SecurityWall Logo
Back to Blog
SaaS Security
July 21, 2026
21 min read

How to Pass a Vendor Security Assessment in 2026

HM

Hisham Mir

July 21, 2026

How to Pass a Vendor Security Assessment in 2026
Quick answer

A vendor security assessment is the buyer's risk check on you before they sign. It arrives as a questionnaire of anywhere from 20 to 500 questions, plus requests for evidence: a current penetration test report, a SOC 2 Type II or ISO 27001 certificate, policy documents, and a signed data processing agreement.

You pass by producing current, consistent evidence fast. Most vendors do not fail on control quality. They fail because the pentest report is 18 months old, the SOC 2 is Type I when the buyer needs Type II, or the answers contradict each other across three rounds of follow up.

The fastest single unlock is a current penetration test. It is the one item you can obtain in two to three weeks. SOC 2 Type II needs an observation window measured in months, so a pentest report buys you credibility and time while the rest is built.

What a vendor security assessment actually checks

It is not one thing. It is three, and confusing them is where most teams lose time.

The questionnaire is the visible part: a spreadsheet, a PDF, or a link to a portal. The evidence request is what actually decides the outcome: certificates, reports, policies, and signed agreements. The follow up round is where deals die, when a reviewer finds an answer that contradicts a document you attached.

Most buyers do not invent their questions. They start from a published standard and tailor it.

Questionnaire Standards What Arrives in Your Inbox, and What It Signals
Standard Who Sends It What It Tells You
SIG / SIG LiteFinancial services, insurance, large enterpriseMature programme. Expect evidence requests with every section
CAIQCloud-first buyers, via the CSA STAR registryYes or no format. Publishing a CAIQ pre-empts the whole exercise
HECVATUniversities and higher educationAccessibility and student data sections you will not have prepared
VSATech companies assessing other tech companiesShorter, more technical, less policy theatre
Custom spreadsheetMid-market, or a buyer without a TPRM programmeUnpredictable. Often the slowest to close because nobody owns it

SIG is maintained by Shared Assessments, CAIQ by the Cloud Security Alliance, HECVAT by EDUCAUSE, VSA by the Vendor Security Alliance. Naming the standard back to the buyer in your reply signals you have done this before.

Underneath the format, the evidence list is remarkably consistent: a SOC 2 Type II report or ISO 27001 certificate, a penetration test report dated within the last twelve months, an access control policy, an incident response plan, and a data processing agreement ready to sign.

Basis — Questionnaire standards per Shared Assessments (SIG), Cloud Security Alliance (CAIQ), EDUCAUSE (HECVAT) and the Vendor Security Alliance (VSA).

Why the buyer is asking, and why that changes your answer

Almost every guide treats the questionnaire as an obstacle. It is more useful to see it as the buyer discharging their own compliance obligation. Once you know which obligation is driving a question, you know exactly what evidence closes it.

Reverse Map The Buyer's Obligation, the Question It Produces, the Evidence That Ends It
Their Obligation The Question You Receive What Closes It
SOC 2 CC9.2 (vendor management)"Provide your most recent SOC 2 report or equivalent"SOC 2 Type II, or ISO 27001 plus a current pentest
ISO 27001 A.5.19 to A.5.22 (supplier relationships)"Describe your information security requirements for suppliers"Your own supplier policy and subprocessor list
GDPR Article 28 (processors)"Do you have a DPA and where is data stored?"Pre-signed DPA plus data residency statement
DORA Article 28 (EU financial entities)"Provide ICT third-party due diligence documentation"Pentest evidence, exit plan, subcontractor register
NIS2 supply chain provisions"Describe your vulnerability management and disclosure process"Patch SLA, scan cadence, and a security.txt or VDP page
PCI DSS 12.8 (service providers)"Confirm PCI responsibilities in a written agreement"Responsibility matrix and AOC if you are in cardholder scope

A question you cannot answer is rarely fatal. A question you answer without addressing the obligation behind it usually triggers another round. Say which obligation you believe the question maps to, and answer that.

This reframing has a practical payoff. When a buyer asks something that genuinely does not apply, "not applicable" reads as evasive on its own. Explain the obligation, explain why it does not apply to your architecture, and name the compensating control. Reviewers accept that. They do not accept a blank cell.

