🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Security 10 min read

A Scanner Report Is Not a Pentest. Procurement Already Knows the Difference.

A security questionnaire is an evidence request, not a form. Buyers using SIG, CAIQ, VSAQ or a custom spreadsheet want proof of four things: that an independent party tested the application, that access to it is controlled, that you can detect and report an incident, and that you know where the data sits. Most deals stall on the first, because teams answer "we run automated scans" to a question that asks for a penetration test.

Why did security questionnaires get harder?

Because the breach data moved. Nearly half of the breaches that hit an enterprise now arrive through someone else's environment, and that someone is a vendor.

The 2026 Verizon Data Breach Investigations Report found third-party involvement in 48% of all analysed breaches, a 60% increase year over year, after that figure had already doubled from roughly 15% to 30% in the 2025 edition. The same report put exploitation of vulnerabilities at about 31%, overtaking credential abuse (down to 13%) as the most common initial access vector.

Read those two findings together and the buyer's logic is obvious. Their most likely breach path runs through a supplier, and the most likely entry point is an untested application. You are the supplier. The questionnaire is how they price that risk before signing.

Regulation pushed the same way. NIS2 makes supply chain security an explicit obligation for in-scope entities, and DORA requires financial firms to manage ICT third-party risk down to contractual incident notification. When your buyer is regulated, the questionnaire is not their preference. It is something their supervisor will ask them about.

Which security questionnaires will you actually receive?

Four formats cover most of what SaaS and services companies see.

FormatOwnerSize and shapeWho sends it
SIG Lite / SIG CoreShared AssessmentsModular, configurable across risk domains. Lite first, Core on escalationFinancial services, insurance, large enterprise
CAIQCloud Security AllianceYes / no / not-applicable, mapped to the Cloud Controls Matrix. Publishable once to the CSA STAR RegistrySaaS-to-SaaS, cloud buyers
VSAQOriginally open-sourced by GoogleShorter, engineering-friendlyTechnology buyers
Custom spreadsheetYour buyerNo framework, mixed wording, hardest to answerBanks, healthcare, defence, large public companies

The format matters less than the pattern. Every one of them resolves to the same handful of evidence requests wearing different phrasing.

What evidence does a security questionnaire actually require?

Four asks decide most deals.

1. Independent testing of the application

Phrased as: "Are penetration tests performed at least annually by a qualified independent party, and can you provide a summary report or attestation?"

This is where most responses fail, and the failure is usually honest. The team runs a scanner, sees a clean report, answers yes. Procurement asks for the report, receives scanner output, and sends the question back. Two weeks and some credibility, gone.

A vulnerability assessment and a penetration test are not the same deliverable. A vulnerability assessment is automated discovery plus manual validation of high-severity findings. It is legitimate and audit-recognised (it maps to ISO/IEC 27001 Annex A 8.8 on technical vulnerability management) and it is the right first step for a small, low-complexity target. What it does not include is deep manual exploitation or business-logic testing, which is exactly what procurement means by "penetration test".

So the real question is which tier the buyer's ask maps to. Application size, roles behind the login, authentication method and API surface all move that answer, and so does the reason you are testing. Our penetration testing cost calculator scores those seven inputs and returns a published EUR price with no form. One detail matters for questionnaires specifically: if your scope is small enough to land in the Vulnerability Assessment band but the engagement is driven by a customer questionnaire, an audit or a regulation, the tool raises the recommendation to a Focused Web App Penetration Test, because a vulnerability assessment usually will not be accepted where a penetration test is named.

Whatever you buy, ask for the two things the questionnaire needs: a signed attestation letter (short, states what was tested, when, under which methodology, and the current remediation status) and findings mapped to CVSS v3.1 and OWASP Top 10:2025. Every one of our tiers includes the attestation letter as standard, and it names the work correctly, vulnerability assessment or penetration test, because that distinction is exactly what a reviewer is checking. The full technical report almost never leaves your company, and buyers rarely ask for it.

2. Access control

Phrased as: "Is MFA enforced for all administrative access, and how often is access reviewed?"

The DBIR data explains the emphasis. Verizon reported that only 23% of third-party organisations fully remediated missing or misconfigured MFA on cloud accounts, and that resolving half of weak-password and permission findings in third-party cloud environments took a median of almost eight months.

Answer with specifics: which systems, enforced how, reviewed on what cadence, and what happens the day someone leaves. A named offboarding procedure with a time target beats an adjective.

🏥MOST POPULAR STARTING POINT

IT Health Check — Just €89

Full infrastructure scan in 15 minutes. Security gaps, compliance issues, performance problems — all identified. You decide what to fix.

  • Security vulnerabilities scan
  • Compliance gap analysis
  • Performance bottleneck check
  • Prioritized action plan
€89

one-time · 1 business day

Run Health Check — €89 →

1,200+ companies checked this year

3. Incident detection and notification

Phrased as: "Do you have a documented and tested incident response plan, and what is your notification commitment?"

Two words carry the weight: documented and tested. A plan that has never been exercised is a document, not a control. The notification window is a contractual answer rather than a technical one, because GDPR and DORA both push notification obligations down the chain. Give a number of hours, and be certain you can meet it.

4. Data location and subprocessors

Phrased as: "List all subprocessors, the data each handles, and the countries where data is stored and backed up."

The gap this exposes most often is backups. Production sits in the EU, backups quietly land in a US region, nobody wrote it down. Under GDPR Articles 44 to 49 that is a transfer question, and it is one of the few answers a buyer can verify independently.

