All resources
// Resources

Third-Party Cybersecurity Questionnaire: Evidence, Scores, Owners

Published August 12, 2026

Questionnaire is evidence intake, not assurance

NIST SP 800-161 Rev. 1, updated November 2024, provides supply-chain cybersecurity risk-management guidance. It frames supplier risk as visibility, assessment, and mitigation work. CISA describes information sharing as part of cyber incident coordination. Neither source turns a supplier questionnaire into proof that a supplier is secure, compliant, certified, or acceptable for every service.

Start with service context: data types, hosting regions, integrations, privileged access, subcontractors, business criticality, and exit dependency. Buyer procurement owns commercial decisions; security owns technical review; privacy/legal review contractual and data obligations; service owner accepts operational fit. No single responder should score their own exception.

Questions, evidence, and scoring

Score each answer after reviewing named evidence: 2 = supported and current, 1 = partly supported or expiring, 0 = absent, contradicted, or out of scope. Evidence older than twelve months, without a named owner or service boundary, scores at most 1 until refreshed. Weight items by the buyer’s risk model; scores help triage, not replace approval.

Domain and questionEvidence requestReview ownerPass/fail rule
Service inventory: What service and data are in scope?architecture/data-flow diagram, current subprocessor listservice ownerpass when boundary and data classes match procurement record
Access: How is privileged access approved and removed?access-review sample, MFA configuration, termination recordIAM ownerfail when privileged population or removal proof is missing
Vulnerability handling: How are material findings tracked?current policy, sanitized ticket sample, retest recordsecurity ownerfail when no owner, due date, or validation exists
Incident coordination: How will parties exchange facts?contact matrix, playbook extract, latest exercise lessonsincident ownerfail when contact or escalation path is unowned
Resilience and exit: How are data and access returned or removed?exit runbook, deletion/disablement evidencevendor managerfail when exit cannot be tested or assigned

Completed example: supplier hosts a low-risk scheduling API and has no production privileged access. Data-flow diagram matches contract; the last access review is six months old and includes removal evidence; one vulnerability ticket has retest proof; incident contact matrix names 24-hour operational contacts but contract owner must validate notifications. Scores are 2, 2, 2, 1, 1. Result: conditional approval, with vendor manager due dates for tested exit evidence and legal confirmation. It is not “supplier approved forever.”

Exceptions and remediation

An exception needs control gap, service impact, risk rating, compensating control, approving authority, start date, expiry, and reassessment trigger. Missing expiry is a failed exception. Remediation needs accountable supplier owner, buyer owner, action, proof expected, target date, and verification method. A spreadsheet answer claiming “encrypted” without configuration, scope, or key-management evidence is unresolved, not a pass.

Protect submitted evidence. Request redacted reports and samples first; do not collect credentials, raw customer data, exploitable proof, or a full penetration-test report without defined need and custody controls. Record document version, received date, reviewer, and retention decision.

Decision packet

Before approval meeting, buyer owner assembles one packet: service description, completed questionnaire, evidence index, scorecard, unresolved answers, exceptions, remediation dates, and recommendation. Meeting record states decision, conditions, expiry, and accountable signatory. If service changes before onboarding, reopen relevant answers rather than carrying score forward unchanged.

Evidence challenge

Reviewer samples claims rather than accepting summary statements. For encryption, ask where it operates, which data and backups it covers, who administers keys, and date configuration was reviewed. For access, reconcile privileged-user population with review evidence. For incident readiness, call one supplied contact during agreed exercise. Failed challenge lowers score and creates remediation item.

Conditional-approval closure

For scheduling API, vendor manager records condition VND-22: exit runbook must show tenant-data deletion route, approver, target date, and validation method. At follow-up, supplier supplies redacted deletion evidence for a synthetic tenant; buyer verifies identifier, service boundary, date, and authorized sign-off. If only policy text arrives, score stays 1 and approval condition remains open. Expired condition triggers owner decision to extend with documented risk or pause onboarding; questionnaire responder cannot self-close it.

Review cadence

Refresh answers when service scope, data flow, hosting, privileged access, subprocessor, material incident, or contract term changes. At minimum, vendor manager records next review date, evidence age, and outstanding actions. A score without a date is not decision-ready.

Decision boundary

Legal, privacy, procurement, and service owners must review their own obligations before contracting. This questionnaire produces a traceable diligence record only. It makes no promise of regulatory compliance, security outcome, certification, service availability, or transfer of buyer risk.

Questionnaire closure records unanswered items, evidence age, provider owner, and buyer decision without treating absence as a failed control. Expected result: each material answer remains traceable to supplied evidence and stated service boundary. Edge case: provider changes a subcontractor after review; reopen affected answers. Close only when exceptions, follow-up date, and decision owner are explicit.

Sources

Worked closure check

For hosted identity-provider diligence, retain service boundary, supplier evidence version, response date, buyer reviewer, conditional-approval decision, and next review trigger. Questionnaire evidence supports a bounded procurement decision only; it does not guarantee supplier security, compliance, certification, availability, or legal adequacy. Reopen relevant answers after subprocessor, privileged-access, hosting, or contract changes. Independent buyer reviewer tests one material response against supplied artifact and service context, keeping stale evidence, conditions, and unverified assertions in remediation queue.

Have a system that needs testing?