How to Pass a Vendor Security Assessment in 2026
Hisham Mir
July 21, 2026

A vendor security assessment is the buyer's risk check on you before they sign. It arrives as a questionnaire of anywhere from 20 to 500 questions, plus requests for evidence: a current penetration test report, a SOC 2 Type II or ISO 27001 certificate, policy documents, and a signed data processing agreement.
You pass by producing current, consistent evidence fast. Most vendors do not fail on control quality. They fail because the pentest report is 18 months old, the SOC 2 is Type I when the buyer needs Type II, or the answers contradict each other across three rounds of follow up.
The fastest single unlock is a current penetration test. It is the one item you can obtain in two to three weeks. SOC 2 Type II needs an observation window measured in months, so a pentest report buys you credibility and time while the rest is built.
What a vendor security assessment actually checks
It is not one thing. It is three, and confusing them is where most teams lose time.
The questionnaire is the visible part: a spreadsheet, a PDF, or a link to a portal. The evidence request is what actually decides the outcome: certificates, reports, policies, and signed agreements. The follow up round is where deals die, when a reviewer finds an answer that contradicts a document you attached.
Most buyers do not invent their questions. They start from a published standard and tailor it.
| Standard | Who Sends It | What It Tells You |
|---|---|---|
| SIG / SIG Lite | Financial services, insurance, large enterprise | Mature programme. Expect evidence requests with every section |
| CAIQ | Cloud-first buyers, via the CSA STAR registry | Yes or no format. Publishing a CAIQ pre-empts the whole exercise |
| HECVAT | Universities and higher education | Accessibility and student data sections you will not have prepared |
| VSA | Tech companies assessing other tech companies | Shorter, more technical, less policy theatre |
| Custom spreadsheet | Mid-market, or a buyer without a TPRM programme | Unpredictable. Often the slowest to close because nobody owns it |
SIG is maintained by Shared Assessments, CAIQ by the Cloud Security Alliance, HECVAT by EDUCAUSE, VSA by the Vendor Security Alliance. Naming the standard back to the buyer in your reply signals you have done this before.
Underneath the format, the evidence list is remarkably consistent: a SOC 2 Type II report or ISO 27001 certificate, a penetration test report dated within the last twelve months, an access control policy, an incident response plan, and a data processing agreement ready to sign.
Basis — Questionnaire standards per Shared Assessments (SIG), Cloud Security Alliance (CAIQ), EDUCAUSE (HECVAT) and the Vendor Security Alliance (VSA).
Why the buyer is asking, and why that changes your answer
Almost every guide treats the questionnaire as an obstacle. It is more useful to see it as the buyer discharging their own compliance obligation. Once you know which obligation is driving a question, you know exactly what evidence closes it.
| Their Obligation | The Question You Receive | What Closes It |
|---|---|---|
| SOC 2 CC9.2 (vendor management) | "Provide your most recent SOC 2 report or equivalent" | SOC 2 Type II, or ISO 27001 plus a current pentest |
| ISO 27001 A.5.19 to A.5.22 (supplier relationships) | "Describe your information security requirements for suppliers" | Your own supplier policy and subprocessor list |
| GDPR Article 28 (processors) | "Do you have a DPA and where is data stored?" | Pre-signed DPA plus data residency statement |
| DORA Article 28 (EU financial entities) | "Provide ICT third-party due diligence documentation" | Pentest evidence, exit plan, subcontractor register |
| NIS2 supply chain provisions | "Describe your vulnerability management and disclosure process" | Patch SLA, scan cadence, and a security.txt or VDP page |
| PCI DSS 12.8 (service providers) | "Confirm PCI responsibilities in a written agreement" | Responsibility matrix and AOC if you are in cardholder scope |
A question you cannot answer is rarely fatal. A question you answer without addressing the obligation behind it usually triggers another round. Say which obligation you believe the question maps to, and answer that.
This reframing has a practical payoff. When a buyer asks something that genuinely does not apply, "not applicable" reads as evasive on its own. Explain the obligation, explain why it does not apply to your architecture, and name the compensating control. Reviewers accept that. They do not accept a blank cell.
Basis — AICPA TSP Section 100 CC9.2; ISO/IEC 27001:2022 Annex A 5.19 to 5.22; GDPR Article 28; Regulation (EU) 2022/2554 (DORA) Article 28; Directive (EU) 2022/2555 (NIS2); PCI DSS v4.0.1 Requirement 12.8.
If a questionnaire is already sitting in your inbox with a deadline attached, the scoping call is twenty minutes and tells you exactly which items you can clear before the buyer's date and which you cannot.
Book a free scoping call →The 8 reasons SaaS companies fail vendor assessments
| Failure | Why It Fails the Review | Time to Fix |
|---|---|---|
| No pentest report, or one over 12 months old | Most reviewers treat anything older than a year as no evidence at all | 2 to 3 weeks |
| SOC 2 Type I when they need Type II | Type I describes design at a point in time. Enterprise wants operating effectiveness | 3 to 12 months |
| No documented access control policy | The policy is the artifact. Saying you do it is not evidence | 1 to 2 weeks |
| Shared credentials in production | Breaks individual accountability. Often an automatic finding | 2 to 4 weeks |
| MFA not enforced on admin accounts | The single most checked technical control in any questionnaire | Days |
| No incident response plan | Buyers need to know how and when you will notify them | 1 to 2 weeks |
| PII in application logs | Contradicts your own data handling answers. Triggers a second round | 2 to 6 weeks |
| No DPA ready to sign | Adds legal review time to a deal that was otherwise ready to close | 1 to 2 weeks |
Seven of the eight are fixable inside a month. The one that is not, SOC 2 Type II, is precisely the one a current pentest report buys you time on.
