Glossary

What is Security questionnaire?

A security questionnaire is a structured set of questions a buyer sends a prospective vendor to assess how it protects data — covering access control, encryption, subprocessors, incident response, certifications and data residency. It is typically required before procurement approval, and answering it is a recurring cost for every vendor that sells to enterprises.

Last updated:

Security questionnaires exist because a buyer inherits its vendors' risk. If a SaaS tool holds your customer data, its weaknesses become yours, and regulators generally do not accept 'the vendor did it' as a defence.

The problem is not the questions but the duplication. Most questionnaires ask substantially the same things in different words and different formats — a spreadsheet from one buyer, a portal from another, a bespoke PDF from a third. A vendor selling to a hundred enterprises answers the same question about encryption at rest a hundred times, by hand, in a hundred layouts.

Standardised frameworks exist to reduce this: SIG, CAIQ, and in Japan buyer-specific チェックシート derived from ISMS control lists. They help, but adoption is partial, and most buyers still layer their own additions on top.

This is one of the clearest cases for structured agent-to-agent exchange. The underlying facts a vendor is asserting are stable and already documented — in its SOC 2 report, its ISO 27001 scope statement, its subprocessor list. What changes each time is only the shape of the question. When both sides exchange structured claims rather than prose, the vendor maintains one source of truth and the buyer receives answers that are directly comparable across vendors instead of a stack of differently-worded PDFs.

What should stay human: judging whether an answer is acceptable for your risk appetite, and following up on the answers that are technically true but evasive.

Frequently asked questions

Does a SOC 2 report replace a security questionnaire?
It reduces one but rarely replaces it. A SOC 2 report evidences controls the auditor tested within a defined scope; questionnaires also ask about scope boundaries, subprocessors, data residency and contractual commitments that the report may not address.
Who should answer a security questionnaire?
Whoever can be held to the answers — typically security or compliance, not sales. Answers become contractual representations in many deals, so a salesperson guessing at an encryption detail creates real liability rather than a minor inaccuracy.

Skip the discovery calls.

Describe what you need and let AgentDoor's agents interview the vendors for you — you get a decision-ready shortlist, not six meetings.

We'll reach out at launch. No spam, ever.