A vendor risk assessment questionnaire is how you find out whether the third parties handling your data and systems are as secure as you are — before an auditor asks you to prove you checked. This guide gives you the sections and sample questions to actually ask, shows how the questionnaire maps to SOC 2 CC9 vendor-management expectations and NIST 800-171 supply-chain reality, and explains how to right-size it by vendor criticality so a low-risk tool does not get the same 200-question treatment as the vendor holding your production data.
A vendor risk assessment questionnaire is a structured set of security and compliance questions you send to a third party before (and periodically after) you trust them with your data, systems, or customers. You use it to answer one question your auditor will eventually ask you: how do you know this vendor is safe to use? A good questionnaire covers governance, data protection, access control, infrastructure security, incident response, business continuity, and the vendor's own compliance attestations — and it is right-sized to the vendor's criticality, so the SaaS tool with read-only access to a calendar does not get the same treatment as the sub-processor holding your production database. Below is a reusable template you can adapt, sample questions for each section, and — the part most templates skip — how the questionnaire maps to SOC 2 CC9 vendor-management expectations and the supply-chain reality of NIST 800-171 for defense contractors.
You can outsource work, but you cannot outsource responsibility. When a vendor mishandles your customers' data, it is your breach in the eyes of your customers and regulators. The questionnaire is how you exercise — and document — due diligence before that risk lands.
Auditors care because the frameworks require it. Under SOC 2, vendor and third-party risk management is an explicit part of the Common Criteria (CC9, covering risk mitigation). Point-in-time, undocumented assessments do not satisfy that expectation; assessors look for a repeatable program with evidence. And if you are a defense contractor, DFARS 252.204-7012 requires you to flow its safeguarding requirements down to subcontractors that handle covered defense information, and your questionnaire is one of the mechanisms that makes that flow-down real and provable.
A practical vendor risk questionnaire is organized into sections, each targeting a category of risk. Below are the core sections with representative sample questions. Use these as a starting point and tailor them to the vendor's role.
| # | Section | What it assesses | Sample questions |
|---|---|---|---|
| 1 | Company & governance | Whether security is owned and managed | Who owns your security program? Do you have documented information security policies, reviewed at least annually? Do you conduct security awareness training for staff? |
| 2 | Compliance & attestations | Independent proof of controls | Do you hold a current SOC 2 Type II report, ISO 27001:2022 certificate, or equivalent? Can you share it under NDA? What frameworks are you assessed against, and when was your last audit? |
| 3 | Data protection | How your data is handled | What data of ours will you store, process, or transmit? Is data encrypted in transit and at rest? Do you use sub-processors, and where are they located? What are your data retention and deletion practices? |
| 4 | Access control | Who can reach your data | Is access to our data restricted on a least-privilege basis? Do you enforce multi-factor authentication? How is access granted, reviewed, and revoked (especially at offboarding)? |
| 5 | Infrastructure & application security | Technical hardening | Where is our data hosted (cloud provider, region)? Do you perform regular vulnerability scanning and penetration testing? How do you manage patching and secure development? |
| 6 | Incident response | What happens when something goes wrong | Do you have a documented incident response plan? What is your breach notification commitment and timeline to notify us? Have you had a security incident in the last 24 months? |
| 7 | Business continuity & availability | Whether they stay up | Do you have documented business continuity and disaster recovery plans? What are your RTO/RPO targets? When were these last tested? |
| 8 | Subcontractor / fourth-party risk | Risk beyond your direct vendor | Do you assess the security of your own vendors and sub-processors? Do you flow security requirements down to them? |
| 9 | Federal / regulated data (if applicable) | Handling of CUI or regulated data | Will any Controlled Unclassified Information (CUI) be involved? If a cloud service stores covered defense information, does it meet the FedRAMP Moderate baseline or its equivalent, as DFARS 252.204-7012 requires? Do you meet applicable NIST 800-171 requirements and flow them down? |
Section 9 only applies if regulated or federal data is in play — a good example of right-sizing, covered next.
If you are pursuing or maintaining SOC 2, the vendor questionnaire is not optional busywork — it is how you produce evidence for the vendor-management expectations in the Common Criteria.
SOC 2's CC9 addresses risk mitigation, and its vendor-focused criterion (CC9.2) expects organizations to assess and manage the risks associated with vendors and business partners. In practice, assessors look for:
Your questionnaire, plus a documented process for classifying vendors, re-assessing them on a schedule, and tracking findings to closure, is exactly the evidence that satisfies these expectations. The key auditor insight: point-in-time assessments are not enough — CC9.2 expects continuous oversight with documented evidence, so build re-assessment cadence into the program, not just an onboarding form. For the wider control picture, see the SOC 2 compliance checklist.
