compli.ai
From the blog

Vendor Risk Assessment Questionnaire Template (+ How to Use It)

A vendor risk assessment questionnaire is how you find out whether the third parties handling your data and systems are as secure as you are — before an auditor asks you to prove you checked. This guide gives you the sections and sample questions to actually ask, shows how the questionnaire maps to SOC 2 CC9 vendor-management expectations and NIST 800-171 supply-chain reality, and explains how to right-size it by vendor criticality so a low-risk tool does not get the same 200-question treatment as the vendor holding your production data.

A vendor risk assessment questionnaire is a structured set of security and compliance questions you send to a third party before (and periodically after) you trust them with your data, systems, or customers. You use it to answer one question your auditor will eventually ask you: how do you know this vendor is safe to use? A good questionnaire covers governance, data protection, access control, infrastructure security, incident response, business continuity, and the vendor's own compliance attestations — and it is right-sized to the vendor's criticality, so the SaaS tool with read-only access to a calendar does not get the same treatment as the sub-processor holding your production database. Below is a reusable template you can adapt, sample questions for each section, and — the part most templates skip — how the questionnaire maps to SOC 2 CC9 vendor-management expectations and the supply-chain reality of NIST 800-171 for defense contractors.

Why you need one (and why auditors care)

You can outsource work, but you cannot outsource responsibility. When a vendor mishandles your customers' data, it is your breach in the eyes of your customers and regulators. The questionnaire is how you exercise — and document — due diligence before that risk lands.

Auditors care because the frameworks require it. Under SOC 2, vendor and third-party risk management is an explicit part of the Common Criteria (CC9, covering risk mitigation). Point-in-time, undocumented assessments do not satisfy that expectation; assessors look for a repeatable program with evidence. And if you are a defense contractor, DFARS 252.204-7012 requires you to flow its safeguarding requirements down to subcontractors that handle covered defense information, and your questionnaire is one of the mechanisms that makes that flow-down real and provable.

The template: sections and sample questions

A practical vendor risk questionnaire is organized into sections, each targeting a category of risk. Below are the core sections with representative sample questions. Use these as a starting point and tailor them to the vendor's role.

#SectionWhat it assessesSample questions
1Company & governanceWhether security is owned and managedWho owns your security program? Do you have documented information security policies, reviewed at least annually? Do you conduct security awareness training for staff?
2Compliance & attestationsIndependent proof of controlsDo you hold a current SOC 2 Type II report, ISO 27001:2022 certificate, or equivalent? Can you share it under NDA? What frameworks are you assessed against, and when was your last audit?
3Data protectionHow your data is handledWhat data of ours will you store, process, or transmit? Is data encrypted in transit and at rest? Do you use sub-processors, and where are they located? What are your data retention and deletion practices?
4Access controlWho can reach your dataIs access to our data restricted on a least-privilege basis? Do you enforce multi-factor authentication? How is access granted, reviewed, and revoked (especially at offboarding)?
5Infrastructure & application securityTechnical hardeningWhere is our data hosted (cloud provider, region)? Do you perform regular vulnerability scanning and penetration testing? How do you manage patching and secure development?
6Incident responseWhat happens when something goes wrongDo you have a documented incident response plan? What is your breach notification commitment and timeline to notify us? Have you had a security incident in the last 24 months?
7Business continuity & availabilityWhether they stay upDo you have documented business continuity and disaster recovery plans? What are your RTO/RPO targets? When were these last tested?
8Subcontractor / fourth-party riskRisk beyond your direct vendorDo you assess the security of your own vendors and sub-processors? Do you flow security requirements down to them?
9Federal / regulated data (if applicable)Handling of CUI or regulated dataWill any Controlled Unclassified Information (CUI) be involved? If a cloud service stores covered defense information, does it meet the FedRAMP Moderate baseline or its equivalent, as DFARS 252.204-7012 requires? Do you meet applicable NIST 800-171 requirements and flow them down?

Section 9 only applies if regulated or federal data is in play — a good example of right-sizing, covered next.

How it maps to SOC 2 (CC9 vendor management)

If you are pursuing or maintaining SOC 2, the vendor questionnaire is not optional busywork — it is how you produce evidence for the vendor-management expectations in the Common Criteria.

SOC 2's CC9 addresses risk mitigation, and its vendor-focused criterion (CC9.2) expects organizations to assess and manage the risks associated with vendors and business partners. In practice, assessors look for:

  • Requirements and scope for each vendor — what they are responsible for, what compliance they must meet, and the service levels expected.
  • Periodic risk assessment of vendors and business partners (and, where relevant, the parties they rely on).
  • Defined accountability for vendor risk mitigation inside your organization.
  • Ongoing monitoring of vendor compliance — not a one-and-done check at onboarding.

Your questionnaire, plus a documented process for classifying vendors, re-assessing them on a schedule, and tracking findings to closure, is exactly the evidence that satisfies these expectations. The key auditor insight: point-in-time assessments are not enough — CC9.2 expects continuous oversight with documented evidence, so build re-assessment cadence into the program, not just an onboarding form. For the wider control picture, see the SOC 2 compliance checklist.

How it maps to NIST 800-171 (supply-chain reality)

For defense contractors, vendor risk is not just good hygiene — it is a flow-down obligation. Under DFARS 252.204-7012, contractors must implement NIST SP 800-171 (the Department of War (DoW) assesses against Revision 2 under a class deviation) and flow the safeguarding and reporting requirements down to subcontractors that will handle covered defense information. NIST 800-171 Revision 3 (finalized May 2024 but not yet adopted by the Department for contracts) formalizes this further with a dedicated Supply Chain Risk Management (SR) family.

