Vendor Security Questionnaire Response Service
Turn 40 Hours of Engineering Work Into a Fixed-Price Project
Quick Answer
Optimum completes vendor security questionnaires on your behalf — including SIG Lite, CAIQ, custom enterprise procurement forms, and underwriter-style forms. 50–200 questions answered accurately with supporting evidence from your existing documentation. Gap identification before submission. Defence through 1–2 rounds of clarification questions from the prospect's security team. Delivered in 5–10 business days. Saves 20–40 hours of senior engineering time per application. From €600 per questionnaire.
Why You Need This
When an enterprise prospect sends a vendor security questionnaire, your senior engineers face 20–40 hours of work answering 50–200 detailed questions about information security policies, access controls, encryption, incident response, backup and recovery, vendor risk management, and personnel security.
Done internally:
- 2–4 weeks of senior engineering time lost
- Risk of over-stating controls (future claim risk)
- Risk of under-stating controls (losing the deal)
- Inconsistency with previous questionnaires
- Inputs required from CTO, CISO, legal, and operations
Done with Optimum:
- Fixed price, fixed timeline
- Accurate answers backed by evidence
- Consistent with previous questionnaires
- Defended through clarification rounds
- Engineering team stays focused on product
Who sends you these questionnaires: Enterprise customers during vendor onboarding · Financial services counterparties (TPRM) · Healthcare providers during BAA review · Public sector procurement · Insurance brokers and underwriters · Multinational corporations during vendor consolidation
The Four Formats You'll See
Almost every questionnaire you'll receive is one of these four variants. Knowing which one landed in your inbox tells you roughly how much work — and how many days — you're looking at.
| Format | Volume | Who usually sends it | Typical turnaround |
|---|---|---|---|
| SIG Lite | ~136 questions | Financial services, insurance, regulated enterprise procurement | 5–7 business days |
| SIG Core | 627+ questions across 18 risk domains | Large enterprise / strategic vendor onboarding | 2 weeks, delivered in sections |
| CAIQ v4 | 261 questions | Cloud-first enterprises and SaaS-focused procurement (Cloud Security Alliance) | 5–10 business days |
| Custom enterprise form | Varies — often 50–200+, proprietary structure | Banks, insurers, Fortune 500 procurement teams | 7–10 business days |
The Questions You Cannot Answer With Paperwork
Most of a questionnaire is policies and process descriptions — we can draft those from your existing documentation. A handful of questions are different: they ask for an artefact, and no amount of careful wording produces one that doesn't exist.
| Question as it appears | What it's really asking | What closes it |
|---|---|---|
| "Do you perform annual penetration testing of your production environment?" | Is there independent, scheduled testing of the live environment | A penetration test report or Attestation Letter dated within the last 12 months |
| "Can you share your latest pentest report or attestation letter?" | Is there an artefact you can actually produce, not just a policy statement | An Attestation Letter — the shareable summary of a completed test |
| "Are findings tracked to remediation and retested?" | Is there a process, not a one-off test | A test report plus a documented retest of prior findings |
| "Is testing performed by an independent third party?" | Confirming you aren't only testing yourselves | An external vendor's report — not an internal audit |
These question patterns derive from standard frameworks referenced by SIG Lite, CAIQ, and the controls buyers typically cite when justifying them — including SOC 2 (change management / monitoring criteria), ISO/IEC 27001:2022 Annex A (vulnerability management), and PCI DSS 4.0 (penetration testing requirements). Exact clause numbers vary by framework revision — always confirm against the current published standard before citing one in a formal response.
If your questionnaire has a pentest-related question and you don't have a recent report, that's the fastest gap to close.
What You Get
Questionnaire completion
- Full completion of vendor questionnaire (50–200+ questions)
- Compatible with SIG Lite / SIG Core (Shared Assessments)
- Compatible with CAIQ (Cloud Security Alliance)
- Compatible with VSAQ (Vendor Security Alignment Questionnaire)
- Custom enterprise procurement forms
- Underwriter-style forms (AIG, Hiscox, Beazley)
- Each answer supported by evidence from your existing documentation
- Identification of gaps requiring remediation BEFORE submission
Evidence assembly and defence
- Compiles supporting documents from your existing collateral
- Identifies missing documentation
- Suggests minimum viable documentation if gaps exist
- 1–2 rounds of clarification questions from the prospect's security team — included
- Additional rounds available at +€200/round
Reusable assets (delivered)
- Template package for future questionnaires
- Standardised answer library you can maintain internally
- Evidence index for quick retrieval
- Optional: full internal answer library (+€500 add-on) reducing future costs by 50–70%
What Happens If You Don't
Our Process
The Fastest Path to a Defensible Answer
Which service you need depends on what the questionnaire actually asks and how much runway you have. Three honest paths:
Need a "yes" with an artefact, fast. A Vulnerability Assessment produces a dated Attestation Letter in 5 business days.
Vulnerability Assessment — €539The questionnaire is custom or the contract value justifies a fuller test — API coverage, authenticated testing, deeper reporting.
Focused Web App Pentest — from €1,800The testing questions are covered — you just need the rest of the questionnaire answered accurately and on time.
Questionnaire response — from €600Pricing
Fixed price per questionnaire based on scope. No hourly billing, no surprises.
