact. For this reason a questionnaire is generally corroborated with independent evidence—such as audit reports or certifications—rather than relied upon alone. A questionnaire is also a point-in-time evaluation, capturing a snapshot of controls at the moment it is completed; it does not substitute for the ongoing program of vendor risk management that tracks how a supplier's posture changes over time.

Questionnaires also vary widely in scope, which matters for both the organization sending them and the vendor answering. Standardized industry templates such as the Vendor Security Alliance Questionnaire offer a common format, while bespoke instruments may run to a hundred or more items—some reported to exceed two hundred questions. Length does not guarantee rigor, and an overly long or poorly targeted questionnaire can burden respondents without proportionately improving insight. Calibrating scope to the organization's risk appetite and the nature of the engagement is therefore central to using the tool effectively.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams design, send, and evaluate vendor security questionnaires as part of a broader vendor risk management program. For them, the questionnaire is one instrument within a continuous process, and their work includes corroborating self-attested responses with independent evidence and reassessing vendors over time rather than treating a single completed questionnaire as a final answer.
Information Security Professionals
Security teams both author questionnaires for inbound vendor assessments and respond to those received from customers and partners. They are positioned to judge whether a questionnaire's scope is appropriate to the engagement, to interpret questions about certifications and controls accurately, and to distinguish claimed adherence to standards from independently verified evidence.
Procurement and Vendor Onboarding Functions
Procurement teams often initiate security questionnaires as part of vendor onboarding and due diligence. They coordinate the exchange between the organization and the vendor and need to understand that a completed questionnaire informs a risk-based decision but is not a certification or a guarantee of a vendor's security.
Vendors and Service Providers Responding to Assessments
Suppliers that receive questionnaires must respond accurately, often to instruments varying widely in length and format—from standardized templates to bespoke sets exceeding a hundred or more items. Because responses are self-attested, vendors should be prepared to substantiate their answers with supporting evidence such as audit reports or certifications when requested.
Compliance Officers and Legal Counsel
These professionals help determine what a questionnaire must cover in light of applicable contractual or sector-specific obligations and the organization's risk appetite. They can advise on how questionnaire use fits within due-diligence expectations, while recognizing that application to a specific vendor relationship requires professional judgment and that the questionnaire itself carries no independent legal force.

Inside VSQ

Organizational and Governance Information
Questions covering the vendor's security policies, governance structure, personnel responsible for security, and any published attestations. This section typically seeks to establish whether the vendor maintains a documented security program rather than ad hoc practices.
Technical and Administrative Controls
Inquiries into access controls, encryption practices, network security, vulnerability management, logging, and similar safeguards. These questions generally aim to assess how the vendor protects systems and data at a technical and procedural level.
Data Handling and Privacy Practices
Questions addressing what data the vendor processes, where it is stored or transferred, retention practices, and sub-processor arrangements. Note that privacy practices and security controls are distinct concerns; a questionnaire may cover both, but answering security questions does not by itself demonstrate compliance with any specific privacy regulation.
Certifications and Third-Party Attestations
Requests for evidence such as ISO/IEC 27001 certification or SOC 2 reports. These are voluntary or contractual standards rather than legal requirements in themselves, and a claimed certification should be verified against the current certificate or report rather than accepted on the basis of a questionnaire response alone.
Incident Response and Business Continuity
Questions on breach notification procedures, incident handling, backup arrangements, and continuity planning. These help the assessing organization understand how the vendor would respond to and recover from disruptions or security events.
Compliance and Regulatory Posture
Questions asking which regulations or frameworks the vendor considers applicable to its services. Because obligations differ across jurisdictions such as the EU, the United States, and the United Kingdom, responses here indicate the vendor's self-assessment and are not a substitute for the assessing organization's own determination of applicable requirements.

Common questions

Answers to the questions practitioners most commonly ask about VSQ.

