Security Questionnaires: What They Mean for Your Organization

A security questionnaire is a set of questions a customer, partner or cyber insurer sends to find out how you protect information. Some arrive as recognized formats, such as the SIG, the CAIQ or the HECVAT. Others are a customer’s own spreadsheet or an insurer’s application. They all ask the same core things: who can sign in and how, whether data is encrypted and backed up, what gets logged, how you handle incidents, and which rules you follow. The answers become part of how people decide to trust you, and sometimes part of a contract or an insurance policy. ALCON DTS can help you gather evidence and draft the technical answers for your review. You review, sign and submit.

Talk with ALCON DTSSee what you need in place

At a glance

  • SIG: the Standardized Information Gathering questionnaire from Shared Assessments, updated on an annual cycle; SIG Lite covers lower-risk third parties and SIG Core goes deeper for higher-risk service providers
  • CAIQ: the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance; CAIQ v4.1, released January 2026, has 283 questions aligned with the Cloud Controls Matrix v4.1
  • HECVAT: the Higher Education Community Vendor Assessment Toolkit from EDUCAUSE; the current version is HECVAT 4 (version 4.1.6), which combines the former Full, Lite and On-Prem versions into one file
  • Insurer applications: each insurer uses its own forms, and questions change from year to year
  • Who is responsible for the answers: you are. Others can help draft them, but the person who signs is vouching for the answers on behalf of your organization.
  • Best practice: answer what is true today, keep evidence for every “yes,” and ask your broker or attorney when a question has legal or coverage consequences
  • Last reviewed: September 30, 2026

What are security questionnaires?

Security questionnaires are how organizations check the security of the companies they work with. A hospital checks its billing service. A manufacturer checks its IT provider. A university checks a software vendor. An insurer checks a business before it offers cyber coverage.

The questions come in a few common forms:

  • Standard formats. Recognized questionnaires published by industry groups, so one set of answers can be reused across many customers.
  • Custom customer questionnaires. A customer’s own list, often built from a standard format or a framework.
  • Insurer applications. Cyber insurance applications, renewal forms and supplemental questionnaires, often focused on MFA, backups, email security and incident response.
  • Contract security exhibits. Security requirements written into a contract, sometimes with a questionnaire attached.

What does this cover, and what doesn’t it?

It covers: the common questionnaire formats, how to answer honestly, what evidence to keep, how the topics in our other guides map to typical questions, and where ALCON DTS can help.

It is not:

  • An audit or a certification. A completed questionnaire is your own statement about your controls. It is not an independent audit.
  • Something your IT provider signs for you. You attest to your answers. ALCON DTS can help gather evidence and draft technical answers, and you decide what to submit.
  • Legal or insurance advice. Questions about contract terms, coverage or the effect of an answer belong with your attorney or broker.

Do security questionnaires apply to you?

You will likely see security questionnaires if:

  1. You sell services to larger organizations. Health systems, manufacturers, financial firms, universities and government contractors commonly assess their vendors.
  2. You buy or renew cyber insurance. Applications and renewals ask about your controls.
  3. You handle regulated information for someone else. A business associate under HIPAA or a defense supplier handling controlled unclassified information will be asked how that information is protected.

Quick check: does this apply to you?

  • A customer, partner or insurer has sent you security questions in the last year, or you expect them at your next renewal or contract.
  • Your answers affect a sale, a contract or your insurance.

If both are true, this very likely applies to you. If a questionnaire is tied to a contract or an insurance policy, confirm with your attorney or broker what signing it means for you.

What do you need to have in place?

The common formats

Versions confirmed from the publishers’ websites where available. Always answer the version the requester sends, and keep a copy of what you submitted.
Format Published by Current version (as of September 30, 2026) Typically used for
SIG (Standardized Information Gathering) Shared Assessments Annual release; the 2026 content is current Third-party service providers of all kinds; SIG Lite for lower risk, SIG Core for higher risk
CAIQ (Consensus Assessments Initiative Questionnaire) Cloud Security Alliance CAIQ v4.1, released January 2026, with 283 questions; a shorter CAIQ-Lite is also available Cloud service providers describing their controls against the Cloud Controls Matrix
HECVAT (Higher Education Community Vendor Assessment Toolkit) EDUCAUSE, with Internet2 and REN-ISAC HECVAT 4, version 4.1.6 Vendors selling technology to colleges and universities
Insurer applications Each insurer Varies by insurer and year New policies, renewals and supplemental questions
Customer questionnaires Each customer Varies Vendor onboarding and annual reviews

A few details worth knowing:

  • SIG. Shared Assessments describes SIG Lite as a foundation of questions for lower-risk third parties and SIG Core as a comprehensive set for service providers that pose higher risk. Assessors can also mix in more detailed questions from the SIG content library for specific domains. In March 2026, Shared Assessments launched a web-based version of the SIG alongside the familiar spreadsheet.
  • CAIQ. The Cloud Security Alliance describes the CAIQ as a set of “yes/no” questions to assess security controls. Both version 4.0 and 4.1 are accepted for its public registry until December 2027. If you are not a cloud service provider, you may still receive a CAIQ from a customer who uses it as a general template.
  • HECVAT. EDUCAUSE says HECVAT 4 added questions on privacy and AI. Vendors may use it with their college and university customers at no cost.

How do you answer honestly?

  • Answer what is true today. A control you plan to add next quarter is a “no” or “in progress” today. Say when it is planned.
  • Use the comment field. “Partially” with a short explanation is better than a “yes” that is only true for some systems. Name the scope: which users, which systems, which locations.
  • Mention compensating controls, not excuses. If you don’t do exactly what is asked, explain what you do instead and why.
  • Keep answers consistent. Different customers will ask the same question in different words. Keep one answer library so your answers match.
  • Know who signs. The person who signs is attesting for the organization. Make sure they have read the answers.
  • Don’t guess. If you don’t know, find out. A wrong “yes” can cause more trouble than an honest “no.”

