Free template
Vendor security questionnaire template
The questions to ask before a vendor gets access to your data or network, grouped by security domain, with the evidence to request alongside the answers. Copy the questions you need and scale them to each vendor’s risk.

How to use it
Send the right questions to the right vendors
Inventory your vendors
List every third party that stores, processes or can access your data or systems, including software you subscribe to.
Tier by risk
Rank vendors by the sensitivity of the data they hold and the access they have. Critical vendors get the full questionnaire; low-risk vendors get a short version.
Ask for evidence
Request the documents listed below to back up key answers. A SOC 2 report or ISO 27001 certificate can replace many questions.
Score and follow up
Flag gaps, agree on fixes or contract terms, and repeat the review on a schedule and when the relationship changes.
The questionnaire
Vendor security questions by domain
1. Company and governance
- Who is responsible for information security at your company, and to whom do they report?
- Do you have a documented information security program that leadership has approved and reviews at least annually?
- Have you had a security breach or incident affecting customer data in the past three years? If so, describe it and what changed.
- Do you carry cyber liability insurance?
2. Compliance and attestations
- Do you have a current SOC 2 Type 2 report, ISO 27001 certificate or equivalent independent assessment? Which services are in scope?
- Which regulations apply to the services you provide us (for example HIPAA, PCI DSS, CMMC or state privacy laws), and how do you comply?
- Will you sign a business associate agreement or data processing agreement if required?
- When was your last penetration test performed by an independent party, and were critical findings fixed?
3. Data handling and privacy
- What types of our data will you store, process or access?
- Where is our data stored and processed, including backups? Name the countries and hosting providers.
- Is our data encrypted in transit and at rest? Who manages the encryption keys?
- How is our data separated from other customers’ data?
- How long do you keep our data, and how do you return or destroy it when the contract ends?
4. Access control and identity
- Is multi-factor authentication required for all access to systems that hold our data, including administrative and remote access?
- Do you support single sign-on with our identity provider?
- How do you grant, review and remove employee access? How often are access reviews performed?
- How are privileged accounts managed and monitored?
5. Infrastructure and network security
- How is your network segmented to protect systems that handle customer data?
- Which firewall, endpoint protection and email security controls are in place?
- How are cloud environments configured and reviewed against security baselines?
- If you will connect to our network, how is that connection secured and limited?
6. Application security
- Do you follow a secure development process, including code review and security testing before release?
- How do you manage vulnerabilities in open source and third-party components?
- Are your applications and APIs tested against the OWASP Top 10?
7. Vulnerability management
- How often do you scan for vulnerabilities, and what are your target timelines for fixing critical and high findings?
- How do you track and apply security patches for operating systems and applications?
- Do you run a vulnerability disclosure or bug bounty program?
8. Logging and monitoring
- Do you monitor systems that hold our data for security events around the clock?
- Which events are logged, and how long are logs retained?
- Can you provide logs related to our account if we need them for an investigation?
9. Incident response and notification
- Do you have a documented incident response plan, and when was it last tested?
- How and how quickly will you notify us of an incident that affects our data or services?
- Who is our point of contact during an incident, and what information will you share?
10. Business continuity and resilience
- Do you have business continuity and disaster recovery plans covering the services you provide us? When were they last tested?
- What are your recovery time and recovery point objectives for those services?
- Are backups protected from ransomware, for example with immutable or offline copies?
11. Subcontractors and fourth parties
- Which subcontractors or service providers will have access to our data? Provide a current list.
- How do you assess the security of your own vendors?
- Will you notify us before adding or changing subcontractors that handle our data?
12. People and AI use
- Do employees with access to our data pass background checks where permitted by law?
- Do all employees complete security awareness training at least annually?
- Do you use AI tools or models to process our data? If so, which ones, and is our data used to train them?
- Do you have an AI acceptable use policy for your staff?
Evidence to request
Documents that back up the answers
Ask critical vendors for supporting evidence. Answers without evidence are claims.
FAQ
Vendor security questionnaire questions
Related services
Related services
Get help reviewing vendors
Need help with third-party risk?
Tell us how many vendors you work with and what’s driving the review. An advisor will reply by email to talk through a program or a set of assessments.
Prefer email? Write to [email protected] or call (858) 712-0040.
