When a customer sends a security questionnaire, it is often based on a standard template rather than written from scratch. Recognising the template helps, because they ask similar things in a familiar structure, and answers you write for one can be reused on another.
This guide explains the templates you are most likely to see and how to approach them.
Draft your answers free →Why templates exist
Standard questionnaire templates let big customers assess many suppliers consistently, and let suppliers reuse answers instead of reinventing them each time. The catch is that templates are often long and generic, so a small supplier can find whole sections that do not apply. That is normal, and "not applicable, because X" is a valid answer.
SIG (Standardized Information Gathering)
The SIG, maintained by Shared Assessments, is one of the most comprehensive templates. It comes in a shorter core version and a very long detailed version, organised into risk domains covering everything from access control to physical security. If you receive a full SIG, expect hundreds of questions, many of which will not apply to a small business. Focus on answering the applicable ones clearly and marking the rest not applicable with a brief reason.
CAIQ (Consensus Assessments Initiative Questionnaire)
The CAIQ, from the Cloud Security Alliance, is aimed at cloud and software providers. It maps to the Cloud Controls Matrix and is often a set of yes or no questions with room to explain. If you provide a SaaS product, this is a common one to receive. Answer yes or no honestly and use the explanation space to describe how, or why a control does not apply.
VSA, bespoke, and portal-based questionnaires
You will also meet the VSA (Vendor Security Alliance) questionnaire, plenty of bespoke customer spreadsheets, and questionnaires delivered through a third-party risk portal. Despite the different wrappers, they cover the same core themes as everything else: access, encryption, data protection, resilience, and governance.
The reuse advantage
Because the templates overlap so heavily, the smart approach is to answer well once and reuse. Keep your approved answers somewhere you can find them, so the next questionnaire is mostly editing rather than writing. This is the single biggest time saver once you have done one or two.
A faster way to handle any template
Tickbox reads whichever template or spreadsheet you upload, extracts the questions, and drafts an answer to each in your own words. Approved answers are saved to a library and reused to draft your next questionnaire, so each one is faster than the last. You review and send, and your first few answers are free.
Example answers
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
What does "not applicable" mean on a security questionnaire?
It means the question does not apply to your business, for example a question about card payments when you do not take them. Mark it not applicable and add a short reason, rather than leaving it blank.
Do I have to answer every question in a SIG?
You respond to every question, but many will be "not applicable" for a small business. A clear reason for each keeps the reviewer confident you did not just skip them.
Can I reuse answers between a SIG, CAIQ, and a bespoke questionnaire?
Yes. They cover overlapping themes, so a good answer adapts across templates. Saving and reusing your answers is the fastest way to handle repeat questionnaires, which is exactly what Tickbox automates.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free