Tickbox Draft your answers free
Guide

The SIG questionnaire explained, and how to answer it

Been sent a "SIG" questionnaire? Here is what the Standardized Information Gathering questionnaire is, why it can run to hundreds of questions, and how to work through it without a security team.

Last updated: July 2026

SIG stands for Standardized Information Gathering. It is a widely used template for assessing how a supplier manages security and privacy risk, maintained by an industry body called Shared Assessments and sent by many larger organisations to their vendors.

Because it is a standard template, a SIG can feel enormous and generic. This guide explains what it is, the difference between the longer and shorter versions, and how a small supplier can complete one honestly.

Draft your answers free →

What SIG is, and who sends it

A SIG questionnaire is a ready-made spreadsheet of questions covering security, privacy, and resilience, grouped into risk areas. Large customers use it so they can assess every supplier against the same yardstick instead of writing a bespoke form each time.

If you have received one, a customer has chosen a standard template rather than their own. The upside is that once you have answered a SIG well, much of that work carries over to the next customer who uses one.

SIG Core vs SIG Lite

SIG comes in more than one size. SIG Core is the comprehensive version, running to hundreds of detailed questions for suppliers who handle sensitive data or sit deep in a customer’s operations. SIG Lite is a shorter, higher-level subset designed for a first-pass or lower-risk assessment.

As a small supplier you are most likely to receive SIG Lite, or a trimmed version of Core. Either way the approach is the same: answer the areas that apply to you, and mark the rest clearly.

The areas a SIG covers

A SIG spans the familiar risk domains, at varying depth depending on the version:

How to complete a SIG as a small supplier

The scale is the intimidating part, not the questions themselves, which probe the same fundamentals as any other security questionnaire. Work down the spreadsheet, answer what applies to you in plain language, and use "not applicable" with a short reason wherever a control assumes an enterprise you are not.

Keep your answers consistent from row to row. A long SIG makes it easy to describe the same practice, such as how you enforce MFA or approve access, three slightly different ways. Consistent answers read as more credible and are quicker to review.

Turning a huge spreadsheet into a review task

A SIG is usually an Excel file with hundreds of rows, which is exactly the kind of document that takes days by hand. Tickbox reads the spreadsheet, drafts a grounded answer for each question in your own words, and shows which policy or control it drew on. You review and edit rather than write from a blank cell, and your approved answers are reused on the next questionnaire. Your first few answers are free, so you can try it on the real file before paying.

Example answers to SIG-style questions

Is there an information security policy that has been approved by management?
Yes. We hold a written information security policy that is approved by our management and reviewed at least annually. It sets out our controls for access, data protection, and incident response.
Are user access rights reviewed on a periodic basis?
Yes. Access is granted on a least-privilege basis through named accounts, and we review who has access to systems holding customer data periodically, removing access promptly when someone changes role or leaves.
Is data encrypted both in transit and at rest?
Yes. Data is encrypted in transit using TLS, and data at rest is held on reputable cloud services that encrypt stored data by default. We do not hold customer data on unencrypted local devices.
Is there a documented incident response plan?
Yes. We have a documented process for identifying, containing, and investigating incidents, including assessing the impact on individuals and reporting a personal data breach to the ICO within 72 hours where required.

These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.

Frequently asked questions

What is the difference between SIG Core and SIG Lite?

SIG Core is the full, detailed questionnaire with hundreds of questions, used for higher-risk suppliers. SIG Lite is a shorter, higher-level subset used for lower-risk or first-pass assessments. Small suppliers most often receive SIG Lite.

Do I have to answer every question in a SIG?

Answer every question that applies to you. Where a question assumes controls or infrastructure a small business does not have, mark it "not applicable" with a brief reason rather than leaving it blank or inventing a control.

What format does a SIG come in?

It is normally an Excel spreadsheet with questions grouped into tabs or sections by risk area, and a column for your response. Tools that read spreadsheets can extract the questions and draft answers directly from the file.

Is a SIG the same as CAIQ?

No, but they serve a similar purpose. CAIQ is a cloud-focused questionnaire from the Cloud Security Alliance, while SIG is a broader third-party risk template from Shared Assessments. A customer will usually send one or the other.

More guides

Answer your questionnaire in minutes

Drop it in and Tickbox drafts every answer for you to review. Your first few are free.

Try it free