SIG · Standard Information Gathering

What is the SIG questionnaire? A 2026 guide for the vendor who just received one.

A customer — probably your biggest prospect this quarter — has sent you a spreadsheet called a SIG, and the deal is paused until it comes back. This guide explains what the SIG questionnaire is, why you received it, and how to answer it without burning weeks or signing up for commitments you can't keep.

What the SIG actually is

The SIG — Standard Information Gathering questionnaire — is a standardized third-party risk assessment maintained by Shared Assessments. Instead of every enterprise writing its own security questions, the SIG gives buyers a common question bank organized into risk domains: information security policy, access control, incident response, business continuity, cloud security, privacy, third-party management, and more.

When procurement says "please complete the attached SIG," they are asking you to document, in writing, how your company actually runs security. Your answers usually become part of the vendor file — and often part of the contract's representations.

SIG Core vs SIG Lite

There are two main editions, and which one lands on your desk tells you how the buyer has classified you:

  • SIG Lite — the condensed screening version. Used for lower-risk vendors, smaller engagements, or as a first pass. Still substantial, but answerable in days.
  • SIG Core — the full assessment, several times longer, with deeper questions per domain. Typically reserved for vendors that touch sensitive data or critical processes.

Some buyers also cherry-pick SIG content into their own spreadsheet. If the row IDs look like SIG numbering but the file has your customer's logo on it, treat it as a SIG — your answer library (more on that below) will still apply.

Why you received it

Someone on the buying side — security, procurement, or a GRC platform acting for them — flagged your product as a third-party risk. That is not an accusation; it's a process. The questionnaire is a gate in their purchase workflow, which means the deal does not move until it's returned. That asymmetry is why a document nobody budgeted time for becomes the most urgent thing on your desk.

33 worked sample answers across 14 risk domains, each mapped to ISO 27001:2022 / NIST CSF / CSA CCM. Most SIG questions overlap the SIG Lite domains; use it to pre-stage your library before the real SIG lands.

What reviewers actually check

The person reading your answers is rarely impressed by volume. Experienced reviewers look for three things:

  1. Internal consistency. If you claim quarterly access reviews in one domain and "not applicable" identity governance in another, you've told them you didn't read your own answers.
  2. Evidence behind claims. Answers that cite a named policy, a tool, or a dated report read as real. Bare "Yes" answers read as hopeful.
  3. Honest gaps. A "No — compensating control X, roadmap Y" earns more trust than a "Yes" that collapses in the follow-up call. Reviewers expect gaps; they're testing whether you know yours.

How to answer the SIG, step by step

If you're doing it in-house, this sequence saves the most time:

  1. Triage by risk domain before answering anything. The SIG is organized into risk domains — access control, incident response, cloud security, third-party management, and so on. Read every question once, tag it know-it / need-to-ask / genuine-gap, and mark whole domains in or out of scope for what you actually sell. A physical-datacenter domain is "N/A — fully cloud-hosted on AWS," not forty individual blanks. The tag distribution tells you the real effort and who you need in the room.
  2. Start from an answer library, not a blank spreadsheet. Our free SIG Lite answer-library template gives you the structure: one row per question, columns for the answer, the evidence citation, and the date it was last verified. Even if you've received SIG Core, the Lite library covers the questions that repeat most.
  3. Answer to what you run today, not what you intend. Your answers usually become contract representations. Aspirations belong in a roadmap note, not in the answer cell — a reviewer who catches one inflated "Yes" discounts every other answer in the file.
  4. Cite evidence on every "Yes." Name the policy and section ("Access Control Policy §4.2"), the tool, or the dated report behind each affirmative answer. Cited answers read as real, survive the follow-up call, and are the only kind worth reusing.
  5. Write defensible answers for the gaps. For each genuine-gap question, choose one of three honest shapes: a plain "No," a "No — compensating control X covers the same risk," or a "No — on the roadmap for Q3 with owner named." Reviewers expect gaps; what they're testing is whether you know yours.
  6. Save the library with verification dates. Most of the next SIG — from any prospect — repeats this one. Record when each answer was last verified so that next time you re-confirm the stale rows instead of starting over.

When the answer is no: closing SIG-specific gaps

The SIG's heaviest domains — logging, access control, vulnerability management — are also the ones most often answered "no." Each maps to an open-source component we deploy and operate, so the gap list from one SIG becomes deployed controls before the next:

  • Information-security / logging domains: Managed Wazuh — centralised logs with retention you can cite by number.
  • Access-control domains: Managed Teleport — recorded, just-in-time privileged access that turns access-review questions into a log export.
  • Threat & vulnerability management: Managed OpenVAS — scheduled authenticated scans with tracked remediation.

If your customer named the SIG specifically

"Please complete the attached SIG" is procurement-speak for "your deal is on hold until this comes back." If procurement wants it by Friday and the questionnaire arrived Tuesday, building the library while answering the live document is the trap that stalls the deal. The faster route: send us the questionnaire — $399 flat for a SIG Lite, scoping session included, fixed-price quoted from the document for SIG Core or SIG Plus, three business days, and you keep the reusable answer library.

Send Gordon the SIG →

When to hand it off

The honest math: a SIG consumes days of your most senior engineering attention at exactly the moment a deal needs it. If the questions are landing on someone who didn't build the controls — or if the deadline is measured in days — a specialist who answers questionnaires all week is faster and usually more defensible. ThinSky's Questionnaire Rescue reads your SIG and your actual posture in parallel, drafts truthful cited answers in about 3 days, and hands back the answer library you keep.

Common questions.

How long does it take to complete a SIG questionnaire?

Teams answering their first SIG typically spend days of focused senior-engineer time spread over several weeks, because the answers live in many heads. A specialist working from your documentation and a structured interview can return a defensible draft in 3 business days — $399 flat for a SIG Lite, scoping session included, with SIG Core or SIG Plus quoted fixed-price from the document.

What is the SIG questionnaire?

The SIG (Standard Information Gathering) questionnaire is a standardized vendor risk assessment published by Shared Assessments. Your customer's procurement or security team sends it to evaluate your security posture before — or while — signing a contract.

What is the difference between SIG Core and SIG Lite?

SIG Lite is the condensed version used for lower-risk vendors or early-stage screening. SIG Core is the full assessment, several times longer, covering domains like access control, incident response, business continuity, and third-party management in depth. Which one you receive depends on how much risk the buyer assigns to your service.

Can I outsource the SIG questionnaire?

Yes. A done-for-you service reads the questionnaire and your actual security posture in parallel, drafts truthful answers that cite your real controls, and flags gaps before you commit them to a contract. ThinSky does this for a fixed price quoted up front.

Or skip the spreadsheet entirely.

Email us the questionnaire, the deadline, and a sentence about the deal — we reply with scope and a fixed quote within one business day.

Get questionnaire rescue →