Vendor Risk Assessment Questionnaire Template (Free Download) — 2026 Guide
Cyberlords Editorial Team

Your vendors have the keys to your kingdom. They process your customer data, host your applications, manage your payroll, and store your backups. If any one of them gets breached, you get breached.
This is not a theoretical risk. The Verizon Data Breach Investigations Report (DBIR) 2025 found that third-party breaches doubled year-over-year, rising from 15% of all breaches to 30%. A separate study by SecurityScorecard found that 71% of organizations experienced at least one material third-party cyber incident in the past year.
A vendor risk assessment questionnaire is your first line of defense. It is a structured set of questions you send to every vendor before they touch your data, and it is repeated on a regular cycle to ensure ongoing compliance.
This guide provides a free, copy-paste questionnaire template with 40+ questions across 8 risk domains, aligned with ISO 27001, SOC 2, NIST SP 800-161, and CISA guidance. Whether you are a 10-person startup or a 500-person company, you can start using this template today.
Quick Summary
- Third-party breaches doubled from 15% to 30% of all breaches (Verizon DBIR 2025).
- 71% of organizations experienced at least one material third-party cyber incident (SecurityScorecard).
- Supply chain breach remediation costs $4.9 million on average — 17× more than a direct attack (IBM 2025).
- This article includes a free 40+ question template covering 8 risk domains.
- The questionnaire aligns with ISO 27001, SOC 2, NIST SP 800-161, and CISA SCRM guidance.
- You should tier vendors by risk level and assess critical vendors at least annually.
Why Vendor Risk Assessment Matters More Than Ever
The Supply Chain Is Now the Attack Surface
| Statistic | Source |
|---|---|
| Third-party breaches rose from 15% to 30% of all breaches (100% YoY increase) | Verizon DBIR 2025 |
| 71% of organizations had at least one material third-party cyber incident | SecurityScorecard 2025 |
| Average cost to remediate a supply chain breach: $4.9 million | IBM 2025 |
| Supply chain breaches cost 17× more than direct attacks to remediate | IBM 2025 |
| Global cost of software supply chain attacks projected at $60 billion in 2025 | Cybersecurity Ventures |
| 75% of organizations already experienced supply chain attacks | BlackBerry Survey 2024 |
| Fewer than 50% of organizations monitor nth-party supply chains | SecurityScorecard 2025 |
| 47% of organizations had a breach involving third-party network access | Ponemon Institute 2025 |
High-profile supply chain attacks — from SolarWinds to MOVEit to the 2024 Snowflake breach — show that attackers increasingly target the weakest link in the chain. And for many organizations, that weakest link is a vendor that passed a one-time security review three years ago and has not been reassessed since.
What Happens Without a Vendor Assessment Program
Without a structured questionnaire and review process, small businesses face three critical blind spots:
- Unknown data access — You may not know which vendors have access to your most sensitive customer data, intellectual property, or financial records.
- No contractual security obligations — Without documented requirements, vendors have no legal obligation to meet your security standards.
- Regulatory exposure — Regulations like GDPR, HIPAA, and PCI DSS hold your organization — not the vendor — responsible for protecting data, even when a vendor is processing it.
How to Use This Questionnaire Template
Step 1: Classify Your Vendors by Risk Tier
Not every vendor needs the same depth of assessment. Classify vendors into three tiers:
| Tier | Criteria | Assessment Depth |
|---|---|---|
| Tier 1 — Critical | Processes sensitive data (PII, PHI, financial), has network access, or is essential to operations | Full questionnaire (40+ questions), annual review, evidence requests (SOC 2, pentest reports) |
| Tier 2 — Moderate | Limited data access, not mission-critical, but interacts with internal systems | Abbreviated questionnaire (15–25 questions), review every 18 months |
| Tier 3 — Low | No access to sensitive data, no network integration, easily replaceable | Basic questionnaire (10–15 questions), review every 24 months |
Step 2: Send Before Onboarding
Send the questionnaire before the vendor signs a contract or gains access to your systems. Embed the requirement into your procurement workflow.
