SecurSentry
← All notes
Security questionnaires

Security Questionnaire Examples, Explained Simply

A plain walk through the three security questionnaires you're most likely to be sent, with example questions and what a good, honest answer looks like.

The short version

You’ve won the interest of a bigger customer, the conversation is going well, and then a spreadsheet lands in your inbox with a name like “Vendor Security Assessment”. A hundred-odd questions, half of them in language you’ve never used. It’s a normal part of selling to larger organisations, and it catches almost every first-timer off guard.

The good news: these documents are more predictable than they look. There are a few standard shapes, the questions repeat across all of them, and once you’ve seen real examples you stop reading them as an exam and start reading them as a form. This piece walks through the three you’re most likely to be sent, with sample questions and what a solid, honest answer sounds like.

What a security questionnaire is, in plain terms

A security questionnaire is how a prospective customer checks that letting you into their world won’t create a problem for them.

When a company hands you their data, gives you access to their systems, or relies on your service, they inherit some of your risk. Their own auditors, insurers and regulators expect them to check before they sign. The questionnaire is that check, written down. Nothing about it is personal, and a request for one is usually a good sign: it means you’re being taken seriously as a supplier.

The format varies, but the intent never does. They want to understand how you control access, how you look after data, what happens if something goes wrong, and who else you depend on. Keep that in mind and even an intimidating spreadsheet becomes readable.

Example 1: a standardised set (SIG-style)

A standardised questionnaire uses an off-the-shelf bank of questions so the buyer isn’t reinventing the wheel for every supplier.

The best-known of these is the SIG, the Standardized Information Gathering questionnaire from Shared Assessments. The 2025 edition covers 21 risk domains organised under four control areas: governance and risk management, information protection, IT operations and business resilience, and security incident and threat management. The detailed version runs into the hundreds of questions. There’s also a shorter “Lite” version, closer to a hundred, which is what a smaller supplier is more likely to face first.

You’ll recognise the topics even if the labels are unfamiliar. A typical SIG-style section asks things like:

A good answer to the first one isn’t just “Yes”. It’s: “Yes. Multi-factor authentication is enforced for all remote access through our identity provider, covering every staff account with no exceptions.” You’ve answered the question, named the mechanism, and closed the obvious follow-up.

Spot the topic, not the jargon

Most questions in a standardised set are a formal way of asking something simple. "Cryptographic controls" means encryption. "Logical access provisioning" means how people get and lose accounts. Read past the wording to the topic and you'll usually find you already know the answer. You've just never had to phrase it this way.

Example 2: a cloud-focused set (CAIQ-style)

A CAIQ-style questionnaire zooms in on how you run things in the cloud.

The CAIQ, the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance, is built directly on top of the Cloud Controls Matrix, which spreads its controls across seventeen security domains. It comes as a spreadsheet of yes/no questions, each tied to a specific cloud control. If your product is a SaaS tool or you hold customer data in cloud services, this is the format a security-minded buyer may reach for.

Because it’s cloud-specific, the questions get more concrete about your infrastructure:

That last one matters for UK buyers, who often need to know data stays in the UK or EU. An honest answer names the region plainly: “Customer data is hosted in UK data centres and does not leave the UK.” If you genuinely don’t know where your cloud provider stores things, that’s worth finding out before you answer rather than guessing. The answer is sitting in your provider’s documentation.

The CAIQ asks not just whether a control exists, but how it’s implemented. A one-word “Yes” with no explanation reads as a box-tick. A sentence that says what you actually do reads as a real answer.

Example 3: the buyer’s own spreadsheet (bespoke)

Plenty of companies skip the standards entirely and write their own list of questions.

This is the most common format a small UK supplier meets, and the most unpredictable. A bespoke questionnaire reflects whatever that particular buyer cares about. Sometimes it’s a tidy two-page form. Sometimes it’s a sprawling sheet a security team has bolted onto over years, with duplicate questions and the odd one that makes no sense for your business.

The questions tend to be a mix of the familiar and the company-specific:

The breach question worries people most. The honest approach wins here too. If you’ve had no notifiable incidents, say so clearly. If you have, a calm description of what happened and what you changed afterwards is far more reassuring than a defensive non-answer. Buyers know incidents happen; they’re checking how you handle them. (The ICO sets out what counts as a reportable personal data breach in the UK, which is a useful reference for that whole section.)

For questions that genuinely don’t apply, “Not applicable” with a one-line reason is a perfectly good answer. Don’t leave blanks, and don’t invent a control to fill the gap.

What a good honest answer looks like, every time

Across all three formats, the recipe for a strong answer is the same: be specific, be honest, and reuse your work.

A weak answer is vague (“We take security seriously”) or inflated (claiming a control you don’t really have). A strong answer does three things. It states what you actually do. It names the policy, tool or process behind it. And where you’re not there yet, it says so plainly with a sensible date attached.

Here’s the same question answered two ways:

The strong version takes ten more seconds and earns far more trust. And once you’ve written it, you own it. That exact answer will fit the next questionnaire’s encryption question, whatever format it arrives in.

That’s the quiet truth behind all of this. Most questionnaires are asking the same things in different clothes. A small set of facts about your business (how you control access, how you protect data, how you back up, how you’d respond to an incident) answers the bulk of any format you’ll ever be sent. Build that set of honest answers once and most of the work becomes reuse. SecurSentry is being built around exactly that idea: getting the underlying controls in place and described clearly, so answering the next questionnaire is mostly looking things up rather than starting from scratch.

If you want to go deeper, our guide on how to answer a security questionnaire walks through the actual answering process step by step, SIG, CAIQ and DDQ explained for small suppliers unpacks the standard formats in more detail, and why security questionnaires kill deals covers the commercial side of getting through them quickly. The first questionnaire is the hardest. After that, you’re mostly filling in a form you’ve already half-written.

Frequently asked questions

What does a security questionnaire actually look like?

Usually a spreadsheet or web form with anywhere from a dozen to several hundred questions, grouped into sections like access control, data handling, and incident response. Most questions are yes/no with a comment box, or a short free-text answer. Some buyers send a recognised standard set such as the SIG or CAIQ; others write their own.

What are common security questionnaire questions?

The recurring ones cover who can access systems and how (passwords, multi-factor authentication), how data is stored and encrypted, how often you back up, whether staff get security training, how you'd respond to a breach, and which suppliers you rely on. The same themes appear in almost every questionnaire regardless of its name or length.

What is the difference between SIG and CAIQ?

The SIG (Standardized Information Gathering questionnaire, from Shared Assessments) is a broad third-party risk set covering governance, information protection, IT operations and incident response. The CAIQ (Consensus Assessments Initiative Questionnaire, from the Cloud Security Alliance) is built specifically around cloud security controls. The SIG is general-purpose; the CAIQ is for when the buyer cares about your cloud setup.

How should a small business answer a security questionnaire?

Answer truthfully and specifically. Describe the control you actually have, name the policy or tool behind it, and keep it short. If you don't do something yet, say so and add when you plan to. A clear, honest answer beats a vague or inflated one every time.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

UK GDPR

What a Record of Processing Activities (ROPA) Is, and How to Build One

19 Jul 2026 · 7 min
UK GDPR

Personal Data Breach: What a Small Business Must Do

16 Jul 2026 · 6 min
EU AI Act

EU AI Act Timeline: When Each Rule Starts to Bite

13 Jul 2026 · 7 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.