Our approach draws on the consulting background described on our expertise page. See our editorial and quality standards for how we prepare these resources.
A useful vendor security questionnaire is short enough to complete and specific enough to reveal whether a deeper conversation is needed.
Questions should follow the relationship. Ask about the controls that matter for the data, access, service, and impact involved.
Working checklist
- Security responsibility and contact
- Data collection, location, retention, and deletion
- Access control, MFA, and privileged access
- Encryption in transit and at rest
- Vulnerability and patch management
- Logging, monitoring, and incident response
- Backups, recovery, and continuity
- Employee screening and security training
- Subprocessors and fourth parties
- Independent testing, certifications, and available evidence
A practical way to approach it
1Tier the vendor first
Use the initial risk facts to choose a Low, Moderate, High, or Critical questionnaire.
2Explain the context
Tell the vendor what service is being reviewed and how answers will be used.
3Allow evidence references
Ask vendors to point to policies, reports, test summaries, or contractual commitments.
4Review inconsistencies
Follow up when answers conflict, rely on vague marketing language, or leave key items unknown.
5Record the disposition
Document accepted answers, exceptions, remediation, and the final decision.
Common mistakes to avoid
- Sending 200 questions to a low-risk supplier
- Treating yes-or-no answers as proof
- Requesting sensitive evidence you cannot protect
- Accepting expired or irrelevant reports
- Failing to follow up on unanswered questions
Questionnaires work when they support judgment; they fail when completion becomes the only goal.
Sources and further reading
- NIST Cybersecurity Framework 2.0
- NIST SP 800-161 Rev. 1: Supply Chain Risk Management
- CISA Cyber Guidance for Small Businesses
- FTC Cybersecurity for Small Business
These sources inform the methodology. Inclusion does not imply endorsement, certification, or applicability to every organization. The worked examples and decision prompts are PBW’s practical guidance.
This guidance is a general business resource, not legal, insurance, cybersecurity, or regulatory-compliance advice. Adapt it to your circumstances and obtain qualified advice when appropriate.