🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Compliance Services

Vendor Security Questionnaire Response Service

Turn 40 Hours of Engineering Work Into a Fixed-Price Project

from€600
5–10 business days

Quick Answer

Optimum completes vendor security questionnaires on your behalf — including SIG Lite, CAIQ, custom enterprise procurement forms, and underwriter-style forms. 50–200 questions answered accurately with supporting evidence from your existing documentation. Gap identification before submission. Defence through 1–2 rounds of clarification questions from the prospect's security team. Delivered in 5–10 business days. Saves 20–40 hours of senior engineering time per application. From €600 per questionnaire.

Why You Need This

When an enterprise prospect sends a vendor security questionnaire, your senior engineers face 20–40 hours of work answering 50–200 detailed questions about information security policies, access controls, encryption, incident response, backup and recovery, vendor risk management, and personnel security.

Done internally:

  • 2–4 weeks of senior engineering time lost
  • Risk of over-stating controls (future claim risk)
  • Risk of under-stating controls (losing the deal)
  • Inconsistency with previous questionnaires
  • Inputs required from CTO, CISO, legal, and operations

Done with Optimum:

  • Fixed price, fixed timeline
  • Accurate answers backed by evidence
  • Consistent with previous questionnaires
  • Defended through clarification rounds
  • Engineering team stays focused on product

Who sends you these questionnaires: Enterprise customers during vendor onboarding · Financial services counterparties (TPRM) · Healthcare providers during BAA review · Public sector procurement · Insurance brokers and underwriters · Multinational corporations during vendor consolidation

The Four Formats You'll See

Almost every questionnaire you'll receive is one of these four variants. Knowing which one landed in your inbox tells you roughly how much work — and how many days — you're looking at.

FormatVolumeWho usually sends itTypical turnaround
SIG Lite~136 questionsFinancial services, insurance, regulated enterprise procurement5–7 business days
SIG Core627+ questions across 18 risk domainsLarge enterprise / strategic vendor onboarding2 weeks, delivered in sections
CAIQ v4261 questionsCloud-first enterprises and SaaS-focused procurement (Cloud Security Alliance)5–10 business days
Custom enterprise formVaries — often 50–200+, proprietary structureBanks, insurers, Fortune 500 procurement teams7–10 business days

The Questions You Cannot Answer With Paperwork

Most of a questionnaire is policies and process descriptions — we can draft those from your existing documentation. A handful of questions are different: they ask for an artefact, and no amount of careful wording produces one that doesn't exist.

Question as it appearsWhat it's really askingWhat closes it
"Do you perform annual penetration testing of your production environment?"Is there independent, scheduled testing of the live environmentA penetration test report or Attestation Letter dated within the last 12 months
"Can you share your latest pentest report or attestation letter?"Is there an artefact you can actually produce, not just a policy statementAn Attestation Letter — the shareable summary of a completed test
"Are findings tracked to remediation and retested?"Is there a process, not a one-off testA test report plus a documented retest of prior findings
"Is testing performed by an independent third party?"Confirming you aren't only testing yourselvesAn external vendor's report — not an internal audit

These question patterns derive from standard frameworks referenced by SIG Lite, CAIQ, and the controls buyers typically cite when justifying them — including SOC 2 (change management / monitoring criteria), ISO/IEC 27001:2022 Annex A (vulnerability management), and PCI DSS 4.0 (penetration testing requirements). Exact clause numbers vary by framework revision — always confirm against the current published standard before citing one in a formal response.

If your questionnaire has a pentest-related question and you don't have a recent report, that's the fastest gap to close.