Step 3: Verify With Evidence
Do not accept "Yes" answers at face value. For critical vendors, request supporting evidence:
- SOC 2 Type II report (covering at least 6 months)
- ISO 27001 certificate with scope statement
- Most recent penetration test executive summary
- Business continuity / disaster recovery plan
- Cyber insurance certificate of coverage
Step 4: Score and Track
Assign a risk score to each vendor based on their responses. Track scores over time and flag vendors whose scores deteriorate.
Vendor Risk Assessment Questionnaire Template
The template below contains 40+ questions across 8 risk domains. Copy it into a spreadsheet or document and customize it for your organization.
Domain 1: Company Information and Scope
| # | Question |
|---|---|
| 1.1 | What is the legal name and headquarters location of your organization? |
| 1.2 | What services will you provide to our organization? |
| 1.3 | Will you process, store, or have access to any of our data? If yes, describe the data types (PII, financial, health, etc.). |
| 1.4 | Will you use any subcontractors or fourth-party providers to deliver these services? If yes, list them. |
| 1.5 | What is your annual revenue and number of employees? |
Domain 2: Security Governance and Policies
| # | Question |
|---|---|
| 2.1 | Do you have a formal, documented information security policy? When was it last reviewed? |
| 2.2 | Do you have a dedicated Chief Information Security Officer (CISO) or equivalent role? |
| 2.3 | Is your organization certified under ISO 27001? If yes, provide the certificate scope and expiry date. |
| 2.4 | Have you completed a SOC 2 Type II audit in the past 12 months? If yes, provide the report. |
| 2.5 | Do you conduct regular security risk assessments (at least annually)? |
| 2.6 | Do you have a documented acceptable use policy for employees? |
Domain 3: Data Protection and Privacy
| # | Question |
|---|---|
| 3.1 | How is our data encrypted at rest and in transit? Specify algorithms and key lengths. |
| 3.2 | Where is our data stored geographically? Will it be transferred across borders? |
| 3.3 | Do you have a documented data retention and destruction policy? |
| 3.4 | Can you provide a Data Processing Agreement (DPA) that complies with GDPR / applicable regulations? |
| 3.5 | Do you implement data loss prevention (DLP) controls? |
| 3.6 | How do you ensure logical separation of customer data in multi-tenant environments? |
Domain 4: Access Control and Authentication
| # | Question |
|---|---|
| 4.1 | Do you enforce multi-factor authentication (MFA) for all administrative and remote access? |
| 4.2 | Do you follow the principle of least privilege for access to customer data and systems? |
| 4.3 | How do you manage and review user access rights? How often are access reviews conducted? |
| 4.4 | Do you have a documented process for revoking access when employees leave or change roles? |
| 4.5 | Do you log and monitor all access to customer data and systems? |
Domain 5: Incident Response
| # | Question |
|---|---|
| 5.1 | Do you have a documented incident response plan? When was it last tested? |
| 5.2 | What is your committed notification timeline for security incidents affecting our data? |
| 5.3 | Have you experienced any data breaches or security incidents in the past 24 months? If yes, describe the incident and remediation. |
| 5.4 | Do you carry cyber liability insurance? What are the coverage limits? |
Domain 6: Business Continuity and Disaster Recovery
| # | Question |
|---|---|
| 6.1 | Do you have a documented business continuity plan (BCP) and disaster recovery plan (DRP)? |
| 6.2 | When were the BCP and DRP last tested? Provide results or summary. |
| 6.3 | What is your Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for the services you provide to us? |
| 6.4 | Do you maintain offsite or geographically separated backups? |
Domain 7: Vulnerability Management and Testing
| # | Question |
|---|---|
| 7.1 | Do you conduct regular vulnerability scans? How often? |
| 7.2 | Do you conduct annual penetration testing by an independent third party? Provide the most recent executive summary. |
| 7.3 | What is your average patching timeline for critical vulnerabilities? |
| 7.4 | Do you have a responsible disclosure or bug bounty program? |
Domain 8: Regulatory Compliance
| # | Question |
|---|---|
| 8.1 | Which regulatory frameworks or standards do you comply with? (ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, CMMC, NIST SP 800-161, etc.) |
| 8.2 | Have you been subject to any regulatory enforcement actions, fines, or consent decrees in the past 36 months? |
| 8.3 | Can you provide evidence of compliance (certifications, audit reports, attestation letters)? |
| 8.4 | Do you have a process for tracking and responding to emerging regulatory requirements? |
Vendor Risk Scoring Matrix
After collecting responses, use this scoring framework to assign a risk rating:
| Response Quality | Score | Meaning |
|---|---|---|
| Full compliance with evidence provided | 1 (Low Risk) | Vendor meets or exceeds requirements with documentation |
| Partial compliance, improvement plan in place | 2 (Medium Risk) | Vendor has gaps but is actively working to close them |
| Non-compliant, no evidence or plan | 3 (High Risk) | Vendor introduces significant risk — requires immediate attention |
| Refused to answer or no response | 4 (Critical Risk) | Vendor cannot be assessed — consider alternative vendors |
Overall vendor risk rating: Sum the scores across all domains, divide by the number of questions answered, and classify:
- 1.0 – 1.5: Low risk — proceed with standard monitoring
- 1.6 – 2.0: Medium risk — proceed with enhanced monitoring and remediation tracking
- 2.1 – 3.0: High risk — require remediation plan before onboarding; escalate to management
- 3.1 – 4.0: Critical risk — do not onboard; seek alternative vendors
Common Mistakes in Vendor Risk Assessments
- Assessing only at onboarding — Risk changes over time. Vendors add subcontractors, experience incidents, and let certifications lapse. Annual reassessment is essential.