Basis — AICPA TSP Section 100 CC9.2; ISO/IEC 27001:2022 Annex A 5.19 to 5.22; GDPR Article 28; Regulation (EU) 2022/2554 (DORA) Article 28; Directive (EU) 2022/2555 (NIS2); PCI DSS v4.0.1 Requirement 12.8.

Deal on the line right now?

If a questionnaire is already sitting in your inbox with a deadline attached, the scoping call is twenty minutes and tells you exactly which items you can clear before the buyer's date and which you cannot.

Book a free scoping call →

The 8 reasons SaaS companies fail vendor assessments

Failure Modes What Actually Sinks the Review, and How Long the Fix Takes
Failure Why It Fails the Review Time to Fix
No pentest report, or one over 12 months oldMost reviewers treat anything older than a year as no evidence at all2 to 3 weeks
SOC 2 Type I when they need Type IIType I describes design at a point in time. Enterprise wants operating effectiveness3 to 12 months
No documented access control policyThe policy is the artifact. Saying you do it is not evidence1 to 2 weeks
Shared credentials in productionBreaks individual accountability. Often an automatic finding2 to 4 weeks
MFA not enforced on admin accountsThe single most checked technical control in any questionnaireDays
No incident response planBuyers need to know how and when you will notify them1 to 2 weeks
PII in application logsContradicts your own data handling answers. Triggers a second round2 to 6 weeks
No DPA ready to signAdds legal review time to a deal that was otherwise ready to close1 to 2 weeks

Seven of the eight are fixable inside a month. The one that is not, SOC 2 Type II, is precisely the one a current pentest report buys you time on.

Notice the pattern. Only two of these are genuinely about security posture. The rest are about documentation and consistency, which is why teams with good engineering hygiene still fail.

Evidence freshness: what expires and when

The most common avoidable rejection is stale evidence. Reviewers check dates before they read content.

Expiry Table How Long Each Artifact Stays Credible
Artifact Accepted Age What Reviewers Do When It Is Older
Penetration test report12 monthsTreated as absent. Expect a request for a current test
SOC 2 Type II report12 months, plus a bridge letterBridge letter requested to cover the gap since period end
ISO 27001 certificateWithin the 3 year cycleSurveillance audit evidence requested
Vulnerability scan3 to 6 monthsCredibility drops sharply past six months
PoliciesReviewed within 12 monthsAn unreviewed policy suggests the programme is dormant
Retest or remediation evidenceSame age as the pentestA report with open criticals and no retest is worse than none

The bridge letter point catches people out. If your SOC 2 period ended four months ago, your auditor can issue a short letter confirming nothing material changed. Buyers ask for it routinely.

How fast can you get assessment ready?

The honest answer depends entirely on where you are starting.

  • You already hold SOC 2 Type II or ISO 27001. You need a current penetration test and a tidy evidence pack. Two to three weeks.
  • You hold nothing but your controls are genuinely decent. Pentest plus policy set plus DPA. Four to six weeks to answer credibly, though a Type II report will still be months away.
  • You are starting from zero. Three to six months is the honest number for full readiness. Anyone promising less is selling you a document generator.

The shortcut that works, and the one nobody in the compliance automation market will tell you, is this: get the penetration test first. It is the only major artifact obtainable in weeks rather than months, it directly answers the most-asked evidence question, and a clean report with retest evidence buys credibility while the longer programme is built. It also surfaces the technical problems early, when fixing them is cheap, rather than during a SOC 2 observation window when the auditor's clock is running.

The 30 day readiness sprint

Four weeks, from questionnaire received to answers returned
Week 1Triage and scopeMap every question to an owner and an artifact. Book the pentest. Enforce MFA on all admin accounts, which is the fastest visible win.
Week 2Documents and testingTesting runs. In parallel, draft the access control policy, incident response plan, and DPA. Kill shared production credentials.
Week 3Remediate and draftFix critical and high findings while the report is finalised. Write answers, checking each one against the document you will attach.
Week 4Retest and returnRetest confirms closure. Assemble one evidence bundle, review for contradictions, return it in a single complete response.

One discipline matters more than any other here: return the questionnaire complete and once. Partial responses invite rounds, and every round adds a week to the deal.

Basis — Timeline reflects a scoped single application or API engagement with retest included. Longer scopes and multi-product environments extend week 2.

What the pentest report must contain for enterprise buyers

Enterprise reviewers are not security engineers. They check for presence, not technique. A report missing any of the following will generate follow up questions even if the testing was excellent.