Bundle discount: +15% off when combined with Focused Pentest (€1,800+) or Standard Pentest (€4,500+). Recurring discount: 20% off for 3+ questionnaires per quarter.
Small questionnaire (under 50 questions, no custom format), SaaS startup context.
Standard questionnaire (50–100 questions, common formats like SIG Lite, CAIQ).
Complex questionnaire (100–200 questions, custom enterprise format, multiple defence rounds expected).
Strategic enterprise questionnaire (200+ questions, multi-stakeholder, multi-round defence).
Frequently Asked Questions
What is a vendor security questionnaire?
A structured set of questions — 50 to 600+ depending on format — that a prospective enterprise customer, insurer, or partner sends to assess your information security posture before signing a contract. Common formats: SIG Lite, SIG Core, CAIQ v4, or a custom procurement form. The deal typically doesn't move forward until it's answered.
Can I answer 'not applicable' to the penetration testing questions?
Only if testing genuinely doesn't apply to your architecture (rare for any product handling customer data). For almost every SaaS or web application vendor, 'not applicable' reads as a red flag to the reviewer, not a valid answer. If you don't have a recent test, the honest and more effective move is to get one — a €539 Vulnerability Assessment turns an 'N/A' into a dated, evidenced 'yes.'
Do I need a full pentest or is a vulnerability assessment enough?
For most questionnaire responses, a Vulnerability Assessment (€539) is enough to produce the Attestation Letter these questions are actually looking for. Move up to a Focused Web App Pentest (from €1,800) if the counterparty is an enterprise buyer with its own deeper security review, or if your contract value justifies the deeper scope.
How long does a SIG Lite questionnaire take?
SIG Lite (136 questions) typically takes 5–7 business days for initial completion, plus 1–2 rounds of clarification if the prospect's security team follows up. Our standard pricing at €1,200 covers SIG Lite including one clarification round. SIG Core (627+ questions) is priced at €1,800–2,500.
What's the difference between SIG Lite and CAIQ v4?
SIG Lite (Shared Assessments, 136 questions) is used by enterprise procurement teams primarily in financial services, insurance, and regulated industries. CAIQ v4 (Cloud Security Alliance, 261 questions) is used specifically for cloud service providers and SaaS vendors. We handle both. If your prospect is a bank or insurer, expect SIG Lite. If they're a cloud-first enterprise, expect CAIQ v4.
How much does vendor questionnaire response cost?
Small questionnaire (under 50 questions, no custom format): €600. Standard SIG Lite or CAIQ (50–100 questions): €1,200. Complex enterprise questionnaire (100–200 questions): €1,800. Strategic (200+ questions, multi-round defence): €2,500. Rush (+50% premium, same-day NDA).
Can you complete custom enterprise questionnaires?
Yes. Large enterprises (banks, insurers, Fortune 500 procurement) often send proprietary formats that are longer and more specific than SIG Lite. We handle these under our Complex (€1,800) and Strategic (€2,500) tiers. Send us the questionnaire first — we'll confirm fit and pricing within 24 hours.
What evidence do you need from us?
Minimum documentation: pen test report (if you have one), security policies (even basic ones), MFA configuration proof, backup process description, and incident response contact details. We work with what you have and flag gaps. If you're missing critical evidence (no pen test, no MFA), we can recommend remediation services to fill those gaps.
How many clarification rounds are included?
One round of clarification questions from the prospect's security team is included in all tiers. Additional rounds are available at €200 per round. Enterprise questionnaires (€1,800+) include two rounds as standard.
What if the buyer sends follow-up questions?
We handle follow-up questions on your behalf (with your approval on each response). One clarification round is included. Additional rounds are €200 each. Rush responses (same-day) available at +50% premium.
Do you handle SIG Core (627+ questions)?
Yes. SIG Core is our most complex tier at €2,500. It covers 18 risk domains across 627 questions. We batch the work over 2 weeks and deliver in sections for your ongoing review. Multi-stakeholder review process available.
How is this different from doing it internally?
Internal completion typically takes 40–80 hours of your Head of Security's time per questionnaire — at €100+/hr that's €4,000–8,000 in opportunity cost. We deliver in 5–10 days at €600–2,500. For companies handling more than 3 questionnaires per quarter, our Compliance-as-a-Service (€729/month) includes unlimited questionnaire responses.
How is this different from Compliance-as-a-Service (€729/month)?
Compliance-as-a-Service is a recurring monthly subscription that includes ongoing compliance work including questionnaire responses up to a monthly cap. The Vendor Security Questionnaire service is a one-off, pay-per-questionnaire model — better if you have occasional questionnaires. If you're handling more than 3 questionnaires per quarter, Compliance-as-a-Service is more cost-effective.
Our last pentest was two years old — is that acceptable?
Rarely. Most reviewers expect a test dated within the last 12 months; a two-year-old report usually gets flagged and sent back for an update. It's faster to commission a fresh Vulnerability Assessment (€539, 5-day delivery) than to argue the old report is still valid.
Can you respond to the questionnaire and do the testing?
Yes. It's a common combination: we run the Vulnerability Assessment (or a higher pentest tier) to produce the Attestation Letter, then use that same evidence as part of the questionnaire response. Send us the questionnaire and we'll flag exactly which questions the test evidence closes.
Ready to Start?
Send us your questionnaire for a free scope review. We'll confirm fit and pricing within 24 hours.
