Definition
A security questionnaire, such as the SIG, is a standardised set of questions used to assess a vendor's security, privacy, and compliance controls during due diligence.
The questionnaire is only as good as how you read the answers - vague or evasive responses matter more than the checkboxes. Pair it with independent evidence like a SOC 2 report rather than taking self-attestation at face value.
Go deeperVendor due diligence checklistRelated terms
Benchside turns security questionnaire into the exact questions, exclusions, and lock-in math for your specific vendor - your first project is free.