Why accuracy matters on insurance applications

Insurers generally rely on the answers in your application when they decide whether to offer coverage and on what terms. If an answer turns out to be inaccurate, it can create problems later, including when you make a claim. How that works depends on your policy language and the law that applies, so this is a question for your broker and your attorney, not your IT provider. Read every question carefully, answer for the whole organization, and tell your broker if something changes before the policy starts.

What evidence should you keep?

Keep a dated evidence file that backs up your answers. Common items include:

  • MFA registration and enforcement reports, and your sign-in policies
  • A list of administrator accounts and when they were last reviewed
  • Device inventory and encryption status
  • Backup settings and records of restore tests
  • Email authentication settings and filtering
  • Logging and monitoring settings, and examples of alerts handled
  • Written policies: acceptable use, access control, incident response, and your acceptable AI use rules
  • Security awareness training completion records
  • Your latest risk analysis or framework assessment, with the work plan
  • Business associate agreements and vendor contracts, where they apply
  • A copy of each questionnaire you submitted, with the date and who signed

How the other guides map to typical questions

Questions vary by format and requester. This mapping is general guidance.
Typical question topic Where to find the background
Do you require MFA? For email, remote access, administrators, backups? Our MFA and Conditional Access guide
Do you follow a recognized framework? Our NIST CSF 2.0 and CIS Controls IG1 guides
Do you handle patient information? Have you done a risk analysis? Our HIPAA security risk analysis and ePHI in Microsoft 365 guides
Do you sign business associate agreements? Our business associate agreements guide
Do you have an incident response plan? How do you notify customers of a breach? Our Texas breach notification guide
Are you working toward CMMC or NIST SP 800-171? Our CMMC guide for DoD suppliers
Do you meet Texas requirements? Our Texas SB 2610 Cybersecurity Safe Harbor page
Do you use AI tools with customer data? What are your AI rules? Our Microsoft Copilot readiness guide and Acceptable AI Use page

How can ALCON DTS help you?

You keep the compliance decisions. We run the controls. You keep the attestation: you review, sign and submit every questionnaire, and ALCON DTS does not attest for you. What we can do is make sure the technical answers come from the live environment, not from memory.

Need What ALCON DTS provides
Technical answer drafts Draft technical answers for your review, based on the settings we can see in the systems we manage, covering MFA, encryption, backups, logging and admin access. You confirm each answer before you sign
Evidence Help gathering the reports, settings and records that support each answer, organized in an evidence file
Identity and access MFA, sign-in rules and least-privilege administrator roles, with joiner, mover and leaver changes kept current
Devices, email and backup Devices kept updated, protected and encrypted; email security and domain authentication; tested backup
Monitoring Alerts routed to a named owner. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control.
Training Security awareness training with completion records
Follow-up questions We sit with you to explain the technical controls we run when a customer, insurer or regulator asks how the work is done

Questionnaire help is included in Secure IT. The exact controls behind your answers depend on your ALCON DTS plan and any project work. ALCON DTS does not provide legal or insurance advice, does not certify compliance, and does not sign or submit questionnaires on your behalf.

Have a questionnaire or insurance renewal on your desk? Contact us and we will set up a secure way to share it. We will help gather the evidence and draft the technical answers for your review, and flag anything that isn’t true yet.

Talk with ALCON DTS

How do security questionnaires fit with other rules?

  • HIPAA. Customers that are covered entities often send questionnaires before signing a business associate agreement. Your answers should match your security risk analysis (45 CFR 164.308(a)(1)(ii)(A)) and your agreement.
  • CMMC and NIST SP 800-171. Defense customers may ask about your status. Answer based on your actual assessment results and plan, and see our CMMC guide for DoD suppliers.
  • Texas Cybersecurity Safe Harbor (SB 2610). A documented program that conforms to a recognized framework (Bus. and Com. Code Sec. 542.004) also gives you a consistent basis for questionnaire answers. See Texas SB 2610 Cybersecurity Safe Harbor.
  • Contracts. Some customers attach your answers to the contract or require you to tell them if something changes. Read those terms with your attorney.
  • Insurance. Your application may become part of your policy. Review it with your broker before you sign.

Frequently asked questions

Yes, and you should keep an answer library. Check each answer is still true and fits the exact question before you reuse it.

Say so, and add what you do instead or when you plan to add the control. A clear “no” with a plan is easier to stand behind than a “yes” that later turns out to be wrong.

We can help gather evidence and draft the technical answers for your review. You review, sign and submit. ALCON DTS does not attest for you.

Use the version the requester sends. As of September 30, 2026, the current CAIQ is v4.1 and the current HECVAT is version 4.1.6. The SIG is updated each year.

Mark it not applicable and explain why in a short comment, for example that you don’t store card data.

Tell your broker. Changes before a policy starts, or during it, may matter under your policy terms.

No. A questionnaire is your own statement. Some customers also ask for independent audit reports, which is a separate decision.

At least before each renewal or major questionnaire, and whenever a key control changes.

Sources

Last reviewed: September 30, 2026

This page is general information about security questionnaires, not legal or insurance advice for your situation.

Talk with ALCON DTS about security questionnaires

Have a customer questionnaire or an insurance renewal coming up? We will help pull the evidence together and draft the technical answers for your review, so what you sign matches how your systems run.

Email: info@alcondts.com ยท Phone: 512-892-6900

Talk with ALCON DTS