- Accepting self-attestation without evidence — A vendor checking "Yes" to MFA does not mean MFA is properly implemented. Request SOC 2 reports, penetration test results, and configuration evidence.
- Treating all vendors the same — A Tier 3 office supply vendor does not need the same 80-question assessment as a Tier 1 cloud hosting provider. Use risk tiering to allocate resources.
- Ignoring fourth-party risk — Your vendor's vendor is your risk too. The NIST CSF 2.0 GV.SC function and CISA SCRM guidance both emphasize that supply chain risk extends beyond direct vendors.
- No centralized tracking — If vendor assessments are scattered across inboxes and shared drives with no centralized log, critical gaps will be missed. Use a spreadsheet, GRC tool, or dedicated platform.
- Skipping the legal review — Vendor risk questionnaire answers should inform your contract. Security requirements, breach notification timelines, and data handling obligations should all appear in the agreement.
Frameworks and Standards Referenced
This questionnaire template draws from the following authoritative frameworks:
| Framework | Key Focus Area |
|---|---|
| NIST SP 800-161 Rev 1 | Cybersecurity Supply Chain Risk Management — identifying, assessing, and mitigating risks from third-party products and services |
| NIST CSF 2.0 — GV.SC | Supply Chain Risk Management governance category — embedding cybersecurity criteria into procurement and vendor management |
| ISO 27001:2022 (A.5.19 / A.5.20) | Information security in supplier relationships and addressing security within supplier agreements |
| SOC 2 Trust Services Criteria | Security, Availability, Processing Integrity, Confidentiality, Privacy — evaluating vendor controls |
| CISA ICT SCRM Task Force | Standardized templates and guidance for communicating supply chain risk posture between vendors and customers |
| GDPR Articles 28 & 32 | Controller obligations for data processors, including data processing agreements and appropriate security measures |
Citations and References
- Verizon Data Breach Investigations Report (DBIR) 2025 — Third-party breaches doubled from 15% to 30% of all breaches year-over-year.
- SecurityScorecard 2025 Report — 71% of organizations experienced at least one material third-party cyber incident; fewer than 50% monitor nth-party supply chains.
- IBM Cost of a Data Breach 2025 — Average supply chain breach remediation cost: $4.9 million. Supply chain breaches cost 17× more than direct attacks.
- Cybersecurity Ventures — Global cost of software supply chain attacks projected at $60 billion in 2025.
- BlackBerry Survey 2024 — 75% of organizations had already experienced supply chain attacks.
- Ponemon Institute 2025 — 47% of organizations experienced a breach involving third-party network access in the prior 12 months.
- NIST SP 800-161 Rev 1 — Cybersecurity Supply Chain Risk Management Practices (May 2022, updated Nov 2024).
- CISA ICT SCRM Task Force — Standardized vendor risk communication templates and SMB supply chain guidance.
How Cyberlords Can Help
Building a vendor risk management program from scratch can feel overwhelming, especially for small businesses without a dedicated compliance team.
