4 MIN READ
The vendor security questionnaire, in 2026, is still the same 500 question form it was in 2016. Vendors changed. Threats changed. Cloud architectures changed. The form did not. A SaaS vendor that runs entirely on a hyperscaler with no physical office gets asked about fence height and guard rotation. A vendor with five engineers gets asked about its employee training program and the percentage of staff who completed it last quarter. The form is treating a 200 person startup the same as a 200,000 person bank, and the answers are mostly noise.
The cost of the noise lands on both sides. A vendor filling out a 500 question form for a typical buyer base spends somewhere between 100 and 500 hours a year on questionnaires. A buyer reviewing 200 vendors a year spends 800 to 1,600 hours doing it. Most of the time goes to questions that do not predict a breach, and a meaningful chunk of it goes to the same question answered slightly differently for every buyer. The result is a process that exhausts the people running it and produces a snapshot of the vendor that the buyer could have produced in an hour with a SOC 2 and a coffee.
What the questionnaire should ask
Data handling comes first because it covers the most important risk a vendor introduces. What data the vendor touches, where it sits, how it sits protected at rest and in transit, who can reach it inside the vendor’s environment, how long the vendor keeps it, and what happens to it when the contract ends. If the buyer cannot get a clear answer to those questions, the rest of the questionnaire amounts to paperwork. The data handling section maps directly to the actual exposure.
Access control is the second question that matters, and it sits right behind data handling because the answer to “who can reach the data” is usually less reassuring than the data classification section made it sound. How the vendor enforces MFA on its own staff, how privileged access is granted and revoked, how the joiner mover leaver lifecycle works in practice (not in policy). The vendors that have thought about this will answer it in a paragraph. The ones that have not will point you to a policy document and hope you stop reading.
Incident response is third, and the answer should tell the buyer how the vendor behaves on the worst day of the vendor’s life. How the vendor detects an incident, how the response actually runs (not the playbook, the rehearsal), how the vendor notifies the customer, and what the recovery looks like in practice. A vendor that has actually had an incident and learned from it is a different vendor from one that has a clean SOC 2 and a tabletop exercise scheduled for next quarter.
Compliance certification is fourth, and the buyer should treat it as a hygiene check, not a guarantee. SOC 2 Type II, ISO 27001, PCI DSS where relevant, HIPAA where relevant. The certification tells the buyer that an auditor walked through the vendor’s controls at some point. It does not tell the buyer whether the controls are still operating. The buyer who treats the cert as the answer is the buyer who finds out the cert was renewed on autopilot.
What the questionnaire should not ask
First on the list to drop from the modern questionnaire is physical security. A SaaS vendor that runs on AWS, Azure, or GCP has no fence, no guard, no badge reader in the sense the form is asking about. The physical security of the vendor’s data center amounts to the physical security of the hyperscaler, and the hyperscaler already answers that question in its own SOC 2. Asking a 50 person startup whether its office has a mantrap entry is asking a question the buyer does not actually need answered.
Employee training questions follow. Whether the vendor trains its staff on security awareness, how often, what percentage completed the last round, what the curriculum covers. The form is checking a box. The training exists, the staff clicked through the module, the dashboard reports near perfect completion, and the actual phishing click rate did not move. The question produces compliance theatre, not a security outcome.
Detailed technical questions are the third category to cut. Whether the vendor uses AES-256, whether TLS 1.3 is enabled, whether the database has column level encryption. The buyer who needs to specify the cipher suite is a buyer who is going to write the wrong one in a year when the standards move. The right question is whether the vendor follows current best practice and can show evidence. The wrong question is whether the vendor uses the specific tool the buyer’s 2019 reference architecture recommended.
Policy existence is the fourth cut. Whether the vendor has an information security policy, an acceptable use policy, a data retention policy, a business continuity plan. The vendor will say yes, the buyer will receive a zip file of PDFs, and the buyer will not read them because reading them does not change the risk picture. The vendor that has the policies but does not run them is indistinguishable from the vendor that has the policies and does. The questionnaire cannot tell the difference, and so the question is a waste of both sides’ time.
How to make the questionnaire work
Use a standard questionnaire instead of writing your own. The Shared Assessments SIG and the Cloud Security Alliance CAIQ are the two the industry has settled on. A vendor that fills out the SIG or the CAIQ once can attach the same response to every buyer that asks. A buyer that accepts the SIG or the CAIQ can compare vendors on the same axes, on the same year, on the same answer field. The custom 500 question form forces the vendor to reformat the same answer five times a quarter and produces a document the buyer cannot meaningfully compare across vendors.
Tier the vendors by criticality before sending the questionnaire. A vendor that handles customer data, holds production credentials, or can take down a critical system deserves the deep questionnaire, the SOC 2 review, and the on site audit. A vendor that sells office supplies, books travel, or runs the marketing automation deserves the standard form and nothing more. The buyer that sends the 500 question form to the travel vendor is the buyer whose security team is too busy to do the work that actually matters.
Trust but verify, because the questionnaire does not catch the actual security posture. The verification is the SOC 2 review, the on site audit for the critical tier, the penetration test report, and the occasional evidence request (a sample of access logs, a sample of the joiner mover leaver ticket trail, a current vulnerability scan output). A buyer that runs the questionnaire, accepts the answers, and moves on is a buyer whose questionnaire is a compliance artefact. A buyer that runs the questionnaire, checks the critical answers against evidence, and follows up where the evidence is thin is a buyer whose questionnaire is doing the job.

The bottom line
Data handling, access control, incident response, compliance certification. Drop the fence questions, the training percentage, the cipher suite, and the policy existence check. Use the standard form, tier the vendors, verify the critical answers against evidence. The buyer who runs that playbook gets back the hundreds of hours a year the questionnaire was eating, and gets better answers in the time that is left.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



