◆ traztech
Vendor Security Questionnaire Template
A concise questionnaire to assess the security of a vendor or subprocessor before you rely on them. Also useful to pre-answer the ones your buyers send you.
Use this to run third-party risk, and to prepare for the SIG/CAIQ/VSA questionnaires enterprise buyers will send you. Answer from what is actually true; fabricated answers fall apart under evidence requests.
Company & compliance
- Do you hold SOC 2, ISO 27001, or equivalent? Attach the report.
- Where is data hosted and in which regions?
- Who are your subprocessors, and are they vetted?
Access & data
- Is MFA enforced for all employee access?
- Is customer data encrypted at rest and in transit?
- How is access granted, reviewed, and revoked?
- What is your data retention and deletion policy?
Operations
- Do you have a tested incident response plan and breach notification SLA?
- How often do you run penetration tests and vulnerability scans?
- What is your change management and secure development process?
Continuity & contract
- What are your backup, recovery, and uptime commitments?
- Do you carry cyber insurance?
- Will you sign a DPA/BAA as applicable?