Security Questionnaire Examples, Explained Simply
A plain walk through the three security questionnaires you're most likely to be sent, with example questions and what a good, honest answer looks like.
The short version
- Three common shapes: a standardised set like the SIG, a cloud-focused set like the CAIQ, or a buyer's own bespoke spreadsheet. They look different, but the underlying questions overlap a lot.
- Questions cluster by topic: access control, data protection, backups, supplier management, incident response. Once you spot the topic, the question is far less scary.
- A good answer is specific and honest: say what you do, name the tool or policy, and where you're not there yet, say so plainly with a date. Bluffing is the thing that loses trust.
- You can reuse most of it: the same handful of facts about your business answers most questions across every format you'll ever be sent.
You’ve won the interest of a bigger customer, the conversation is going well, and then a spreadsheet lands in your inbox with a name like “Vendor Security Assessment”. A hundred-odd questions, half of them in language you’ve never used. It’s a normal part of selling to larger organisations, and it catches almost every first-timer off guard.
The good news: these documents are more predictable than they look. There are a few standard shapes, the questions repeat across all of them, and once you’ve seen real examples you stop reading them as an exam and start reading them as a form. This piece walks through the three you’re most likely to be sent, with sample questions and what a solid, honest answer sounds like.
What a security questionnaire is, in plain terms
A security questionnaire is how a prospective customer checks that letting you into their world won’t create a problem for them.
When a company hands you their data, gives you access to their systems, or relies on your service, they inherit some of your risk. Their own auditors, insurers and regulators expect them to check before they sign. The questionnaire is that check, written down. Nothing about it is personal, and a request for one is usually a good sign: it means you’re being taken seriously as a supplier.
The format varies, but the intent never does. They want to understand how you control access, how you look after data, what happens if something goes wrong, and who else you depend on. Keep that in mind and even an intimidating spreadsheet becomes readable.
Example 1: a standardised set (SIG-style)
A standardised questionnaire uses an off-the-shelf bank of questions so the buyer isn’t reinventing the wheel for every supplier.
The best-known of these is the SIG, the Standardized Information Gathering questionnaire from Shared Assessments. The 2025 edition covers 21 risk domains organised under four control areas: governance and risk management, information protection, IT operations and business resilience, and security incident and threat management. The detailed version runs into the hundreds of questions. There’s also a shorter “Lite” version, closer to a hundred, which is what a smaller supplier is more likely to face first.
You’ll recognise the topics even if the labels are unfamiliar. A typical SIG-style section asks things like:
- Access control: “Is multi-factor authentication required for remote access to systems that hold customer data?”
- Data protection: “Is data encrypted both in transit and at rest?”
- Backup and resilience: “How frequently are backups taken, and have you tested that you can restore from them?”
- Supplier management: “Do you assess the security of your own third-party suppliers?”
- Incident response: “Do you have a documented process for responding to a security incident, and who owns it?”
A good answer to the first one isn’t just “Yes”. It’s: “Yes. Multi-factor authentication is enforced for all remote access through our identity provider, covering every staff account with no exceptions.” You’ve answered the question, named the mechanism, and closed the obvious follow-up.
Spot the topic, not the jargon
Most questions in a standardised set are a formal way of asking something simple. "Cryptographic controls" means encryption. "Logical access provisioning" means how people get and lose accounts. Read past the wording to the topic and you'll usually find you already know the answer. You've just never had to phrase it this way.
Example 2: a cloud-focused set (CAIQ-style)
A CAIQ-style questionnaire zooms in on how you run things in the cloud.
The CAIQ, the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance, is built directly on top of the Cloud Controls Matrix, which spreads its controls across seventeen security domains. It comes as a spreadsheet of yes/no questions, each tied to a specific cloud control. If your product is a SaaS tool or you hold customer data in cloud services, this is the format a security-minded buyer may reach for.
Because it’s cloud-specific, the questions get more concrete about your infrastructure:
- Identity and access: “Are administrative accounts to your cloud environment protected by multi-factor authentication?”
- Encryption and key management: “Is customer data encrypted at rest, and who controls the encryption keys?”
- Change management: “Are changes to production systems reviewed and approved before they go live?”
- Data location: “In which geographic regions is customer data stored?”
That last one matters for UK buyers, who often need to know data stays in the UK or EU. An honest answer names the region plainly: “Customer data is hosted in UK data centres and does not leave the UK.” If you genuinely don’t know where your cloud provider stores things, that’s worth finding out before you answer rather than guessing. The answer is sitting in your provider’s documentation.
The CAIQ asks not just whether a control exists, but how it’s implemented. A one-word “Yes” with no explanation reads as a box-tick. A sentence that says what you actually do reads as a real answer.
Example 3: the buyer’s own spreadsheet (bespoke)
Plenty of companies skip the standards entirely and write their own list of questions.
This is the most common format a small UK supplier meets, and the most unpredictable. A bespoke questionnaire reflects whatever that particular buyer cares about. Sometimes it’s a tidy two-page form. Sometimes it’s a sprawling sheet a security team has bolted onto over years, with duplicate questions and the odd one that makes no sense for your business.
The questions tend to be a mix of the familiar and the company-specific:
- “Do you hold Cyber Essentials or any other security certification?”
- “Have you had a security breach in the last 24 months? If so, describe it.”
- “Where are your staff based, and do any work from outside the UK?”
- “Can you provide a copy of your information security policy?”
- “Do you carry cyber insurance, and to what level?”
The breach question worries people most. The honest approach wins here too. If you’ve had no notifiable incidents, say so clearly. If you have, a calm description of what happened and what you changed afterwards is far more reassuring than a defensive non-answer. Buyers know incidents happen; they’re checking how you handle them. (The ICO sets out what counts as a reportable personal data breach in the UK, which is a useful reference for that whole section.)
For questions that genuinely don’t apply, “Not applicable” with a one-line reason is a perfectly good answer. Don’t leave blanks, and don’t invent a control to fill the gap.
What a good honest answer looks like, every time
Across all three formats, the recipe for a strong answer is the same: be specific, be honest, and reuse your work.
A weak answer is vague (“We take security seriously”) or inflated (claiming a control you don’t really have). A strong answer does three things. It states what you actually do. It names the policy, tool or process behind it. And where you’re not there yet, it says so plainly with a sensible date attached.
Here’s the same question answered two ways:
- Weak: “Yes, we have good security practices in place.”
- Strong: “Yes. All staff laptops have full-disk encryption enabled and automatic screen lock after five minutes, managed centrally through our device management tool.”
The strong version takes ten more seconds and earns far more trust. And once you’ve written it, you own it. That exact answer will fit the next questionnaire’s encryption question, whatever format it arrives in.
That’s the quiet truth behind all of this. Most questionnaires are asking the same things in different clothes. A small set of facts about your business (how you control access, how you protect data, how you back up, how you’d respond to an incident) answers the bulk of any format you’ll ever be sent. Build that set of honest answers once and most of the work becomes reuse. SecurSentry is being built around exactly that idea: getting the underlying controls in place and described clearly, so answering the next questionnaire is mostly looking things up rather than starting from scratch.
If you want to go deeper, our guide on how to answer a security questionnaire walks through the actual answering process step by step, SIG, CAIQ and DDQ explained for small suppliers unpacks the standard formats in more detail, and why security questionnaires kill deals covers the commercial side of getting through them quickly. The first questionnaire is the hardest. After that, you’re mostly filling in a form you’ve already half-written.