What You Get

Questionnaire completion

  • Full completion of vendor questionnaire (50–200+ questions)
  • Compatible with SIG Lite / SIG Core (Shared Assessments)
  • Compatible with CAIQ (Cloud Security Alliance)
  • Compatible with VSAQ (Vendor Security Alignment Questionnaire)
  • Custom enterprise procurement forms
  • Underwriter-style forms (AIG, Hiscox, Beazley)
  • Each answer supported by evidence from your existing documentation
  • Identification of gaps requiring remediation BEFORE submission

Evidence assembly and defence

  • Compiles supporting documents from your existing collateral
  • Identifies missing documentation
  • Suggests minimum viable documentation if gaps exist
  • 1–2 rounds of clarification questions from the prospect's security team — included
  • Additional rounds available at +€200/round

Reusable assets (delivered)

  • Template package for future questionnaires
  • Standardised answer library you can maintain internally
  • Evidence index for quick retrieval
  • Optional: full internal answer library (+€500 add-on) reducing future costs by 50–70%

What Happens If You Don't

Deal lost in procurement — even after sales champion approval
Engineering team distracted for 2–4 weeks during critical product work
Inconsistent answers across questionnaires create future audit risk
Over-commitment to controls you can't actually deliver — future breach exposure
Slow response — enterprise prospect moves to competitor

Our Process

1
Initial review (Day 1)
You forward the questionnaire and your existing documentation. We confirm scope and pricing within 24 hours.
2
Mutual NDA signed (Day 1–2)
Standard mutual NDA, English law, available pre-signed for fast turnaround.
3
Gap analysis (Day 2–3)
We identify what evidence you have, what's missing, and what should be remediated vs disclosed.
4
Drafting (Day 4–7)
Each question answered with supporting evidence. Risk-flagged answers marked for your review.
5
Your review (Day 7–8)
You review and approve answers. We don't submit anything without your explicit sign-off.
6
Submission (Day 8–10)
Either we submit on your behalf, or you submit using our drafted answers — your choice.
7
Clarification rounds
Any follow-up questions from the prospect's security team are handled by us, with your approval on each response.

The Fastest Path to a Defensible Answer

Which service you need depends on what the questionnaire actually asks and how much runway you have. Three honest paths:

Sharp deadline, pentest question

Need a "yes" with an artefact, fast. A Vulnerability Assessment produces a dated Attestation Letter in 5 business days.

Vulnerability Assessment — €539
Enterprise buyer, deeper scope expected

The questionnaire is custom or the contract value justifies a fuller test — API coverage, authenticated testing, deeper reporting.

Focused Web App Pentest — from €1,800
You already have testing evidence

The testing questions are covered — you just need the rest of the questionnaire answered accurately and on time.

Questionnaire response — from €600

Pricing

Fixed price per questionnaire based on scope. No hourly billing, no surprises.
Bundle discount: +15% off when combined with Focused Pentest (€1,800+) or Standard Pentest (€4,500+). Recurring discount: 20% off for 3+ questionnaires per quarter.

€600

Small questionnaire (under 50 questions, no custom format), SaaS startup context.

€1,200

Standard questionnaire (50–100 questions, common formats like SIG Lite, CAIQ).

€1,800

Complex questionnaire (100–200 questions, custom enterprise format, multiple defence rounds expected).

€2,500

Strategic enterprise questionnaire (200+ questions, multi-stakeholder, multi-round defence).

Frequently Asked Questions

What is a vendor security questionnaire?

A structured set of questions — 50 to 600+ depending on format — that a prospective enterprise customer, insurer, or partner sends to assess your information security posture before signing a contract. Common formats: SIG Lite, SIG Core, CAIQ v4, or a custom procurement form. The deal typically doesn't move forward until it's answered.

Can I answer 'not applicable' to the penetration testing questions?

Only if testing genuinely doesn't apply to your architecture (rare for any product handling customer data). For almost every SaaS or web application vendor, 'not applicable' reads as a red flag to the reviewer, not a valid answer. If you don't have a recent test, the honest and more effective move is to get one — a €539 Vulnerability Assessment turns an 'N/A' into a dated, evidenced 'yes.'

Do I need a full pentest or is a vulnerability assessment enough?

