Vendor security assessment questionnaire template, free to send

Sort your vendors first, then send questions only to the few that can reach your data. All 24 are free to copy.

This vendor security assessment questionnaire template is free: 24 questions in six groups, ready to paste into an email. Before you send it, sort your vendors. Only the ones that can reach your customer data or production need the full set. The rest need a line in a spreadsheet and nothing more.

Sort vendors before you send anything

Sending a questionnaire costs you time twice: once to send and chase, once to read. Spend that time only where the risk is. Rank vendors by what they can reach, not by the size of the invoice. A low-cost logging tool may see every request your app handles. An expensive furniture contract sees nothing. Three tiers are enough.

TierCan reachSendAsk again
1, criticalCustomer data, production, identity or source codeAll 24 questions and their reportYearly
2, limitedInternal data only, no productionGroups A, B and CEvery two years
3, peripheralNothing of yoursNo form, just a register rowWhen its reach changes

Keep the register current as you sign up new tools. Several requests on a SOC 2 evidence request list ask for exactly this: the vendor list, the assurance you collected and the risk review before data started flowing. Rebuilding that a year later is slow and error prone.

The 24 questions

Numbered straight through so you can send the whole list or split groups between owners. Each one can be answered with a sentence or a document name. None asks the vendor to describe a philosophy, because answers like that can never later turn out to be false.

A. The company

  1. What is your registered legal name and country of registration?
  2. Which of your products will we use, and what will it do with our data?
  3. Who is your security contact, and how do we escalate?

B. Independent assurance

  1. Do you have a current SOC 2 Type 2 report, and for what period?
  2. Which criteria are in scope, and which vendors of yours are carved out?
  3. If that period closed more than three months ago, will you provide a bridge letter?
  4. When was your most recent penetration test, and may we see the summary?

C. Our data

  1. Which kinds of our data will you hold, and in which countries?
  2. How is our data encrypted in transit and at rest?
  3. How do you keep our data separate from other customers’ data?
  4. How long do you keep our data after we leave, and how do you confirm deletion?
  5. Which of your staff can read our production data, and who approves that?

D. Access and change

  1. Do all your staff use multi factor authentication for production?
  2. Can our users sign in through our single sign on, and on which plan?
  3. How fast do you remove access when one of your staff leaves?
  4. How are production changes reviewed and approved?

E. Incidents and staff

  1. Have you had a security incident involving customer data in the past two years?
  2. How many hours or days after confirming a breach would you tell us?
  3. Are staff with production access background checked?
  4. How often do staff complete security training?

F. Subprocessors and recovery

  1. Which subprocessors touch our data, and where is that list published?
  2. How much notice do we get before you add one?
  3. What are your recovery time and recovery point targets, and when did you last test a restore?
  4. Do you hold cyber insurance, and what is the limit?

Questions to leave out

Cutting questions saves both sides time. Drop anything whose answer would not change your decision. Three examples:

  • “Do you have a security policy?” Everyone says yes. Ask about the specific control instead, like question 15.
  • “Describe your security culture.” No answer to it can ever be proven wrong, so it tells you nothing.
  • Anything their report already answers. Read the report first rather than making them retype it into your form.

If they send a SOC 2 report instead

Good. A report holds evidence that a licensed CPA firm tested against set criteria.1 A filled in form holds what the vendor says about itself. Take the report and do three things. First, check it is genuine and current: signer, period, scope and exceptions, using how to tell if a SOC 2 report is real. Second, read the complementary user entity controls. They are jobs assigned to you, and if you skip them the vendor’s controls may not hold.2 The CUEC guide explains. Third, send only what the report leaves open, usually questions 8, 11, 14, 21 and 24, since a report covers the vendor’s system and not your contract. Then write a dated note of who read it and what they concluded. A report sitting in a folder proves nobody read it.

If a critical vendor has no report

That is not an automatic no. It means you gather assurance another way and record the decision. Get all 24 answers in writing from a named person, with a date. An email thread counts, a phone call does not. Ask for what they do have, like a pen test summary or an ISO 27001 certificate. Put the rest into the contract: a breach notice window in hours, a deletion duty, subprocessor notice and a right to re-assess. Finally, log the exception with the vendor, the gap, who accepted it and when you will look again. Your own examination tests your vendor management, so that record is what counts.

When to ask again

Follow the tier table, and time Tier 1 reviews to land after the vendor’s report period ends so you read fresh coverage. Four events pull a review forward: the vendor starts touching customer data and moves up a tier, its report lapses with no bridge letter, it announces a breach, or it adds a subprocessor that handles your data.

Free template, or tracked for you

Sending this questionnaire costs nothing. Keeping a register current, with dated review notes, is the part that slips as the vendor list grows. The cybersoftware software generates the register and tracks each review and its evidence, at $199 a month, cancel any time. Try the free readiness assessment first, or compare plans on pricing.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

How do I decide which vendors to assess?
Rank them by what they can reach, not by what they cost. Tier 1 holds customer data or can reach production, identity or source code. Tier 2 holds internal data only. Tier 3 reaches nothing of yours and gets a register entry but no questionnaire.
What makes a good vendor security question?
One that can be answered with a sentence or a document and could later be shown wrong. Ask where your data is stored, how it is encrypted, who can read it, what happens when you leave, how fast they report a breach, who their subprocessors are, and whether they hold a current SOC 2 Type 2 report.
A vendor sent a SOC 2 report instead of answering. Is that enough?
Accept it, since a CPA firm tested it. Check the signer, period and scope, read the complementary user entity controls because those are your jobs, and send only the questions the report leaves open. Contract matters such as data location, deletion and subprocessor notice stay on your list.
What if an important vendor has no SOC 2 report?
Get written answers from a named person with a date, ask for other assurance such as a pen test summary or an ISO 27001 certificate, and put the rest into the contract: a breach notice window, a deletion duty and subprocessor notice. Then record the exception with an owner and a review date.
How often should vendors be re-assessed?
Tier 1 yearly, timed after their report period ends. Tier 2 every two years. Tier 3 only if its reach changes. Move a review forward if the vendor changes tier, lets its report lapse with no bridge letter, announces a breach or adds a subprocessor that touches your data.

Sources

  1. SOC 2 Report AICPA. What a SOC 2 report is and who may issue one. Checked 1 August 2026.
  2. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.