Third-Party Cybersecurity Questionnaire: Evidence, Scores, Owners
Questionnaire is evidence intake, not assurance
NIST SP 800-161 Rev. 1, updated November 2024, provides supply-chain cybersecurity risk-management guidance. It frames supplier risk as visibility, assessment, and mitigation work. CISA describes information sharing as part of cyber incident coordination. Neither source turns a supplier questionnaire into proof that a supplier is secure, compliant, certified, or acceptable for every service.
Start with service context: data types, hosting regions, integrations, privileged access, subcontractors, business criticality, and exit dependency. Buyer procurement owns commercial decisions; security owns technical review; privacy/legal review contractual and data obligations; service owner accepts operational fit. No single responder should score their own exception.
Questions, evidence, and scoring
Score each answer after reviewing named evidence: 2 = supported and current, 1 = partly supported or expiring, 0 = absent, contradicted, or out of scope. Evidence older than twelve months, without a named owner or service boundary, scores at most 1 until refreshed. Weight items by the buyer’s risk model; scores help triage, not replace approval.
| Domain and question | Evidence request | Review owner | Pass/fail rule |
|---|---|---|---|
| Service inventory: What service and data are in scope? | architecture/data-flow diagram, current subprocessor list | service owner | pass when boundary and data classes match procurement record |
| Access: How is privileged access approved and removed? | access-review sample, MFA configuration, termination record | IAM owner | fail when privileged population or removal proof is missing |
| Vulnerability handling: How are material findings tracked? | current policy, sanitized ticket sample, retest record | security owner | fail when no owner, due date, or validation exists |
| Incident coordination: How will parties exchange facts? | contact matrix, playbook extract, latest exercise lessons | incident owner | fail when contact or escalation path is unowned |
| Resilience and exit: How are data and access returned or removed? | exit runbook, deletion/disablement evidence | vendor manager | fail when exit cannot be tested or assigned |
Completed example: supplier hosts a low-risk scheduling API and has no production privileged access. Data-flow diagram matches contract; the last access review is six months old and includes removal evidence; one vulnerability ticket has retest proof; incident contact matrix names 24-hour operational contacts but contract owner must validate notifications. Scores are 2, 2, 2, 1, 1. Result: conditional approval, with vendor manager due dates for tested exit evidence and legal confirmation. It is not “supplier approved forever.”
Exceptions and remediation
An exception needs control gap, service impact, risk rating, compensating control, approving authority, start date, expiry, and reassessment trigger. Missing expiry is a failed exception. Remediation needs accountable supplier owner, buyer owner, action, proof expected, target date, and verification method. A spreadsheet answer claiming “encrypted” without configuration, scope, or key-management evidence is unresolved, not a pass.
Protect submitted evidence. Request redacted reports and samples first; do not collect credentials, raw customer data, exploitable proof, or a full penetration-test report without defined need and custody controls. Record document version, received date, reviewer, and retention decision.
Decision packet
Before approval meeting, buyer owner assembles one packet: service description, completed questionnaire, evidence index, scorecard, unresolved answers, exceptions, remediation dates, and recommendation. Meeting record states decision, conditions, expiry, and accountable signatory. If service changes before onboarding, reopen relevant answers rather than carrying score forward unchanged.
Evidence challenge
Reviewer samples claims rather than accepting summary statements. For encryption, ask where it operates, which data and backups it covers, who administers keys, and date configuration was reviewed. For access, reconcile privileged-user population with review evidence. For incident readiness, call one supplied contact during agreed exercise. Failed challenge lowers score and creates remediation item.
Conditional-approval closure
For scheduling API, vendor manager records condition VND-22: exit runbook must show tenant-data deletion route, approver, target date, and validation method. At follow-up, supplier supplies redacted deletion evidence for a synthetic tenant; buyer verifies identifier, service boundary, date, and authorized sign-off. If only policy text arrives, score stays 1 and approval condition remains open. Expired condition triggers owner decision to extend with documented risk or pause onboarding; questionnaire responder cannot self-close it.
Review cadence
Refresh answers when service scope, data flow, hosting, privileged access, subprocessor, material incident, or contract term changes. At minimum, vendor manager records next review date, evidence age, and outstanding actions. A score without a date is not decision-ready.
Decision boundary
Legal, privacy, procurement, and service owners must review their own obligations before contracting. This questionnaire produces a traceable diligence record only. It makes no promise of regulatory compliance, security outcome, certification, service availability, or transfer of buyer risk.
Questionnaire closure records unanswered items, evidence age, provider owner, and buyer decision without treating absence as a failed control. Expected result: each material answer remains traceable to supplied evidence and stated service boundary. Edge case: provider changes a subcontractor after review; reopen affected answers. Close only when exceptions, follow-up date, and decision owner are explicit.
Sources
Worked closure check
For hosted identity-provider diligence, retain service boundary, supplier evidence version, response date, buyer reviewer, conditional-approval decision, and next review trigger. Questionnaire evidence supports a bounded procurement decision only; it does not guarantee supplier security, compliance, certification, availability, or legal adequacy. Reopen relevant answers after subprocessor, privileged-access, hosting, or contract changes. Independent buyer reviewer tests one material response against supplied artifact and service context, keeping stale evidence, conditions, and unverified assertions in remediation queue.