Security Questionnaires: What They Mean for Your Organization
A security questionnaire is a set of questions a customer, partner or cyber insurer sends to find out how you protect information. Some arrive as recognized formats, such as the SIG, the CAIQ or the HECVAT. Others are a customer’s own spreadsheet or an insurer’s application. They all ask the same core things: who can sign in and how, whether data is encrypted and backed up, what gets logged, how you handle incidents, and which rules you follow. The answers become part of how people decide to trust you, and sometimes part of a contract or an insurance policy. ALCON DTS can help you gather evidence and draft the technical answers for your review. You review, sign and submit.
This page answers:
At a glance
- SIG: the Standardized Information Gathering questionnaire from Shared Assessments, updated on an annual cycle; SIG Lite covers lower-risk third parties and SIG Core goes deeper for higher-risk service providers
- CAIQ: the Consensus Assessments Initiative Questionnaire from the Cloud Security Alliance; CAIQ v4.1, released January 2026, has 283 questions aligned with the Cloud Controls Matrix v4.1
- HECVAT: the Higher Education Community Vendor Assessment Toolkit from EDUCAUSE; the current version is HECVAT 4 (version 4.1.6), which combines the former Full, Lite and On-Prem versions into one file
- Insurer applications: each insurer uses its own forms, and questions change from year to year
- Who is responsible for the answers: you are. Others can help draft them, but the person who signs is vouching for the answers on behalf of your organization.
- Best practice: answer what is true today, keep evidence for every “yes,” and ask your broker or attorney when a question has legal or coverage consequences
- Last reviewed: September 30, 2026
What are security questionnaires?
Security questionnaires are how organizations check the security of the companies they work with. A hospital checks its billing service. A manufacturer checks its IT provider. A university checks a software vendor. An insurer checks a business before it offers cyber coverage.
The questions come in a few common forms:
- Standard formats. Recognized questionnaires published by industry groups, so one set of answers can be reused across many customers.
- Custom customer questionnaires. A customer’s own list, often built from a standard format or a framework.
- Insurer applications. Cyber insurance applications, renewal forms and supplemental questionnaires, often focused on MFA, backups, email security and incident response.
- Contract security exhibits. Security requirements written into a contract, sometimes with a questionnaire attached.
What does this cover, and what doesn’t it?
It covers: the common questionnaire formats, how to answer honestly, what evidence to keep, how the topics in our other guides map to typical questions, and where ALCON DTS can help.
It is not:
- An audit or a certification. A completed questionnaire is your own statement about your controls. It is not an independent audit.
- Something your IT provider signs for you. You attest to your answers. ALCON DTS can help gather evidence and draft technical answers, and you decide what to submit.
- Legal or insurance advice. Questions about contract terms, coverage or the effect of an answer belong with your attorney or broker.
Do security questionnaires apply to you?
You will likely see security questionnaires if:
- You sell services to larger organizations. Health systems, manufacturers, financial firms, universities and government contractors commonly assess their vendors.
- You buy or renew cyber insurance. Applications and renewals ask about your controls.
- You handle regulated information for someone else. A business associate under HIPAA or a defense supplier handling controlled unclassified information will be asked how that information is protected.
Quick check: does this apply to you?
- A customer, partner or insurer has sent you security questions in the last year, or you expect them at your next renewal or contract.
- Your answers affect a sale, a contract or your insurance.
If both are true, this very likely applies to you. If a questionnaire is tied to a contract or an insurance policy, confirm with your attorney or broker what signing it means for you.
What do you need to have in place?
The common formats
| Format | Published by | Current version (as of September 30, 2026) | Typically used for |
|---|---|---|---|
| SIG (Standardized Information Gathering) | Shared Assessments | Annual release; the 2026 content is current | Third-party service providers of all kinds; SIG Lite for lower risk, SIG Core for higher risk |
| CAIQ (Consensus Assessments Initiative Questionnaire) | Cloud Security Alliance | CAIQ v4.1, released January 2026, with 283 questions; a shorter CAIQ-Lite is also available | Cloud service providers describing their controls against the Cloud Controls Matrix |
| HECVAT (Higher Education Community Vendor Assessment Toolkit) | EDUCAUSE, with Internet2 and REN-ISAC | HECVAT 4, version 4.1.6 | Vendors selling technology to colleges and universities |
| Insurer applications | Each insurer | Varies by insurer and year | New policies, renewals and supplemental questions |
| Customer questionnaires | Each customer | Varies | Vendor onboarding and annual reviews |
A few details worth knowing:
- SIG. Shared Assessments describes SIG Lite as a foundation of questions for lower-risk third parties and SIG Core as a comprehensive set for service providers that pose higher risk. Assessors can also mix in more detailed questions from the SIG content library for specific domains. In March 2026, Shared Assessments launched a web-based version of the SIG alongside the familiar spreadsheet.
- CAIQ. The Cloud Security Alliance describes the CAIQ as a set of “yes/no” questions to assess security controls. Both version 4.0 and 4.1 are accepted for its public registry until December 2027. If you are not a cloud service provider, you may still receive a CAIQ from a customer who uses it as a general template.
- HECVAT. EDUCAUSE says HECVAT 4 added questions on privacy and AI. Vendors may use it with their college and university customers at no cost.
How do you answer honestly?
- Answer what is true today. A control you plan to add next quarter is a “no” or “in progress” today. Say when it is planned.
- Use the comment field. “Partially” with a short explanation is better than a “yes” that is only true for some systems. Name the scope: which users, which systems, which locations.
- Mention compensating controls, not excuses. If you don’t do exactly what is asked, explain what you do instead and why.
