Glossary
Definition·2 min read

Security questionnaire

Definition

A buyer's structured assessment of a vendor's security, privacy and infrastructure practices — one of the longest stages in enterprise procurement.

Also called: vendor risk questionnaire, vendor security assessment, third-party risk review

A security questionnaire is a buyer’s structured assessment of how a vendor handles data, access, infrastructure and incidents. It typically arrives after the commercial conversation is going well, often as a spreadsheet or a portal, and it can run from a dozen questions to several hundred.

It is near-universal in enterprise deals, and it is one of the longest stages in enterprise software procurement.

What it usually asks

Data location and residency. Encryption at rest and in transit, and who holds the keys. Retention and deletion. Subprocessors and their locations. Access control and review cadence. Incident response and breach-notification windows. Business continuity and recovery. Certifications held versus in progress. And increasingly: how your product uses AI, what it trains on, and whether a buyer’s data ever reaches a third-party model.

Why it stalls

The questionnaire arrives to the rep, because the rep is the address the buyer has. The rep cannot answer it. It goes to security, who can — and who are measured on being right rather than on your close date. Part of it goes to IT, who own the systems but have never seen this buyer’s phrasing.

Sales owns the deal, not the answer. Security owns the truth, not the deadline. IT owns the systems, not the buyer. Each is correct that it isn’t theirs.

So it sits in the space between three functions, moved along only by a rep sending follow-ups. It is a real stage in your sales cycle, with a start date, an end date and no owner — and it appears on no org chart and in no pipeline review.

What good looks like

Not a bigger library of past answers. Four things:

  • A named person per content domain — one name against security, one against privacy, one against infrastructure — who can say that the current answer is the current answer.
  • One canonical version of each recurring answer, with its source attached — the policy, the audit report, the person who confirmed it. An answer with no source is a sentence that worked once.
  • An expiry per domain. Infrastructure answers age in weeks; company boilerplate ages in years. One annual review cadence is wrong for both.
  • A consistency check across what you’ve already sent, so two buyers asking the same question in the same quarter don’t receive two different answers.

Speed follows from those. It does not substitute for them — a team answering faster on an ungoverned library just ships unverified answers on a shorter timeline.

Deeper: Nobody owns the security questionnaire · Two buyers. Same question. Two answers.

Talk it through

Is this the thing slowing your deals down?

If this definition described something you recognise, that is usually a process problem rather than a tooling one. Tell me where it is breaking and I will tell you honestly whether I can help.

No pitch. If I can't help, I'll say so.

← All definitions