Report Requirements Six Things a Reviewer Looks For Before Reading a Single Finding
ElementWhy It Is Checked
Scope definitionConfirms the tested systems are the ones being bought
Named methodologyOWASP WSTG, PTES, or NIST SP 800-115. Shows a repeatable process
Tester credentialsOSCP, CREST or CISSP establishes independence and competence
Engagement datesProves the report is inside the 12 month window
Severity ratings with evidenceLets a non-technical reviewer triage without your help
Retest confirmationProves criticals are closed. Most often missing, most often asked for

Many buyers will accept a summary or attestation letter rather than the full technical report. Ask. It is faster to share and avoids exposing detailed findings under NDA negotiation.

More detail on scope and pricing sits in our penetration testing cost FAQ and cost guide. For the compliance side, see ISO 27001 and SOC 2 penetration testing and the SOC 2 compliance page.

Reports written for the reviewer, not just the engineer

SecurityWall delivers scope reconciliation, named methodology, credentialed testers, control mapping and retest evidence in every report, plus a summary letter you can share without an NDA round.

See how we scope engagements →

Answer bank: the 6 hardest questions

These are the questions that most often trigger a second round. Adapt the wording, keep the structure.

Copy, adapt, attach the matching evidence
"Do you hold SOC 2 Type II?" when you do notState the position plainly, give the target date, and offer the substitute: a penetration test dated within the last twelve months with retest evidence, plus your policy set. Never leave it blank and never imply a report exists.
"When was your last penetration test?"Give the exact dates, the scope, the methodology, the testing firm, and whether a retest was performed. A date alone reads as thin.
"Describe your incident response process"Lead with the notification commitment, because that is what the buyer needs for their own obligations. Give the window, the contact route, and attach the plan.
"List all subprocessors"Give the complete list with purpose and data location for each, and link a public subprocessor page. An incomplete list found later is treated as a misrepresentation.
"Do you encrypt data at rest?"Name the algorithm, the key management service, and the rotation policy. "Yes" alone produces a follow up every time.
A question that genuinely does not applyNever write "N/A" alone. State the obligation the question addresses, explain why your architecture puts it out of scope, and name the compensating control.

Frequently asked questions

What do enterprise buyers check in a vendor security assessment? A questionnaire based on SIG, CAIQ, HECVAT, VSA or a custom template, plus evidence: a SOC 2 Type II report or ISO 27001 certificate, a penetration test report under twelve months old, an access control policy, an incident response plan, and a signed DPA.

Do I need SOC 2 to pass a vendor assessment? Not always. Many buyers accept ISO 27001, and some accept a current penetration test plus a documented policy set for lower risk deals. SOC 2 Type II is expected when you process regulated or sensitive customer data at scale.

How quickly can I get a pentest report? Two to three weeks for a scoped single application or API, including retest. It is the fastest major artifact you can add to an evidence pack.

What format do enterprise buyers want the pentest report in? A PDF with scope, methodology, tester credentials, dates, severity-rated findings and retest confirmation. Many will accept a summary or attestation letter instead of the full technical report, which is faster to share.

Is a vulnerability scan the same as a penetration test for vendor assessments? No. A scan finds known CVEs. A penetration test proves exploitability. Reviewers who ask for a penetration test rarely accept scanner output, and submitting one labelled as a pentest is a common cause of a second round.

How much does it cost to get vendor assessment ready? The pentest is the main line item, typically several thousand to low tens of thousands depending on scope. Policy work is usually internal time. SOC 2 Type II is a separate and larger programme cost. Our cost FAQ sets out current market ranges.

Enterprise deal blocked on security review

Clear the gate in two to three weeks

Bring the questionnaire and the buyer's deadline. You leave the call knowing what can be cleared in time, what cannot, and exactly what the evidence pack needs to contain.

Book a free scoping call →
OSCP · CREST · CISSP led testing · Retest included
Deal blocked?
Questionnaire sitting in your inbox?

Twenty minutes and you will know what clears before the buyer's deadline and what does not.

Book a scoping call →

Tags

SaaS SecuritySaaSSOC 2Penetration TestingISO 27001App SecuritySIG LiteCAIQ
HM

About Hisham Mir

Hisham Mir is a cybersecurity professional with 10+ years of hands-on experience and Co-Founder & CTO of SecurityWall. He leads real-world penetration testing and vulnerability research, and is an experienced bug bounty hunter.