Does completing a vendor security questionnaire mean a vendor is certified or formally compliant?
No. A vendor security questionnaire is a self-assessment or information-gathering instrument, not a certification or a compliance determination. The responses are typically self-attested by the vendor and are not independently verified unless supplemented by an audit, an assessment, or evidence such as a SOC 2 report or an ISO/IEC 27001 certificate. A completed questionnaire may indicate a vendor's stated posture, but it does not confer certified status and should not be treated as equivalent to independent assurance. Certification and formal compliance are distinct concepts that generally require third-party involvement.
Is a vendor security questionnaire a legal requirement?
In most cases a vendor security questionnaire is a contractual or organizational practice rather than a directly mandated legal obligation. Some regulations and frameworks generally require organizations to exercise due diligence or oversight over third parties that process data or provide critical services, and a questionnaire is a common way to help demonstrate such diligence. However, the questionnaire itself is a tool chosen by the organization, not a document prescribed by law. Specific obligations vary by jurisdiction, sector, and the nature of the data or service involved, and readers should verify applicable requirements against the relevant authoritative text.
How should a questionnaire be scoped to the risk a vendor presents?
A common approach is to tier vendors by risk and match questionnaire depth accordingly. Factors that may inform tiering include the category and volume of data involved, whether the vendor acts as a processor, the criticality of the service, and the vendor's level of system access. Lower-risk vendors may warrant a short questionnaire, while higher-risk vendors may warrant a more detailed one supported by evidence. Scoping decisions are fact-specific and depend on the organization's risk tolerance and internal policies.
What evidence should accompany questionnaire responses?
Because questionnaire responses are generally self-attested, organizations often request supporting documentation to corroborate them. Depending on the vendor and risk level, this may include audit or assessment reports, certificates for standards the vendor claims to hold, policy documents, penetration test summaries, or subprocessor lists. Requesting and reviewing such evidence helps distinguish stated posture from demonstrated posture. The appropriate mix of evidence is fact-specific and typically defined by the organization's third-party risk process.
How often should vendor security questionnaires be refreshed?
Many organizations reassess vendors on a periodic cycle and also in response to trigger events, such as a material change in the service, a security incident, a change in data processing, or contract renewal. Higher-risk vendors are often reassessed more frequently than lower-risk ones. There is no single universal interval; cadence generally reflects the organization's risk-based policy. Because standards, certifications, and their versions change over time, refreshed reviews also help confirm that prior evidence remains current.
Should standardized questionnaire templates or custom questionnaires be used?
Both approaches are used, and the choice involves trade-offs. Standardized templates can improve consistency, reduce burden on vendors who receive many requests, and ease comparison across vendors. Custom questionnaires can target risks specific to a particular engagement, data type, or regulatory context. Some organizations combine a standardized baseline with tailored questions for higher-risk or specialized vendors. The suitable approach depends on organizational needs and resources, and any mapping to specific regulatory obligations should be verified against the applicable authoritative source.

Common misconceptions

A completed vendor security questionnaire proves the vendor is compliant or certified.
A questionnaire generally captures self-reported assertions at a point in time and is not itself an audit or certification. Compliance and certification are distinct outcomes established through legal obligation or accredited third-party assessment respectively, and questionnaire responses may warrant independent verification against supporting evidence.
One standardized questionnaire satisfies obligations across all jurisdictions and use cases.
Requirements differ by territory, sector, data category, and risk level. A questionnaire designed around one framework or region may not surface the controls relevant to obligations elsewhere, so scope should be tailored to the specific engagement rather than assumed universal.
Answering security questions covers the vendor's privacy obligations as well.
Privacy and security are related but distinct. Demonstrating technical safeguards does not by itself establish lawful processing, data subject rights handling, or transfer mechanisms that a privacy regime may require. Both areas generally need to be assessed separately.

Best practices

Scope the questionnaire to the specific service, data category, and jurisdictions involved rather than reusing a single generic template for every vendor.
Treat questionnaire responses as self-reported claims and request supporting evidence—such as current certificates or assessment reports—verifying them against authoritative sources rather than the questionnaire alone.
Keep security and privacy questions clearly separated so that answers in one area are not mistaken for coverage of the other.
Calibrate the depth of inquiry to the assessed risk level, applying more rigorous scrutiny to vendors handling sensitive data or critical functions.
Confirm that any cited certifications or attestations are current and unexpired, since certification schemes and their versions change over time.
Record how responses were reviewed and what follow-up was taken, recognizing that application to a particular engagement requires professional judgment rather than reliance on the questionnaire as a definitive compliance conclusion.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.