# What is a questionnaire?

When you sell software or services to large businesses or to government, the
buyer has to do due diligence on your security before they can proceed. A
security questionnaire is how they do it: a set of questions about how you
protect data, run your systems, and manage risk.

## What they look like

Most questionnaires arrive as a spreadsheet. Some are hosted in a customer's own
portal instead, to be filled in through a web form.

**Questionnaires in a portal:** If a questionnaire is in a portal rather than a file, you can answer it in place
with the [ResponseHub Chrome extension](/chrome-extension/getting-started/) instead
of copying answers across by hand.

Several standard formats come up repeatedly:

- **SIG Lite** — a shortened version of the Standardized Information Gathering questionnaire
- **CAIQ** — the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire
- **HECVAT** — the Higher Education Community Vendor Assessment Toolkit

Many companies also write their own, or take a standard format and adapt it. In
practice you should expect variation rather than a fixed set of questions.

## Why they are hard

Questionnaires are tedious and time-consuming. A single one can run to hundreds
of questions, and answering it properly usually means gathering information from
across the business — security, engineering, legal, and operations all hold parts
of the answer. Without tooling, that work lands on one person chasing colleagues
for detail.

They also need to be right. A questionnaire response is a set of claims about how
your organisation operates. If an answer is inaccurate and something later goes
wrong with your service, that inaccuracy can become the basis of a claim against
you. Speed matters, but not at the cost of accuracy — which is why every answer
in ResponseHub is reviewed and approved by a person before it goes out.

## How ResponseHub helps

ResponseHub reads the questionnaire, works out its structure, and drafts answers
from your [knowledge base](/knowledge-base/what-is-the-knowledge-base/) and your
[sources](/sources/what-are-sources/) — showing where each answer came from and
how confident it is, so reviewing is quicker than writing.

## Next steps

- [Start a new questionnaire](/questionnaires/start-a-new-questionnaire/)
- [Questionnaire items](/questionnaires/questionnaire-items/) — working through the questions
- [What are RFPs?](/rfps/what-are-rfps/) — how RFPs differ