SIG stands for Standardized Information Gathering. It is a widely used template for assessing how a supplier manages security and privacy risk, maintained by an industry body called Shared Assessments and sent by many larger organisations to their vendors.
Because it is a standard template, a SIG can feel enormous and generic. This guide explains what it is, the difference between the longer and shorter versions, and how a small supplier can complete one honestly.
Draft your answers free →What SIG is, and who sends it
A SIG questionnaire is a ready-made spreadsheet of questions covering security, privacy, and resilience, grouped into risk areas. Large customers use it so they can assess every supplier against the same yardstick instead of writing a bespoke form each time.
If you have received one, a customer has chosen a standard template rather than their own. The upside is that once you have answered a SIG well, much of that work carries over to the next customer who uses one.
SIG Core vs SIG Lite
SIG comes in more than one size. SIG Core is the comprehensive version, running to hundreds of detailed questions for suppliers who handle sensitive data or sit deep in a customer’s operations. SIG Lite is a shorter, higher-level subset designed for a first-pass or lower-risk assessment.
As a small supplier you are most likely to receive SIG Lite, or a trimmed version of Core. Either way the approach is the same: answer the areas that apply to you, and mark the rest clearly.
The areas a SIG covers
A SIG spans the familiar risk domains, at varying depth depending on the version:
- Security policies, governance, and risk management.
- Access control, authentication, and privileged access.
- Asset and configuration management, and patching.
- Data protection, privacy, retention, and disposal.
- Encryption and key handling.
- Threat and vulnerability management.
- Incident response, business continuity, and disaster recovery.
- Physical and environmental security.
- Supplier and fourth-party management.
How to complete a SIG as a small supplier
The scale is the intimidating part, not the questions themselves, which probe the same fundamentals as any other security questionnaire. Work down the spreadsheet, answer what applies to you in plain language, and use "not applicable" with a short reason wherever a control assumes an enterprise you are not.
Keep your answers consistent from row to row. A long SIG makes it easy to describe the same practice, such as how you enforce MFA or approve access, three slightly different ways. Consistent answers read as more credible and are quicker to review.
Turning a huge spreadsheet into a review task
A SIG is usually an Excel file with hundreds of rows, which is exactly the kind of document that takes days by hand. Tickbox reads the spreadsheet, drafts a grounded answer for each question in your own words, and shows which policy or control it drew on. You review and edit rather than write from a blank cell, and your approved answers are reused on the next questionnaire. Your first few answers are free, so you can try it on the real file before paying.
Example answers to SIG-style questions
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
What is the difference between SIG Core and SIG Lite?
SIG Core is the full, detailed questionnaire with hundreds of questions, used for higher-risk suppliers. SIG Lite is a shorter, higher-level subset used for lower-risk or first-pass assessments. Small suppliers most often receive SIG Lite.
Do I have to answer every question in a SIG?
Answer every question that applies to you. Where a question assumes controls or infrastructure a small business does not have, mark it "not applicable" with a brief reason rather than leaving it blank or inventing a control.
What format does a SIG come in?
It is normally an Excel spreadsheet with questions grouped into tabs or sections by risk area, and a column for your response. Tools that read spreadsheets can extract the questions and draft answers directly from the file.
Is a SIG the same as CAIQ?
No, but they serve a similar purpose. CAIQ is a cloud-focused questionnaire from the Cloud Security Alliance, while SIG is a broader third-party risk template from Shared Assessments. A customer will usually send one or the other.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free