← All posts

SIG Lite vs SIG Core: Which One Did the Buyer Actually Send?

A buyer sends “the SIG questionnaire” and the spreadsheet drops into your inbox. Before you start answering, you need to know which one you have — because SIG Lite and SIG Core look similar, are written by the same organisation, and ask many of the same questions, but the time to answer them honestly is very different.

Get the distinction wrong and you either spend a week on a document that needed a day, or you ship a slim response when the buyer expected the full thing.

Same publisher, different scope

First, a note on terminology. “SIG Lite” and “SIG Core” began as two distinct spreadsheets published by Shared Assessments, the industry group that sets the standard for third-party risk questionnaires. In recent releases Shared Assessments has moved toward a single SIG that buyers scope dynamically rather than two fixed files — but “Lite” and “Core” remain the terms almost everyone still uses for the short version and the full version, and that’s how buyers will describe what they send you. We use them the same way here.

Both scopings draw from the same underlying SIG content library and cover the same risk domains: governance, security policy, access control, incident response, business resilience, cloud hosting, and so on.

The difference is depth.

  • SIG Lite is the abbreviated subset — a few hundred questions in a typical release. It is designed for routine vendor assessments: a buyer onboarding a vendor whose product or service is low-to-moderate risk, or doing an annual re-attestation.
  • SIG Core is the comprehensive version, often called “the full SIG.” It runs to many hundreds of questions — commonly a thousand or more once optional content and add-ons are included. It is designed for vendors handling sensitive data, providing critical services, or where the buyer’s own regulators expect enhanced due diligence.

Shared Assessments also publishes domain-specific add-ons (privacy, AI, third-party risk management) that can be appended to either scoping. The buyer chooses what to send.

How to tell which one you’ve received

Three quick checks:

  1. Count the rows. Open the file and look at the populated question rows. A few hundred points to a Lite scoping; a thousand-plus points to Core. Anything in between is usually Lite plus one or two add-on modules.
  2. Check the tab names. A Core scoping typically has every risk-domain tab populated with hundreds of rows each. Lite typically uses a single combined tab or a slim version of each domain tab.
  3. Read the buyer’s covering email. Most buyers tell you explicitly. If they say “we’ve sent our standard vendor due diligence questionnaire,” ask whether it is SIG Lite, SIG Core, or a bespoke spreadsheet derived from one.

If you still aren’t sure, the safe move is to email the buyer’s risk contact and confirm. “Just to confirm — is this SIG Lite or the full SIG?” sounds professional, not naive. Procurement teams send these out hundreds of times a year and assume vendors know the difference, but the minute you ask they will clarify.

What changes between the two

Time to answer honestly. A first-time SIG Lite typically takes a few days of focused work spread across one or two people who hold the relevant context. A first-time SIG Core typically takes a week or two of work spread across security, IT, HR, legal, and engineering — because the questions cross every domain, and no single person inside a small company will have all the answers.

Depth of evidence the buyer will request. SIG Lite “Yes” answers are usually accepted with a brief explanation or a single supporting document. SIG Core “Yes” answers are more likely to draw follow-up requests: policy excerpts, configuration screenshots, third-party attestations, sample audit logs. If you don’t have the evidence ready, the follow-ups extend the procurement cycle by weeks.

The questions that aren’t in SIG Lite. SIG Lite is the standard subset. SIG Core adds depth in three areas that catch unprepared vendors: detailed application security questions for any custom-developed software, granular cloud and infrastructure configuration questions, and full business continuity / disaster recovery testing evidence. If you sell custom software or you are the primary hosting provider for the buyer’s data, the SIG Core will probe those sections hard.

Reusability. Both formats are designed for reuse. Whichever you complete this time, the answers carry forward to the next buyer who sends the same format. SIG Lite answers can be expanded into a SIG Core later by filling in the additional questions; SIG Core answers can be subset into a SIG Lite trivially. The work you do is durable in either direction.

When buyers send each one

You can usually predict which version is coming. SIG Lite is the default for:

  • Mid-market buyers running routine vendor onboarding
  • Annual re-attestations of existing vendors
  • Lower-risk product categories (productivity tools, analytics, marketing software)
  • Engagements where the buyer’s risk team has limited bandwidth and wants to triage fast

SIG Core is the default for:

  • Financial-services buyers, healthcare buyers, and other regulated industries
  • Any vendor handling personally identifiable information at scale
  • Cloud providers, infrastructure providers, and any vendor with privileged access to the buyer’s systems
  • Vendors flagged as “critical” or “tier 1” in the buyer’s vendor risk register
  • Engagements where the buyer’s own auditors will review the vendor file

If you sell into regulated industries and you haven’t seen a SIG Core yet, you will. It’s worth preparing for that scope in advance rather than discovering it the week of the deal.

What to do when the deal is live and the clock is running

Three realistic options once the spreadsheet is in your inbox:

  1. Answer it yourselves. Workable if you have a maintained internal answer library and a SIG Lite. Risky for a first-time SIG Core because of the cross-functional coordination required.
  2. Build the answer library now, under deadline pressure. Not ideal — you’re doing strategic work and tactical work simultaneously — but it sets you up for the next questionnaire to be much faster.
  3. Outsource the response. If the questionnaire is blocking a live deal and the internal team is already at capacity, vendor security questionnaire help handles the full SIG, SIG Lite, CAIQ, or bespoke spreadsheets at a fixed price quoted up front. Typical turnaround is about three days for SIG Lite and about a week for SIG Core, and you keep the answer library at the end so the next one is straightforward.

For the structure and worked examples you can use either way, see our step-by-step questionnaire playbook and the free SIG Lite answer-library template.

FAQ

Is SIG Lite really “lite,” or is the name misleading?

The name is accurate compared to SIG Core but it overstates how quick the document is in absolute terms. A few hundred questions across every risk domain is not a fast answer for a vendor without a prepared library. “Lite” means lighter than SIG Core, not lightweight.

Can we submit a SIG Core answer if the buyer asked for SIG Lite?

You can, but most buyers will not appreciate it. The risk team has a reason for sending the shorter version — usually a triage process that flags vendors who need the longer review. Sending back unprompted SIG Core answers can re-route your deal into a heavier process. Stick to what was asked for unless the buyer explicitly invites the expanded answers.

How often does the SIG update?

Shared Assessments releases a new version of the SIG on a regular annual cadence. Your existing answer library should be reviewed against each release — most years the changes are incremental, but new content areas (AI, privacy, emerging risk areas) periodically get added or expanded.

Is the CAIQ a substitute for the SIG?

No, they are different documents with overlapping content. The Cloud Security Alliance’s Consensus Assessment Initiative Questionnaire (CAIQ) is targeted specifically at cloud service providers. Some buyers accept CAIQ in place of the cloud-hosting section of the SIG; most do not. Expect to maintain both if you sell cloud services.