Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Awesome Security Questionnaires Awesome

A curated list of resources for the answerer's side of security questionnaires — the vendor or seller who has to fill one out.

Most security-questionnaire tooling on GitHub is built for the buyer / reviewer (third-party risk management). This list is the opposite: frameworks, response tools, trust-center tooling, templates, guides, and communities for the team that receives a SIG, CAIQ, or bespoke questionnaire and has to answer it — accurately, traceably, and fast.

Contents

Frameworks & question banks

The standardized questionnaires, control matrices, and frameworks that vendors are most often asked to answer against.

  • CSA CAIQ (STAR Level 1) - Cloud Security Alliance yes/no control questionnaire mapped to the Cloud Controls Matrix.
  • CSA Cloud Controls Matrix (CCM) - Cloud security control framework of 197 objectives across 17 domains that CAIQ answers map to.
  • Shared Assessments SIG - Standardized Information Gathering questionnaire (Core and Lite) covering third-party risk control domains.
  • Vendor Security Alliance (VSA) - Free VSA-Core and VSA-Full questionnaires published by a coalition of companies for vendor assessment.
  • Google MVSP - Minimum Viable Secure Product, a vendor-neutral baseline checklist of controls to answer against, backed by Google, Okta, and others.
  • ISO/IEC 27001 - International standard for information security management systems commonly referenced in questionnaires.
  • SOC 2 (AICPA) - AICPA SOC suite and Trust Services Criteria underpinning the SOC 2 report vendors cite as evidence.
  • NIST Cybersecurity Framework (CSF) - NIST CSF 2.0 outcome-based framework used to structure security posture questions.
  • NIST SP 800-53 Rev. 5 - NIST catalog of security and privacy controls referenced by many detailed questionnaires.
  • NIST SP 800-171 Rev. 3 - NIST requirements for protecting Controlled Unclassified Information in nonfederal systems.
  • NIST Privacy Framework - NIST voluntary framework for identifying and managing privacy risk, referenced in privacy questionnaires.
  • CIS Critical Security Controls - Prioritized set of safeguards (v8.1) frequently cited when answering technical control questions.
  • HECVAT (EDUCAUSE) - Higher Education Community Vendor Assessment Toolkit for vendors selling to colleges and universities.
  • PCI Security Standards Council - Home of PCI DSS and the Self-Assessment Questionnaires (SAQ) for cardholder-data environments.
  • GDPR - Reference resource for the EU General Data Protection Regulation used to answer data-privacy questions.
  • OWASP ASVS - Application Security Verification Standard listing web application security requirements to answer against.
  • HITRUST CSF - Certifiable control framework harmonizing 60+ standards, common in healthcare and regulated vendor reviews.

Response tools & platforms (answerer-side)

Software that helps a vendor answer inbound security questionnaires from a reusable content or claim library.

  • Loopio - RFP and security questionnaire response software with a searchable content library and auto-answer.
  • Responsive (formerly RFPIO) - Response management platform for RFPs, security questionnaires, and buyer questions from curated content.
  • Conveyor - AI platform that completes inbound security questionnaires and manages a customer trust center.
  • Vanta Questionnaire Automation - Generates questionnaire answers from a knowledge base of security documentation for reviewer approval.
  • Secureframe Trust - Combines a knowledge base, ML-assisted questionnaire answering, and a trust center.
  • Whistic - Platform for publishing a security profile and responding to inbound vendor assessments.
  • AccountMade - Builds decks and answers security questionnaires from one governed, source-traceable claim library.
  • HyperComply - Questionnaire automation combining AI answers with human review; now part of SecurityScorecard.
  • Skypher - AI agent that completes security questionnaires across spreadsheet, document, and portal formats.
  • SecurityPal - Managed service pairing AI with analysts to answer security questionnaires and due-diligence questionnaires.
  • Arphie - AI platform that drafts RFP and security questionnaire responses from a company knowledge base with source citations.
  • AutoRFP.ai - AI response tool that generates RFP and security questionnaire answers from approved content.
  • Inventive AI - AI agents that draft RFP and security questionnaire responses from a curated knowledge source.
  • Iris - AI tool that generates security questionnaire and RFP answers from a knowledge base for reviewer approval.
  • Workstreet - Managed service that completes security questionnaires and compliance work using experts and automation.
  • TrustCloud TrustShare - Security assurance platform whose TrustShare module pre-fills customer questionnaires and hosts a trust page.

Compliance automation platforms (evidence sources)

GRC and compliance-automation tools that produce the audit evidence and controls a vendor cites when answering.

