Glossary

Security Questionnaire

A security questionnaire is a buyer’s structured interrogation of your security posture — anywhere from twenty questions to several hundred, arriving as a spreadsheet, a portal, or a standardized instrument like the CAIQ or SIG. It’s procurement’s vendor-risk process made tangible, and for most B2B SaaS companies it’s the single most frequent compliance artifact.

Why they hurt

The pain is structural: questions repeat across buyers but never identically, answers live in engineers’ heads, and every questionnaire lands mid-sprint with a deal attached. The result is the 11pm questionnaire session — senior people re-deriving the same sixty answers per deal.

The system that fixes it

An answer library as a living document: every question answered once, canonically, with an owner and a review date. Standard instruments (CAIQ, SIG Lite) completed and current — many buyers accept them outright. A SOC 2 report and trust center that pre-answer the majority before the spreadsheet arrives. With the system, turnaround drops from weeks to days; without it, every deal pays the tax again.

When to outsource it

Volume past a few per month, or answers requiring judgment nobody has time to apply. Questionnaire support exists as a service precisely because this is the most outsourceable recurring artifact in compliance — the library gets built once, then maintained by people who do nothing else.

Related Terms

CAIQ — The CAIQ is the Cloud Security Alliance's standard security questionnaire — a yes/no assessment cloud vendors complete once and reuse across customer reviews.

SIG Questionnaire — The SIG is Shared Assessments' standardized vendor-risk questionnaire. SIG Core and SIG Lite let buyers assess vendors with one reusable question set.

Trust Center — A trust center is a public page where buyers self-serve your security posture — certifications, sub-processors, and NDA-gated reports. Now table stakes.