What Is a SIG Questionnaire? A Plain-English Guide for Vendors
A buyer just sent you a spreadsheet with hundreds of rows, called it “the SIG,” and asked you to fill it out before the contract can move forward. If you’ve never seen one before, the instinct is to either panic or to delegate it to “whoever does security” and hope they figure it out in time.
Both reactions cost you the deal. Here’s what the document actually is, who created it, what’s in it, and the realistic options for getting it done.
SIG stands for Standardized Information Gathering
The SIG questionnaire is published by Shared Assessments, a member-driven industry group originally founded by financial services firms and the Big Four audit firms. They needed a common format for evaluating third-party vendors because every bank was sending every vendor a slightly different spreadsheet, and every vendor was answering them all slightly differently. The SIG is the standard that ended that chaos — or at least standardised it.
Today, the SIG is the most widely used third-party risk questionnaire in North America. If you sell software, infrastructure, professional services, or really any B2B offering to a mid-market or enterprise buyer, you will eventually be asked to complete one.
What’s actually inside it
The SIG is organised into risk domains that cover the full third-party risk surface. The exact count and naming shift as Shared Assessments updates the standard each year, but the categories are stable. A current SIG spans domains such as:
- Risk management and governance
- Security policy
- Organisational security
- Asset management
- Human resources security
- Physical and environmental security
- Communications and operations management
- Access control
- Information systems acquisition, development, and maintenance
- Incident event and communications management
- Business resilience
- Compliance
- End-user device security
- Network security
- Privacy
- Threat management
- Server security
- Cloud hosting
Within each domain, the questions probe whether you have policies, whether those policies are documented, whether the documentation is current, whether the controls are actually implemented, and whether implementation is monitored. A typical question reads: “Does the organisation have a formal information security policy that is approved by management, published, communicated to employees, and reviewed at planned intervals?”
You answer Yes, No, or N/A — and for any “Yes,” the buyer’s risk team can ask for the evidence.
Why the answers are not optional
The questionnaire is a contractual checkpoint. Procurement teams treat it as a gate: no completed SIG, no signed master services agreement. The buyer is taking on third-party risk by working with you, and their own auditors, regulators, and cyber-insurance carriers want documented evidence of vendor due diligence. The SIG is that evidence.
Two consequences follow:
First, the answers get attached to contracts. Whatever you put in the spreadsheet becomes part of the relationship. Aspirational answers — claiming controls you don’t actually run — resurface during audits, incident post-mortems, and renewal reviews. They are worse than honest “no” answers because they introduce a discoverable gap between contract language and operational reality.
Second, the questionnaire is a sales document with a deadline. The team that returns it fastest, with answers that survive scrutiny, wins. Companies that treat each SIG as a surprise and start from zero every time pay the panic tax on every deal.
Who fills it out
In a small company the honest answer is “whoever has the bandwidth and the most context.” In practice that means the founder, the head of engineering, or the IT generalist gets handed the spreadsheet and given a few days to figure it out. None of them have done it before. None of them have a structured place to put the answers. Every one of the next questionnaires that comes in starts the same exercise from scratch.
The professional pattern is to build an answer library — a structured document where each question theme is paired with your honest answer and a pointer to the evidence behind it (the policy document, the screenshot, the config export). The first SIG is hard work. The next one is mostly lookup.
Honest vs aspirational answers
The tempting move, with a deal on the line, is to answer the questionnaire you wish were true. “Do you have a formal incident response plan?” Yes. “Is access reviewed quarterly?” Of course.
The professional answer pattern is “no, with a compensating control.” For example: “We do not currently run a 24/7 security operations centre. Security alerts page an on-call engineer through a documented escalation path, and monitoring coverage is reviewed each quarter.”
Buyers read thousands of these answers. Specific honesty reads as maturity. Vague perfection reads as fiction. The most experienced procurement risk reviewers will trust a “no with explanation” before they trust an unqualified “yes” — because the no shows you understand the question.
What does it cost in time
A first SIG done properly — meaning the answers are honest, the evidence exists, and the library is structured for reuse — is real work, typically days of effort spread across the people who hold the answers. Subsequent SIGs drop to a fraction of that, because most answers carry forward unchanged.
The cost of doing it badly is harder to quantify but always larger: a deal lost because the questionnaire missed the deadline, a deal closed on answers that don’t hold up at audit, or a renewal lost because the original answers turned out to be wrong.
Your three realistic options
When a SIG lands in your inbox:
- Answer it yourselves from scratch every time. Workable for the first one or two; doesn’t scale.
- Build and maintain an internal answer library. The right long-term answer. Requires someone with security context to own it and keep it current. Our step-by-step playbook walks through the structure, and the free SIG Lite answer-library template gives you a starting frame.
- Outsource the response. If the questionnaire is blocking a live deal and nobody internal has the bandwidth, vendor security questionnaire help is a legitimate play. We answer the full SIG, SIG Lite, CAIQ, or a buyer’s bespoke spreadsheet at a fixed price quoted up front, typically in about three days, and you keep the answer library at the end.
The one option that doesn’t work is treating each new SIG as a one-time emergency. The questionnaire isn’t going away — win this deal and the next customer will send theirs, and renewals re-send them annually.
FAQ
Is the SIG the same thing as SIG Lite?
No. Shared Assessments publishes the full SIG (often called SIG Core) and a shorter version called SIG Lite. SIG Lite covers the same risk domains in less depth and is what most mid-market buyers actually send. If a buyer asks for “the SIG” without specifying, ask whether they want SIG Lite or SIG Core — answering the wrong one wastes everyone’s time.
Is the SIG the same as a SOC 2 report?
No. A SOC 2 report is an attestation produced by an independent auditor describing the controls you run and whether they operated effectively over a period. The SIG is a self-assessment questionnaire you complete yourself. Both can sit in the same vendor file; neither replaces the other. A SOC 2 report shortcuts some SIG questions because you can cite the report instead of writing a long answer, but it doesn’t eliminate the questionnaire.
Do we need an information security policy before answering the SIG?
In practice, yes. A surprising number of SIG questions assume you have documented policies that you can cite. If you don’t, the honest answers will be a lot of “no” and the buyer’s risk team will flag the deal for additional review. The fastest path is to write the policies you actually need to answer the questions, then deploy them — not the other way around.
Can a SIG kill a deal?
It can stall one indefinitely, which amounts to the same thing. The most common pattern is not a flat rejection — it’s the buyer’s risk team asking for clarification, then more clarification, then a follow-up call, while the procurement clock keeps running and the original buyer champion gets reassigned. Answering crisply on the first pass keeps the deal moving.