Notice the pattern. Only two of these are genuinely about security posture. The rest are about documentation and consistency, which is why teams with good engineering hygiene still fail.
Evidence freshness: what expires and when
The most common avoidable rejection is stale evidence. Reviewers check dates before they read content.
| Artifact | Accepted Age | What Reviewers Do When It Is Older |
|---|---|---|
| Penetration test report | 12 months | Treated as absent. Expect a request for a current test |
| SOC 2 Type II report | 12 months, plus a bridge letter | Bridge letter requested to cover the gap since period end |
| ISO 27001 certificate | Within the 3 year cycle | Surveillance audit evidence requested |
| Vulnerability scan | 3 to 6 months | Credibility drops sharply past six months |
| Policies | Reviewed within 12 months | An unreviewed policy suggests the programme is dormant |
| Retest or remediation evidence | Same age as the pentest | A report with open criticals and no retest is worse than none |
The bridge letter point catches people out. If your SOC 2 period ended four months ago, your auditor can issue a short letter confirming nothing material changed. Buyers ask for it routinely.
How fast can you get assessment ready?
The honest answer depends entirely on where you are starting.
- You already hold SOC 2 Type II or ISO 27001. You need a current penetration test and a tidy evidence pack. Two to three weeks.
- You hold nothing but your controls are genuinely decent. Pentest plus policy set plus DPA. Four to six weeks to answer credibly, though a Type II report will still be months away.
- You are starting from zero. Three to six months is the honest number for full readiness. Anyone promising less is selling you a document generator.
The shortcut that works, and the one nobody in the compliance automation market will tell you, is this: get the penetration test first. It is the only major artifact obtainable in weeks rather than months, it directly answers the most-asked evidence question, and a clean report with retest evidence buys credibility while the longer programme is built. It also surfaces the technical problems early, when fixing them is cheap, rather than during a SOC 2 observation window when the auditor's clock is running.
The 30 day readiness sprint
One discipline matters more than any other here: return the questionnaire complete and once. Partial responses invite rounds, and every round adds a week to the deal.
Basis — Timeline reflects a scoped single application or API engagement with retest included. Longer scopes and multi-product environments extend week 2.
What the pentest report must contain for enterprise buyers
Enterprise reviewers are not security engineers. They check for presence, not technique. A report missing any of the following will generate follow up questions even if the testing was excellent.
| Element | Why It Is Checked |
|---|---|
| Scope definition | Confirms the tested systems are the ones being bought |
| Named methodology | OWASP WSTG, PTES, or NIST SP 800-115. Shows a repeatable process |
| Tester credentials | OSCP, CREST or CISSP establishes independence and competence |
| Engagement dates | Proves the report is inside the 12 month window |
| Severity ratings with evidence | Lets a non-technical reviewer triage without your help |
| Retest confirmation | Proves criticals are closed. Most often missing, most often asked for |
Many buyers will accept a summary or attestation letter rather than the full technical report. Ask. It is faster to share and avoids exposing detailed findings under NDA negotiation.
More detail on scope and pricing sits in our penetration testing cost FAQ and cost guide. For the compliance side, see ISO 27001 and SOC 2 penetration testing and the SOC 2 compliance page.
SecurityWall delivers scope reconciliation, named methodology, credentialed testers, control mapping and retest evidence in every report, plus a summary letter you can share without an NDA round.
See how we scope engagements →Answer bank: the 6 hardest questions
These are the questions that most often trigger a second round. Adapt the wording, keep the structure.
Frequently asked questions
What do enterprise buyers check in a vendor security assessment? A questionnaire based on SIG, CAIQ, HECVAT, VSA or a custom template, plus evidence: a SOC 2 Type II report or ISO 27001 certificate, a penetration test report under twelve months old, an access control policy, an incident response plan, and a signed DPA.
Do I need SOC 2 to pass a vendor assessment? Not always. Many buyers accept ISO 27001, and some accept a current penetration test plus a documented policy set for lower risk deals. SOC 2 Type II is expected when you process regulated or sensitive customer data at scale.
How quickly can I get a pentest report? Two to three weeks for a scoped single application or API, including retest. It is the fastest major artifact you can add to an evidence pack.
What format do enterprise buyers want the pentest report in? A PDF with scope, methodology, tester credentials, dates, severity-rated findings and retest confirmation. Many will accept a summary or attestation letter instead of the full technical report, which is faster to share.
Is a vulnerability scan the same as a penetration test for vendor assessments? No. A scan finds known CVEs. A penetration test proves exploitability. Reviewers who ask for a penetration test rarely accept scanner output, and submitting one labelled as a pentest is a common cause of a second round.
How much does it cost to get vendor assessment ready? The pentest is the main line item, typically several thousand to low tens of thousands depending on scope. Policy work is usually internal time. SOC 2 Type II is a separate and larger programme cost. Our cost FAQ sets out current market ranges.
Clear the gate in two to three weeks
Bring the questionnaire and the buyer's deadline. You leave the call knowing what can be cleared in time, what cannot, and exactly what the evidence pack needs to contain.
Book a free scoping call →
Twenty minutes and you will know what clears before the buyer's deadline and what does not.
Book a scoping call →Tags
About Hisham Mir
Hisham Mir is a cybersecurity professional with 10+ years of hands-on experience and Co-Founder & CTO of SecurityWall. He leads real-world penetration testing and vulnerability research, and is an experienced bug bounty hunter.