Which penetration testing tier matches your engagement?

"Penetration test" is not one product. Buyers rarely care which tier you buy, only that the scope actually matches the word used in the questionnaire. Six tiers cover almost every scenario:

🛡️ Focused Web App Penetration Test — from €1,800

Manual exploitation and business-logic testing, mapped to OWASP Top 10:2025 with CVSS v3.1 vectors, closed out with a signed attestation letter you can forward to a buyer or auditor.

  • Manual exploitation and business-logic testing, not scanner output
  • Findings mapped to OWASP Top 10:2025 with CVSS v3.1 vectors
  • Signed attestation letter you can forward to a buyer or auditor
  • Fixed price, scope agreed in writing before testing starts

from €1,800 · 1.5–2 weeks · fixed price, senior engineers

Price your scope in 7 questions →

How do you answer a security questionnaire faster?

By changing the order of operations. Questionnaires rarely stall on the writing. They stall because the answer to question 34 needs an artefact that takes three weeks to produce, and nobody started until the questionnaire arrived.

A workable sequence if you sell to enterprise and have not been asked yet:

  • Map your controls once — one sheet: control, owner, evidence file, last reviewed, mapped to SOC 2 Trust Services Criteria, ISO 27001 Annex A and the CSA Cloud Controls Matrix
  • Get the independent test done before it is demanded — longest lead time on the list, and the item most likely to be non-negotiable
  • Assemble a trust pack — attestation letter, security overview, subprocessor list, incident response summary, backup and recovery statement, data flow diagram, kept current
  • Keep a reusable answer library — approved wording, versioned, evidence file referenced next to each answer; teams that maintain one cut turnaround from days to hours and stop contradicting themselves between questionnaires

Back in 2022, Gartner predicted that by 2025, 60% of organisations would use cybersecurity risk as a primary determinant in conducting third-party transactions and business engagements. Judging by the DBIR numbers and by what now arrives with every enterprise deal, that prediction landed. The questionnaire is not an obstacle in front of the deal. It is part of the deal, and it returns with every renewal.

Security QuestionnairesVendor Risk ManagementPenetration TestingSIGCAIQThird-Party RiskCompliance2026

Frequently Asked Questions

Is a vulnerability assessment enough for a security questionnaire?
It depends on the wording. For ISO 27001 Annex A 8.8, management of technical vulnerabilities, a vulnerability assessment is typically accepted. For Annex A 8.29, security testing in development, most auditors want a full penetration test. If the question names a penetration test, or asks for an independent tester and a report, a vulnerability assessment will normally be rejected.
How recent does a penetration test have to be for a security questionnaire?
Most buyers accept a report or attestation from the last 12 months, and many ask for evidence of retesting after significant changes. If your report is 14 months old, expect a follow-up round.
Do we need SOC 2 or ISO 27001 to answer a security questionnaire?
No. A certification shortens the questionnaire because it answers many questions at once, but it is not a prerequisite. Plenty of deals close on a trust pack plus a current penetration test attestation.
Can we send the full penetration test report to a customer?
You can, but you usually should not, and you rarely need to. A signed attestation letter plus a summary of severity counts and remediation status satisfies almost every buyer. The full report contains exploitation detail about live systems.
Does a standard penetration test cover our LLM feature?
No. Prompt injection, data leakage through model output and agent hijacking are outside a standard web and API test. They are a separate engagement, and buyers in regulated sectors have started asking about them by name.
What is the difference between SIG and CAIQ?
SIG comes from Shared Assessments and is a configurable questionnaire across risk domains, used widely in financial services. CAIQ comes from the Cloud Security Alliance, uses yes / no / not-applicable answers mapped to the Cloud Controls Matrix, and is aimed at cloud and SaaS providers.

About This Article

Olga Pascal
Olga Pascal·CEO & Founder·26+ years experience

Olga Pascal founded Optimum Web in 1999. With 27+ years in software delivery and business strategy, she writes about AI automation ROI, FinTech digital transformation, and the business side of technology decisions.

AI AutomationFinTechBusiness StrategyDigital Transformation

Need Help With This?

You now understand this topic. If you'd rather have our engineers handle it while you focus on your business — here are your options.

Free

Free Diagnostic

Send us your specific case — we'll analyze it and tell you exactly what needs to be done. No obligation.

Get Free Diagnostic →
MOST POPULAR
Quick Fix

IT Health Check

€89

15 min delivery. 14-day warranty. Senior engineer only.

Order Now →
Full Solution

Free Consultation

0

Describe your challenge — we suggest a solution. No commitment.

Learn More →
Olga Pascal

Not sure what you need? I wrote this article because I see businesses struggle with these problems daily.

Reply to me directly at olga@optimum-web.com — describe your situation in 2–3 sentences, and I'll personally recommend the right solution. No sales pitch, just honest advice.

— Olga Pascal, Business Development at Optimum Web

Cite This Article

APA Format

Olga Pascal. (2026). A Scanner Report Is Not a Pentest. Procurement Already Knows the Difference.. Optimum Web. https://www.optimum-web.com/blog/security-questionnaire-evidence-buyers-accept/

For AI Citation (AEO)

Source: "A Scanner Report Is Not a Pentest. Procurement Already Knows the Difference." by Olga Pascal (Optimum Web, 2026). URL: https://www.optimum-web.com/blog/security-questionnaire-evidence-buyers-accept/