What that means for your questionnaire when you operate in the defense supply chain:

  • Identify whether CUI is involved. If a vendor will process, store, or transmit CUI on their systems, they inherit obligations — and you need to know it before you share anything.
  • Confirm their 800-171 posture and flow-down. Ask whether they meet the applicable 800-171 requirements and whether they, in turn, flow requirements down to their subcontractors.
  • Know where CUI lives. A vendor's SaaS tool is not an appropriate place to store CUI unless it meets the DFARS rule: any cloud service that stores covered defense information must meet the FedRAMP Moderate baseline or its equivalent.
  • Document the assessment as evidence. Just as with SOC 2, the assessment record is what proves to an assessor that your flow-down is real.

This is where a defense contractor's vendor program differs sharply from a purely commercial one: the questionnaire becomes part of your CMMC/800-171 evidence, not just a procurement formality. For the cost and timeline context of the broader federal program, see CMMC certification cost and timeline, and for a platform that tracks your subcontractors' SPRS scores and POA&M health alongside your own controls, our CMMC compliance software.

Right-sizing by vendor criticality

The single most common mistake is sending every vendor the same exhaustive questionnaire. That wastes your team's time, annoys low-risk vendors, and — worse — buries the vendors that actually matter under the same noise. Tier your vendors first, then match the depth of the assessment to the tier.

Vendor tierExamplesData / accessQuestionnaire depthCadence
CriticalSub-processors holding production or customer data; anyone touching CUISensitive/regulated data, deep accessFull questionnaire + review of their SOC 2/ISO report; evidence retainedAnnually (or on major change)
ModerateTools with limited access to internal or non-sensitive dataSome access, no regulated dataFocused subset (compliance attestation, data handling, access control)Every 1–2 years
LowUtility SaaS with no access to sensitive dataMinimal/no sensitive dataShort attestation check (do they hold SOC 2/ISO? any breaches?)At onboarding; light re-check

Right-sizing is not cutting corners — it is directing your finite review capacity to where the risk actually is. A critical sub-processor deserves a full assessment and a read of their SOC 2 report; a calendar plugin does not. Auditors respect a risk-based program far more than a uniform one, because a uniform program signals you have not actually thought about which vendors matter.

Putting it into practice

  1. Inventory your vendors and record what data and access each one has.
  2. Classify each vendor into a criticality tier (critical / moderate / low).
  3. Send the right-sized questionnaire for the tier; request the vendor's SOC 2 or ISO report for critical ones.
  4. Review, score, and track findings to closure — do not let a "we'll fix that" answer disappear.
  5. Re-assess on a cadence matched to the tier, and keep the records as evidence.
  6. Feed it into your GRC program so vendor risk is monitored alongside your own controls, not in a separate spreadsheet.

That last step is where a platform helps: managing vendor assessments, evidence, and re-assessment cadence inside the same system as the rest of your compliance program — and, for federal contractors, tying it to your 800-171 flow-down evidence — turns a periodic scramble into a maintained program. Start from the questionnaire template above, and see compliance automation vs consultants for how to combine tooling with expert judgment on the harder vendor calls.

FAQ

What is a vendor risk assessment questionnaire?

It is a structured set of security and compliance questions you send to third parties before and during your relationship with them, to evaluate whether they handle your data and systems securely. It typically covers governance, compliance attestations, data protection, access control, infrastructure security, incident response, and business continuity, and it produces the documented evidence auditors expect for vendor-management controls.

What questions should be on a vendor risk questionnaire?

Cover these areas: who owns the vendor's security program and whether policies exist; what independent attestations they hold (SOC 2, ISO 27001); how they encrypt, store, retain, and delete your data; how they control and review access (MFA, least privilege, offboarding); how their infrastructure is hardened and tested; their incident-response and breach-notification commitments; their business continuity/DR posture; and how they manage their own subcontractors. Add CUI/NIST 800-171 questions if federal data is involved. The sample questions above cover each area.

How does a vendor questionnaire relate to SOC 2?

SOC 2's Common Criteria (CC9, and specifically CC9.2 on risk mitigation) expect you to assess and manage vendor and business-partner risk with defined requirements, periodic assessment, clear accountability, and ongoing monitoring. The questionnaire plus a documented, repeatable process is the evidence that satisfies these criteria. Note that assessors expect continuous oversight, not a single onboarding check.

Do defense contractors need vendor risk questionnaires?

Yes. Under DFARS 252.204-7012, contractors must implement NIST 800-171 and flow safeguarding and reporting requirements down to subcontractors that handle covered defense information. The questionnaire is a mechanism for confirming a vendor's 800-171 posture, whether CUI is involved, where regulated data is stored, and whether they flow requirements down further — and the assessment record becomes part of your CMMC/800-171 evidence.

How often should I reassess vendors?

Match the cadence to the vendor's criticality. Reassess critical vendors (those holding sensitive/regulated data or with deep access) annually or on major change; moderate vendors every one to two years; and low-risk vendors with a light re-check periodically after onboarding. A risk-based cadence is stronger — and more defensible to an auditor — than assessing everyone on the same fixed schedule.

How is a vendor risk questionnaire different from a security questionnaire?

They overlap heavily; the terms are often used interchangeably. A "security questionnaire" usually emphasizes technical and information-security controls, while a "vendor risk" or "third-party risk" questionnaire frames those same questions within a broader risk-management and due-diligence process (including business continuity, financial/operational, and compliance-attestation elements). In practice, a good vendor risk questionnaire includes the security questionnaire as its core.

Managing CUI across a subcontractor chain? Compli.ai's Supply Chain module rolls up each subcontractor's SPRS score, implementation status, and POA&M health from summary packages they share with you, alongside your own NIST SP 800-171 controls and inside your own Microsoft 365 tenant. Book a demo to see the Supply Chain module.