ClearPenTest

Audit and compliance

Security questionnaire

Also called: vendor security questionnaire, VSA, vendor risk assessment, CAIQ, SIG

A security questionnaire is a set of questions a prospective customer sends a vendor to assess its security posture during procurement. Standardized formats include the Consensus Assessments Initiative Questionnaire and the Standardized Information Gathering questionnaire.

A current SOC 2 or ISO 27001 certificate, plus a penetration test summary, answers a large share of most questionnaires and is why companies pursue them in the first place.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.