At Cyberlords, we help organizations:
- Create customized vendor risk questionnaires tailored to your industry and regulatory requirements.
- Conduct third-party security assessments on your behalf, including reviewing SOC 2 and ISO 27001 documentation.
- Build a vendor risk management program that scales with your business, from initial framework design to ongoing monitoring.
- Perform supply chain penetration testing to identify vulnerabilities introduced by vendor integrations.
If you want help vetting your vendors or building a third-party risk program, contact the Cyberlords team today.
Frequently Asked Questions
What is a vendor risk assessment questionnaire?
A vendor risk assessment questionnaire is a structured set of questions used to evaluate a third-party vendor's security posture, compliance status, and operational risk before or during a business relationship. It typically covers areas such as data handling, access controls, incident response, business continuity, and regulatory compliance. The goal is to identify risks before a vendor is given access to your data or systems, and to monitor those risks on an ongoing basis.
How many questions should a vendor risk assessment questionnaire have?
There is no fixed number, and the right length depends on the risk tier of the vendor. For Tier 1 (critical) vendors with access to sensitive data or network integration, a comprehensive questionnaire with 40 to 80 questions is common and appropriate. For Tier 3 (low-risk) vendors with no data access, a shorter 10 to 15 question assessment may suffice. The key principle is proportionality — scale the depth to the risk.
Which compliance frameworks should a vendor risk questionnaire cover?
At a minimum, your questionnaire should address ISO 27001, SOC 2, and NIST SP 800-161. Depending on your industry, you may also need to cover GDPR (if you process EU personal data), HIPAA (healthcare), PCI DSS (payment card data), or CMMC (US defense supply chain). The CISA ICT SCRM Task Force also provides free, standardized templates for supply chain risk communication.
How often should vendor risk assessments be conducted?
High-risk and critical vendors should be assessed annually at a minimum, with continuous monitoring of their security posture between assessments. Medium-risk vendors should be assessed every 12 to 18 months. Low-risk vendors can be assessed every 24 months. Any vendor should be reassessed after a security incident, a significant change in services or scope, or a contract renewal. The NIST CSF 2.0 GV.SC function specifically calls for integrating supply chain risk management into ongoing governance.
What is the difference between SOC 2 Type I and SOC 2 Type II reports?
A SOC 2 Type I report evaluates the design of a vendor's security controls at a single point in time. It answers the question: "Are the controls properly designed?" A SOC 2 Type II report goes further — it evaluates both the design and the operating effectiveness of those controls over a period of time, typically 6 to 12 months. Type II reports provide significantly stronger assurance because they demonstrate that controls are not only designed but are functioning consistently in practice. Always request a Type II report when available.
What should I do if a vendor refuses to complete the questionnaire?
A vendor's refusal to complete a security questionnaire is itself a significant risk signal. You can offer alternatives: accept a recent SOC 2 Type II report, an ISO 27001 certificate with the relevant scope, or a completed SIG (Standardized Information Gathering) questionnaire from Shared Assessments. If the vendor still refuses to provide any security documentation, formally document the risk in your register, implement compensating controls (limit data access, increase monitoring), and seriously consider alternative vendors.
What is nth-party risk and why does it matter?
Nth-party risk refers to the risk introduced by your vendor's own vendors, their subcontractors, and the entire downstream supply chain. A breach at a fourth-party provider — a company you may never have heard of — can cascade through the chain and directly affect your organization. The Verizon DBIR 2025 found that third-party breaches doubled year-over-year, and SecurityScorecard reported that fewer than half of organizations monitor even 50% of their nth-party supply chains. Both NIST CSF 2.0 and CISA SCRM guidance emphasize addressing this risk.
Can a small business conduct vendor risk assessments without a dedicated GRC team?
Yes. Small businesses can start with a standardized questionnaire template like the one in this article, prioritize their top 5 to 10 highest-risk vendors, and use free resources from CISA and NIST to guide the process. As the program matures, consider using a GRC platform (many offer affordable tiers for SMBs) or engaging a cybersecurity firm like Cyberlords to manage assessments at scale. The critical first step is simply having a documented, repeatable process — even a spreadsheet-based one is far better than no program at all.
vendor risk assessment questionnaire template overview
Key decisions, risks, and implementation actions for vendor risk assessment questionnaire template.