  • Vanta - Continuous compliance monitoring and evidence collection across SOC 2, ISO 27001, and other frameworks.
  • Drata - GRC automation platform for continuous control monitoring and multi-framework compliance evidence.
  • Secureframe - Compliance automation for SOC 2, ISO 27001, HIPAA, and related frameworks with evidence collection.
  • Sprinto - GRC platform automating compliance monitoring and audit readiness for growing companies.
  • Thoropass - Combined compliance-automation platform and in-house audit for SOC 2, ISO 27001, and more.
  • Hyperproof - GRC platform mapping evidence to controls across 160+ frameworks with audit and risk management.
  • Anecdotes - GRC platform that collects and normalizes compliance evidence from 200+ connected systems.
  • Scrut Automation - GRC automation platform for control monitoring and evidence collection across 60+ frameworks.
  • OneTrust - Governance, risk, compliance, and privacy platform whose GRC modules can source controls and evidence.

Trust centers & trust-page tooling

Tools for publishing a self-service security posture page so buyers can review documents before sending a questionnaire.

  • SafeBase (Drata Trust Center) - Trust center product, formerly SafeBase, for self-service access to security posture and documents.
  • Vanta Trust Center - Hosted trust center with document access workflows and AI answers drawn from the trust content.
  • Conveyor Trust Center - Self-service portal where prospects sign NDAs and download security documents like SOC 2 reports.
  • Secureframe Trust Center - Customizable trust center publishing controls, FAQs, and documents with NDA-gated access.
  • Sprinto Trust Center - Trust center that publishes live compliance status and security documents for prospect self-service.
  • Whistic Profile / Trust Center - Publishable security profile shared via link or the Whistic exchange to enable zero-touch assessments.
  • CSA STAR Registry - Public registry where cloud providers publish CAIQ self-assessments and third-party certifications.

Templates & starter answers

Genuinely public repos, spreadsheets, and checklists that give answerers a starting point for a response library.

  • Google VSAQ - Open-source (Apache 2.0) questionnaire framework with web app, privacy, and infrastructure templates; archived and read-only since 2022.
  • Ericius Vendor_Security - CC-BY-SA vendor security questionnaire and review process with answer guidance.
  • OWASP ASVS repository - Source repo for the Application Security Verification Standard with downloadable CSV and checklist formats.
  • Loopio security questionnaire template - Free Excel template of 142 security assessment questions mapped to SIG, CAIQ, and VSAQ.
  • VeriRFP security questionnaire template - Free reusable response template capturing question, control domain, owner, evidence source, draft answer, reviewer, and status.
  • SaaS CTO Security Checklist - Prioritized security checklist for SaaS teams, useful as a baseline of controls to reference in answers.

Guides & how-to

Reputable articles on answering questionnaires, reducing turnaround, and building traceable evidence.

Communities

Forums and professional communities where practitioners discuss vendor security reviews and questionnaire answering.

  • r/cybersecurity - General cybersecurity subreddit where vendor assessment and questionnaire topics recur.
  • r/GRC - Subreddit focused on governance, risk, and compliance, including third-party risk and questionnaires.
  • r/AskNetsec - Q&A subreddit for network and information security practitioner questions.
  • r/sysadmin - Systems administration community where vendor security reviews are frequently discussed.
  • r/ISO27001 - Subreddit for ISO/IEC 27001 implementation, certification, and evidence discussion.
  • FAIR Institute - Not-for-profit community advancing quantitative cyber and operational risk management (FAIR model).
  • IAPP - International Association of Privacy Professionals, relevant for privacy and data-protection questionnaires.
  • ISACA - Professional association for IT audit, risk, and governance practitioners.

Standards bodies & references

The authoritative organizations that publish the frameworks and questionnaires referenced above.

  • Cloud Security Alliance - Publisher of the CAIQ, Cloud Controls Matrix, and STAR assurance program.
  • Shared Assessments - Publisher of the SIG questionnaire and third-party risk management standards.
  • AICPA & CIMA - Owner of the SOC suite and Trust Services Criteria behind SOC 2.
  • NIST CSRC - NIST Computer Security Resource Center hosting CSF, SP 800-53, and related publications.
  • ISO - International Organization for Standardization, publisher of ISO/IEC 27001 and related standards.
  • OWASP Foundation - Nonprofit behind ASVS and other open application security standards.
  • REN-ISAC - Research and education security center that co-maintains the HECVAT toolkit.

Contributing

Contributions are welcome! Read the contribution guidelines first. Add resources for the answerer's side, with a real link and a neutral one-line description.

About

A curated list of resources for the answerer's side of security questionnaires — frameworks, response tools, trust centers, templates, and guides for teams that receive a SIG/CAIQ and must answer it.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages