Skip to content

What is a questionnaire?

When you sell software or services to large businesses or to government, the buyer has to do due diligence on your security before they can proceed. A security questionnaire is how they do it: a set of questions about how you protect data, run your systems, and manage risk.

Most questionnaires arrive as a spreadsheet. Some are hosted in a customer’s own portal instead, to be filled in through a web form.

Several standard formats come up repeatedly:

  • SIG Lite — a shortened version of the Standardized Information Gathering questionnaire
  • CAIQ — the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire
  • HECVAT — the Higher Education Community Vendor Assessment Toolkit

Many companies also write their own, or take a standard format and adapt it. In practice you should expect variation rather than a fixed set of questions.

Questionnaires are tedious and time-consuming. A single one can run to hundreds of questions, and answering it properly usually means gathering information from across the business — security, engineering, legal, and operations all hold parts of the answer. Without tooling, that work lands on one person chasing colleagues for detail.

They also need to be right. A questionnaire response is a set of claims about how your organisation operates. If an answer is inaccurate and something later goes wrong with your service, that inaccuracy can become the basis of a claim against you. Speed matters, but not at the cost of accuracy — which is why every answer in ResponseHub is reviewed and approved by a person before it goes out.

ResponseHub reads the questionnaire, works out its structure, and drafts answers from your knowledge base and your sources — showing where each answer came from and how confident it is, so reviewing is quicker than writing.