For most questionnaire responses, a Vulnerability Assessment (€539) is enough to produce the Attestation Letter these questions are actually looking for. Move up to a Focused Web App Pentest (from €1,800) if the counterparty is an enterprise buyer with its own deeper security review, or if your contract value justifies the deeper scope.

How long does a SIG Lite questionnaire take?

SIG Lite (136 questions) typically takes 5–7 business days for initial completion, plus 1–2 rounds of clarification if the prospect's security team follows up. Our standard pricing at €1,200 covers SIG Lite including one clarification round. SIG Core (627+ questions) is priced at €1,800–2,500.

What's the difference between SIG Lite and CAIQ v4?

SIG Lite (Shared Assessments, 136 questions) is used by enterprise procurement teams primarily in financial services, insurance, and regulated industries. CAIQ v4 (Cloud Security Alliance, 261 questions) is used specifically for cloud service providers and SaaS vendors. We handle both. If your prospect is a bank or insurer, expect SIG Lite. If they're a cloud-first enterprise, expect CAIQ v4.

How much does vendor questionnaire response cost?

Small questionnaire (under 50 questions, no custom format): €600. Standard SIG Lite or CAIQ (50–100 questions): €1,200. Complex enterprise questionnaire (100–200 questions): €1,800. Strategic (200+ questions, multi-round defence): €2,500. Rush (+50% premium, same-day NDA).

Can you complete custom enterprise questionnaires?

Yes. Large enterprises (banks, insurers, Fortune 500 procurement) often send proprietary formats that are longer and more specific than SIG Lite. We handle these under our Complex (€1,800) and Strategic (€2,500) tiers. Send us the questionnaire first — we'll confirm fit and pricing within 24 hours.

What evidence do you need from us?

Minimum documentation: pen test report (if you have one), security policies (even basic ones), MFA configuration proof, backup process description, and incident response contact details. We work with what you have and flag gaps. If you're missing critical evidence (no pen test, no MFA), we can recommend remediation services to fill those gaps.

How many clarification rounds are included?

One round of clarification questions from the prospect's security team is included in all tiers. Additional rounds are available at €200 per round. Enterprise questionnaires (€1,800+) include two rounds as standard.

What if the buyer sends follow-up questions?

We handle follow-up questions on your behalf (with your approval on each response). One clarification round is included. Additional rounds are €200 each. Rush responses (same-day) available at +50% premium.

Do you handle SIG Core (627+ questions)?

Yes. SIG Core is our most complex tier at €2,500. It covers 18 risk domains across 627 questions. We batch the work over 2 weeks and deliver in sections for your ongoing review. Multi-stakeholder review process available.

How is this different from doing it internally?

Internal completion typically takes 40–80 hours of your Head of Security's time per questionnaire — at €100+/hr that's €4,000–8,000 in opportunity cost. We deliver in 5–10 days at €600–2,500. For companies handling more than 3 questionnaires per quarter, our Compliance-as-a-Service (€729/month) includes unlimited questionnaire responses.

How is this different from Compliance-as-a-Service (€729/month)?

Compliance-as-a-Service is a recurring monthly subscription that includes ongoing compliance work including questionnaire responses up to a monthly cap. The Vendor Security Questionnaire service is a one-off, pay-per-questionnaire model — better if you have occasional questionnaires. If you're handling more than 3 questionnaires per quarter, Compliance-as-a-Service is more cost-effective.

Our last pentest was two years old — is that acceptable?

Rarely. Most reviewers expect a test dated within the last 12 months; a two-year-old report usually gets flagged and sent back for an update. It's faster to commission a fresh Vulnerability Assessment (€539, 5-day delivery) than to argue the old report is still valid.

Can you respond to the questionnaire and do the testing?

Yes. It's a common combination: we run the Vulnerability Assessment (or a higher pentest tier) to produce the Attestation Letter, then use that same evidence as part of the questionnaire response. Send us the questionnaire and we'll flag exactly which questions the test evidence closes.