Request a Consultation

Free template · CSV

A free SIG Lite answer-library template. No email wall, no watermark.

Most "free security questionnaire templates" are an email gate in front of a PDF you can't type into. This one is a plain CSV: open it in Excel or Google Sheets, and start building the asset that actually saves you time — a cited answer library, structured the way SIG-style reviews are organized.

Download the template (CSV, no email) →

What's in it

  • 30 starter questions across 14 SIG-style risk domains — access control, incident response, application security, business resilience, cloud hosting, privacy, third-party management, and more. The wording is ours; swap in your customer's exact questions as they arrive.
  • Three worked examples showing what a defensible answer looks like: one clean "yes" with citations, one tested-control answer, and one honest gap answered with a compensating control and a roadmap — the three shapes nearly every real answer takes.
  • The columns that make answers reusable: evidence/citation, owner, status, and last-verified date. The citation column is the whole trick — "Yes" expires; "Yes, per Access Control Policy §4, reviewed May 2026" survives into the next questionnaire.

What it is not

SIG and SIG Lite are products of Shared Assessments, and the official question set is licensed — we don't reproduce it, and you should be skeptical of any free download that claims to. You'll receive the real SIG from your customer. What this template gives you is the answer side, organized around comparable domains, so that when the official spreadsheet lands, most of your answers are already written and cited.

How to use it

  1. Fill in what's true today. Work down the rows answering only to controls that actually run. Aspirations go in the notes, not the answer cell.
  2. Cite as you go. Every answer names the policy, tool, or dated report behind it. Uncited answers are the first ones to rot.
  3. Tag the gaps honestly. Empty rows are your gap list — the same list a reviewer would find anyway. Pair each gap with the compensating control you run today (see worked example EX-3).
  4. Assign owners and verify dates. An answer nobody owns is an answer that's wrong by next quarter. Re-verify before each submission.
  5. When the real questionnaire arrives, map its questions to your library rows, copy, adapt wording, done. Teams that maintain the library reuse 70–90% of it per questionnaire.

If the deadline is this week

A template helps you build the library over weeks. It does not help when the SIG arrived Tuesday and procurement wants it back Friday. For that, Questionnaire Rescue exists: we read the questionnaire and your actual posture in parallel, draft truthful answers citing your real controls, and hand back both the completed document and the library — typical SIG in about 3 days.

Common questions.

Is this the official SIG Lite questionnaire?

No. SIG and SIG Lite are products of Shared Assessments, and the official question set is licensed — you'll receive the real document from your customer or from Shared Assessments directly. This is a free answer-library template organized around comparable risk domains, so your answers are ready before the official spreadsheet arrives.

Why build an answer library instead of just filling in the questionnaire?

Because every prospect's questionnaire is mostly the same questions in a different spreadsheet. If your answers live in one cited, dated library, the next SIG, CAIQ, or insurance form starts 70–90% answered. If they only live in last quarter's submitted spreadsheet, you start from scratch every time.

Do I need to give you my email to download it?

No. The CSV downloads directly — no form, no email, no follow-up sequence. If you want the questionnaire answered for you instead, that's our Questionnaire Rescue service.

What if I can't answer most of the rows?

That's a finding, not a failure — the empty rows are your gap list. Answer what's true today, tag the gaps, and either work the roadmap or hand the whole thing to us: we draft truthful, cited answers in about 3 days for an introductory fixed price of $750.

Or send us the real questionnaire.

When the actual SIG lands with a deadline attached, we answer it truthfully in about 3 days and hand back the completed library — introductory fixed price of $750.

Get questionnaire rescue →