For defense contractors, vendor risk is not just good hygiene — it is a flow-down obligation. Under DFARS 252.204-7012, contractors must implement NIST SP 800-171 (the Department of War (DoW) assesses against Revision 2 under a class deviation) and flow the safeguarding and reporting requirements down to subcontractors that will handle covered defense information. NIST 800-171 Revision 3 (finalized May 2024 but not yet adopted by the Department for contracts) formalizes this further with a dedicated Supply Chain Risk Management (SR) family.
What that means for your questionnaire when you operate in the defense supply chain:
This is where a defense contractor's vendor program differs sharply from a purely commercial one: the questionnaire becomes part of your CMMC/800-171 evidence, not just a procurement formality. For the cost and timeline context of the broader federal program, see CMMC certification cost and timeline, and for a platform that tracks your subcontractors' SPRS scores and POA&M health alongside your own controls, our CMMC compliance software.
The single most common mistake is sending every vendor the same exhaustive questionnaire. That wastes your team's time, annoys low-risk vendors, and — worse — buries the vendors that actually matter under the same noise. Tier your vendors first, then match the depth of the assessment to the tier.
| Vendor tier | Examples | Data / access | Questionnaire depth | Cadence |
|---|---|---|---|---|
| Critical | Sub-processors holding production or customer data; anyone touching CUI | Sensitive/regulated data, deep access | Full questionnaire + review of their SOC 2/ISO report; evidence retained | Annually (or on major change) |
| Moderate | Tools with limited access to internal or non-sensitive data | Some access, no regulated data | Focused subset (compliance attestation, data handling, access control) | Every 1–2 years |
| Low | Utility SaaS with no access to sensitive data | Minimal/no sensitive data | Short attestation check (do they hold SOC 2/ISO? any breaches?) | At onboarding; light re-check |
Right-sizing is not cutting corners — it is directing your finite review capacity to where the risk actually is. A critical sub-processor deserves a full assessment and a read of their SOC 2 report; a calendar plugin does not. Auditors respect a risk-based program far more than a uniform one, because a uniform program signals you have not actually thought about which vendors matter.
That last step is where a platform helps: managing vendor assessments, evidence, and re-assessment cadence inside the same system as the rest of your compliance program — and, for federal contractors, tying it to your 800-171 flow-down evidence — turns a periodic scramble into a maintained program. Start from the questionnaire template above, and see compliance automation vs consultants for how to combine tooling with expert judgment on the harder vendor calls.
It is a structured set of security and compliance questions you send to third parties before and during your relationship with them, to evaluate whether they handle your data and systems securely. It typically covers governance, compliance attestations, data protection, access control, infrastructure security, incident response, and business continuity, and it produces the documented evidence auditors expect for vendor-management controls.
Cover these areas: who owns the vendor's security program and whether policies exist; what independent attestations they hold (SOC 2, ISO 27001); how they encrypt, store, retain, and delete your data; how they control and review access (MFA, least privilege, offboarding); how their infrastructure is hardened and tested; their incident-response and breach-notification commitments; their business continuity/DR posture; and how they manage their own subcontractors. Add CUI/NIST 800-171 questions if federal data is involved. The sample questions above cover each area.
SOC 2's Common Criteria (CC9, and specifically CC9.2 on risk mitigation) expect you to assess and manage vendor and business-partner risk with defined requirements, periodic assessment, clear accountability, and ongoing monitoring. The questionnaire plus a documented, repeatable process is the evidence that satisfies these criteria. Note that assessors expect continuous oversight, not a single onboarding check.
Yes. Under DFARS 252.204-7012, contractors must implement NIST 800-171 and flow safeguarding and reporting requirements down to subcontractors that handle covered defense information. The questionnaire is a mechanism for confirming a vendor's 800-171 posture, whether CUI is involved, where regulated data is stored, and whether they flow requirements down further — and the assessment record becomes part of your CMMC/800-171 evidence.
Match the cadence to the vendor's criticality. Reassess critical vendors (those holding sensitive/regulated data or with deep access) annually or on major change; moderate vendors every one to two years; and low-risk vendors with a light re-check periodically after onboarding. A risk-based cadence is stronger — and more defensible to an auditor — than assessing everyone on the same fixed schedule.
They overlap heavily; the terms are often used interchangeably. A "security questionnaire" usually emphasizes technical and information-security controls, while a "vendor risk" or "third-party risk" questionnaire frames those same questions within a broader risk-management and due-diligence process (including business continuity, financial/operational, and compliance-attestation elements). In practice, a good vendor risk questionnaire includes the security questionnaire as its core.
Managing CUI across a subcontractor chain? Compli.ai's Supply Chain module rolls up each subcontractor's SPRS score, implementation status, and POA&M health from summary packages they share with you, alongside your own NIST SP 800-171 controls and inside your own Microsoft 365 tenant. Book a demo to see the Supply Chain module.