Vendor security assessment questionnaire template, free to send
Sort your vendors first, then send questions only to the few that can reach your data. All 24 are free to copy.
This vendor security assessment questionnaire template is free: 24 questions in six groups, ready to paste into an email. Before you send it, sort your vendors. Only the ones that can reach your customer data or production need the full set. The rest need a line in a spreadsheet and nothing more.
Sort vendors before you send anything
Sending a questionnaire costs you time twice: once to send and chase, once to read. Spend that time only where the risk is. Rank vendors by what they can reach, not by the size of the invoice. A low-cost logging tool may see every request your app handles. An expensive furniture contract sees nothing. Three tiers are enough.
| Tier | Can reach | Send | Ask again |
|---|---|---|---|
| 1, critical | Customer data, production, identity or source code | All 24 questions and their report | Yearly |
| 2, limited | Internal data only, no production | Groups A, B and C | Every two years |
| 3, peripheral | Nothing of yours | No form, just a register row | When its reach changes |
Keep the register current as you sign up new tools. Several requests on a SOC 2 evidence request list ask for exactly this: the vendor list, the assurance you collected and the risk review before data started flowing. Rebuilding that a year later is slow and error prone.
The 24 questions
Numbered straight through so you can send the whole list or split groups between owners. Each one can be answered with a sentence or a document name. None asks the vendor to describe a philosophy, because answers like that can never later turn out to be false.
A. The company
- What is your registered legal name and country of registration?
- Which of your products will we use, and what will it do with our data?
- Who is your security contact, and how do we escalate?
B. Independent assurance
- Do you have a current SOC 2 Type 2 report, and for what period?
- Which criteria are in scope, and which vendors of yours are carved out?
- If that period closed more than three months ago, will you provide a bridge letter?
- When was your most recent penetration test, and may we see the summary?
C. Our data
- Which kinds of our data will you hold, and in which countries?
- How is our data encrypted in transit and at rest?
- How do you keep our data separate from other customers’ data?
- How long do you keep our data after we leave, and how do you confirm deletion?
- Which of your staff can read our production data, and who approves that?
D. Access and change
- Do all your staff use multi factor authentication for production?
- Can our users sign in through our single sign on, and on which plan?
- How fast do you remove access when one of your staff leaves?
- How are production changes reviewed and approved?
E. Incidents and staff
- Have you had a security incident involving customer data in the past two years?
- How many hours or days after confirming a breach would you tell us?
- Are staff with production access background checked?
- How often do staff complete security training?
F. Subprocessors and recovery
- Which subprocessors touch our data, and where is that list published?
- How much notice do we get before you add one?
- What are your recovery time and recovery point targets, and when did you last test a restore?
- Do you hold cyber insurance, and what is the limit?
Questions to leave out
Cutting questions saves both sides time. Drop anything whose answer would not change your decision. Three examples:
- “Do you have a security policy?” Everyone says yes. Ask about the specific control instead, like question 15.
- “Describe your security culture.” No answer to it can ever be proven wrong, so it tells you nothing.
- Anything their report already answers. Read the report first rather than making them retype it into your form.
If they send a SOC 2 report instead
Good. A report holds evidence that a licensed CPA firm tested against set criteria.1 A filled in form holds what the vendor says about itself. Take the report and do three things. First, check it is genuine and current: signer, period, scope and exceptions, using how to tell if a SOC 2 report is real. Second, read the complementary user entity controls. They are jobs assigned to you, and if you skip them the vendor’s controls may not hold.2 The CUEC guide explains. Third, send only what the report leaves open, usually questions 8, 11, 14, 21 and 24, since a report covers the vendor’s system and not your contract. Then write a dated note of who read it and what they concluded. A report sitting in a folder proves nobody read it.
If a critical vendor has no report
That is not an automatic no. It means you gather assurance another way and record the decision. Get all 24 answers in writing from a named person, with a date. An email thread counts, a phone call does not. Ask for what they do have, like a pen test summary or an ISO 27001 certificate. Put the rest into the contract: a breach notice window in hours, a deletion duty, subprocessor notice and a right to re-assess. Finally, log the exception with the vendor, the gap, who accepted it and when you will look again. Your own examination tests your vendor management, so that record is what counts.
When to ask again
Follow the tier table, and time Tier 1 reviews to land after the vendor’s report period ends so you read fresh coverage. Four events pull a review forward: the vendor starts touching customer data and moves up a tier, its report lapses with no bridge letter, it announces a breach, or it adds a subprocessor that handles your data.
Free template, or tracked for you
Sending this questionnaire costs nothing. Keeping a register current, with dated review notes, is the part that slips as the vendor list grows. The cybersoftware software generates the register and tracks each review and its evidence, at $199 a month, cancel any time. Try the free readiness assessment first, or compare plans on pricing.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
How do I decide which vendors to assess?
What makes a good vendor security question?
A vendor sent a SOC 2 report instead of answering. Is that enough?
What if an important vendor has no SOC 2 report?
How often should vendors be re-assessed?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.