Free template

Vendor security questionnaire template

The questions to ask before a vendor gets access to your data or network, grouped by security domain, with the evidence to request alongside the answers. Copy the questions you need and scale them to each vendor’s risk.

  • Questions grouped into 12 security domains
  • Evidence to request, not just answers
  • Tiering guidance so reviews match the risk
Network map of connected third parties

How to use it

Send the right questions to the right vendors

1

Inventory your vendors

List every third party that stores, processes or can access your data or systems, including software you subscribe to.

2

Tier by risk

Rank vendors by the sensitivity of the data they hold and the access they have. Critical vendors get the full questionnaire; low-risk vendors get a short version.

3

Ask for evidence

Request the documents listed below to back up key answers. A SOC 2 report or ISO 27001 certificate can replace many questions.

4

Score and follow up

Flag gaps, agree on fixes or contract terms, and repeat the review on a schedule and when the relationship changes.

The questionnaire

Vendor security questions by domain

1. Company and governance

  1. Who is responsible for information security at your company, and to whom do they report?
  2. Do you have a documented information security program that leadership has approved and reviews at least annually?
  3. Have you had a security breach or incident affecting customer data in the past three years? If so, describe it and what changed.
  4. Do you carry cyber liability insurance?

2. Compliance and attestations

  1. Do you have a current SOC 2 Type 2 report, ISO 27001 certificate or equivalent independent assessment? Which services are in scope?
  2. Which regulations apply to the services you provide us (for example HIPAA, PCI DSS, CMMC or state privacy laws), and how do you comply?
  3. Will you sign a business associate agreement or data processing agreement if required?
  4. When was your last penetration test performed by an independent party, and were critical findings fixed?

3. Data handling and privacy

  1. What types of our data will you store, process or access?
  2. Where is our data stored and processed, including backups? Name the countries and hosting providers.
  3. Is our data encrypted in transit and at rest? Who manages the encryption keys?
  4. How is our data separated from other customers’ data?
  5. How long do you keep our data, and how do you return or destroy it when the contract ends?

4. Access control and identity

  1. Is multi-factor authentication required for all access to systems that hold our data, including administrative and remote access?
  2. Do you support single sign-on with our identity provider?
  3. How do you grant, review and remove employee access? How often are access reviews performed?
  4. How are privileged accounts managed and monitored?

5. Infrastructure and network security

  1. How is your network segmented to protect systems that handle customer data?
  2. Which firewall, endpoint protection and email security controls are in place?
  3. How are cloud environments configured and reviewed against security baselines?
  4. If you will connect to our network, how is that connection secured and limited?

6. Application security

  1. Do you follow a secure development process, including code review and security testing before release?
  2. How do you manage vulnerabilities in open source and third-party components?
  3. Are your applications and APIs tested against the OWASP Top 10?

7. Vulnerability management

  1. How often do you scan for vulnerabilities, and what are your target timelines for fixing critical and high findings?
  2. How do you track and apply security patches for operating systems and applications?
  3. Do you run a vulnerability disclosure or bug bounty program?

8. Logging and monitoring

  1. Do you monitor systems that hold our data for security events around the clock?
  2. Which events are logged, and how long are logs retained?
  3. Can you provide logs related to our account if we need them for an investigation?

9. Incident response and notification

  1. Do you have a documented incident response plan, and when was it last tested?
  2. How and how quickly will you notify us of an incident that affects our data or services?
  3. Who is our point of contact during an incident, and what information will you share?

10. Business continuity and resilience

  1. Do you have business continuity and disaster recovery plans covering the services you provide us? When were they last tested?
  2. What are your recovery time and recovery point objectives for those services?
  3. Are backups protected from ransomware, for example with immutable or offline copies?

11. Subcontractors and fourth parties

  1. Which subcontractors or service providers will have access to our data? Provide a current list.
  2. How do you assess the security of your own vendors?
  3. Will you notify us before adding or changing subcontractors that handle our data?

12. People and AI use

  1. Do employees with access to our data pass background checks where permitted by law?
  2. Do all employees complete security awareness training at least annually?
  3. Do you use AI tools or models to process our data? If so, which ones, and is our data used to train them?
  4. Do you have an AI acceptable use policy for your staff?

Evidence to request

Documents that back up the answers

Ask critical vendors for supporting evidence. Answers without evidence are claims.

  • SOC 2 Type 2 report, with bridge letter if the period has ended
  • ISO 27001 certificate and statement of applicability
  • Summary of the most recent independent penetration test
  • Information security and incident response policies
  • Certificate of cyber liability insurance
  • List of subcontractors that handle your data
  • Business continuity and disaster recovery test results
  • Signed data processing or business associate agreement

FAQ

Vendor security questionnaire questions

It’s a set of questions you send to a third party to understand how it protects your data and systems. It’s one part of third-party risk management, alongside contract terms, evidence review and ongoing monitoring.

No. Tier vendors by the data and access they have. Critical vendors get the full set and evidence requests; low-risk vendors might answer only a handful of questions.

Often, for the controls it covers. Check that the report is current, that the services you use are in scope and that the exceptions and complementary user entity controls are acceptable. Then ask only the questions the report doesn’t answer.

Review critical vendors at least annually and whenever something changes, such as a new service, a breach or a change in ownership. Lower-risk vendors can be reviewed less often.

It depends on how many vendors you have, how many are critical, and whether you want a one-time assessment of your program or ongoing reviews. Scope drives the cost more than anything else.

Get help reviewing vendors

Need help with third-party risk?

Tell us how many vendors you work with and what’s driving the review. An advisor will reply by email to talk through a program or a set of assessments.

  • Help tailoring the questionnaire to your vendors
  • Vendor reviews run by Triden advisors

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message