- Keep answers consistent. Different customers will ask the same question in different words. Keep one answer library so your answers match.
- Know who signs. The person who signs is attesting for the organization. Make sure they have read the answers.
- Don’t guess. If you don’t know, find out. A wrong “yes” can cause more trouble than an honest “no.”
Why accuracy matters on insurance applications
Insurers generally rely on the answers in your application when they decide whether to offer coverage and on what terms. If an answer turns out to be inaccurate, it can create problems later, including when you make a claim. How that works depends on your policy language and the law that applies, so this is a question for your broker and your attorney, not your IT provider. Read every question carefully, answer for the whole organization, and tell your broker if something changes before the policy starts.
What evidence should you keep?
Keep a dated evidence file that backs up your answers. Common items include:
- MFA registration and enforcement reports, and your sign-in policies
- A list of administrator accounts and when they were last reviewed
- Device inventory and encryption status
- Backup settings and records of restore tests
- Email authentication settings and filtering
- Logging and monitoring settings, and examples of alerts handled
- Written policies: acceptable use, access control, incident response, and your acceptable AI use rules
- Security awareness training completion records
- Your latest risk analysis or framework assessment, with the work plan
- Business associate agreements and vendor contracts, where they apply
- A copy of each questionnaire you submitted, with the date and who signed
How the other guides map to typical questions
| Typical question topic | Where to find the background |
|---|---|
| Do you require MFA? For email, remote access, administrators, backups? | Our MFA and Conditional Access guide |
| Do you follow a recognized framework? | Our NIST CSF 2.0 and CIS Controls IG1 guides |
| Do you handle patient information? Have you done a risk analysis? | Our HIPAA security risk analysis and ePHI in Microsoft 365 guides |
| Do you sign business associate agreements? | Our business associate agreements guide |
| Do you have an incident response plan? How do you notify customers of a breach? | Our Texas breach notification guide |
| Are you working toward CMMC or NIST SP 800-171? | Our CMMC guide for DoD suppliers |
| Do you meet Texas requirements? | Our Texas SB 2610 Cybersecurity Safe Harbor page |
| Do you use AI tools with customer data? What are your AI rules? | Our Microsoft Copilot readiness guide and Acceptable AI Use page |
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. You keep the attestation: you review, sign and submit every questionnaire, and ALCON DTS does not attest for you. What we can do is make sure the technical answers come from the live environment, not from memory.
| Need | What ALCON DTS provides |
|---|---|
| Technical answer drafts | Draft technical answers for your review, based on the settings we can see in the systems we manage, covering MFA, encryption, backups, logging and admin access. You confirm each answer before you sign |
| Evidence | Help gathering the reports, settings and records that support each answer, organized in an evidence file |
| Identity and access | MFA, sign-in rules and least-privilege administrator roles, with joiner, mover and leaver changes kept current |
| Devices, email and backup | Devices kept updated, protected and encrypted; email security and domain authentication; tested backup |
| Monitoring | Alerts routed to a named owner. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control. |
| Training | Security awareness training with completion records |
| Follow-up questions | We sit with you to explain the technical controls we run when a customer, insurer or regulator asks how the work is done |
Questionnaire help is included in Secure IT. The exact controls behind your answers depend on your ALCON DTS plan and any project work. ALCON DTS does not provide legal or insurance advice, does not certify compliance, and does not sign or submit questionnaires on your behalf.
Have a questionnaire or insurance renewal on your desk? Contact us and we will set up a secure way to share it. We will help gather the evidence and draft the technical answers for your review, and flag anything that isn’t true yet.
How do security questionnaires fit with other rules?
- HIPAA. Customers that are covered entities often send questionnaires before signing a business associate agreement. Your answers should match your security risk analysis (45 CFR 164.308(a)(1)(ii)(A)) and your agreement.
- CMMC and NIST SP 800-171. Defense customers may ask about your status. Answer based on your actual assessment results and plan, and see our CMMC guide for DoD suppliers.
- Texas Cybersecurity Safe Harbor (SB 2610). A documented program that conforms to a recognized framework (Bus. and Com. Code Sec. 542.004) also gives you a consistent basis for questionnaire answers. See Texas SB 2610 Cybersecurity Safe Harbor.
- Contracts. Some customers attach your answers to the contract or require you to tell them if something changes. Read those terms with your attorney.
- Insurance. Your application may become part of your policy. Review it with your broker before you sign.
Frequently asked questions
Can we reuse answers from one questionnaire to the next?
What if the honest answer is "no"?
Can ALCON DTS fill out and sign the questionnaire for us?
Which version of the SIG, CAIQ or HECVAT should we use?
What if a question doesn't apply to us?
What if something changes after we submit an insurance application?
Do we need an outside audit to answer a questionnaire?
How often should we update our evidence?
Sources
- SIG Questionnaire and SIG FAQ (Shared Assessments)
- Cloud Controls Matrix and CAIQ v4.1 (Cloud Security Alliance)
- CCM v4.1 Transition Timeline (Cloud Security Alliance)
- Higher Education Community Vendor Assessment Toolkit (EDUCAUSE)
- HECVAT 4: Better than Ever (EDUCAUSE Review)
- 45 CFR 164.308, Administrative safeguards (eCFR)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about security questionnaires, not legal or insurance advice for your situation.
Talk with ALCON DTS about security questionnaires
Have a customer questionnaire or an insurance renewal coming up? We will help pull the evidence together and draft the technical answers for your review, so what you sign matches how your systems run.
Email: info@alcondts.com ยท Phone: 512-892-6900

