Audit and compliance
Security questionnaire
Also called: vendor security questionnaire, VSA, vendor risk assessment, CAIQ, SIG
A security questionnaire is a set of questions a prospective customer sends a vendor to assess its security posture during procurement. Standardized formats include the Consensus Assessments Initiative Questionnaire and the Standardized Information Gathering questionnaire.
A current SOC 2 or ISO 27001 certificate, plus a penetration test summary, answers a large share of most questionnaires and is why companies pursue them in the first place.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.