TL;DR

The average SaaS vendor fields 37.3 security assessment requests per month—up from 29.5 year-over-year—consuming roughly 179 hours of staff time, essentially a full-time role. Despite that effort, 84% of responses require a follow-up round because the underlying evidence is stale: a SOC 2 report ages out, an ISO scope changes, or a subprocessor is added without updating stored answers. Third-party involvement was tied to 35.5% of 2024 breaches (up 6.5 points from 2023), and the EU’s DORA regulation now mandates formal vendor registers for 22,000 financial entities, raising the stakes even higher. Most questionnaire questions trace to one of four frameworks—SOC 2, ISO 27001, CAIQ, or VSAQ—and mapping answers to the control itself, not a buyer’s specific phrasing, lets a single response survive multiple formats.

The verdict: stop updating against generic templates; instead, inventory the actual questions you received over the last 12 months and link each stored answer to a verifiable, current artifact that won’t expire unnoticed.

Vendor questionnaire content needs to do two things: answer each question with language traceable to a real control or a real audit artifact, and stay current as that underlying evidence expires. Most teams get the first part right once and then let it rot — the SOC 2 report cited in an answer ages out, the ISO scope changes, a subprocessor gets added, and nobody updates the stored text. That gap is what slows deals down, not a lack of templates.

It matters more than it used to. Whistic's 2025 Third-Party Risk Management (TPRM) Impact Report found the average vendor now fields 37.3 assessment requests a month, up from 29.5 the year before, totaling roughly 179 hours of response work monthly — essentially a full-time role — and 84% of responses require a follow-up round before they're accepted (Whistic, 2025 TPRM Impact Report). The volume is rising partly because the underlying risk is real: SecurityScorecard's STRIKE team found 35.5% of breaches analyzed in 2024 involved third-party access, up 6.5 points from 2023 (SecurityScorecard, 2025 Global Third-Party Breach Report). And regulation is adding mandatory rounds on top of the voluntary ones: the EU's Digital Operational Resilience Act (DORA) took effect January 17, 2025, requiring roughly 22,000 financial entities to maintain formal registers of their ICT vendor relationships and subjecting critical providers to direct regulatory oversight (ESMA, Digital Operational Resilience Act). Content that isn't kept current doesn't just look sloppy — it produces the follow-up rounds that are already 84% of the workload.

The frameworks a questionnaire is actually asking about

Direct answer: Most vendor questionnaires aren't inventing new questions. They're translating one or more of a handful of established frameworks into their own wording. Knowing which one is behind a given question tells you what evidence actually answers it.

SOC 2, run under standards from the American Institute of Certified Public Accountants (AICPA), is an independent auditor's attestation report evaluated against the AICPA's Trust Services Criteria (TSC) (AICPA & CIMA, SOC 2). Security is the only mandatory category (Common Criteria CC1–CC9); Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on what the vendor has actually committed to in customer contracts. A Type II report attests that controls operated effectively over an observation period, typically six to twelve months — which means the report is dated the day it's issued, not evergreen.

ISO/IEC 27001:2022 is an international standard for an Information Security Management System (ISMS), not an attestation of a point-in-time control test. Certification is issued by an accredited certification body following a two-stage audit and is checked against Annex A, which lists 93 controls across four categories (people, organizational, technological, physical) (ISO, ISO/IEC 27001:2022). The certificate covers only the scope defined in the organization's Statement of Applicability — a common mistake is assuming a certificate covers the whole company when it may cover one product line or one data center.

CAIQ (Consensus Assessments Initiative Questionnaire), maintained by the Cloud Security Alliance (CSA), is a self-assessment: a set of yes/no questions mapped directly to CSA's Cloud Controls Matrix (CCM). CCM v4 covers 197 control objectives across 17 domains, and CAIQ v4 condenses that into 261 questions (CSA, Cloud Controls Matrix v4). Vendors can submit a completed CAIQ to the CSA STAR Registry for public visibility, but — unlike SOC 2 or ISO 27001 — nothing in CAIQ itself is independently verified by a third party.

VSAQ (Vendor Security Assessment Questionnaire) started as Google's internal tool for assessing hundreds of vendors a year and was open-sourced under Apache 2.0 in 2016 (Google Open Source Blog, Scalable vendor security reviews). It ships four templates — web app security, security/privacy program, physical/data center security, infrastructure — as a client-side questionnaire engine rather than a certification. Security firm Veracode noted at the time that VSAQ asks a lot about a vendor's general practices but only lightly touches the specific software being purchased, which is worth remembering when a buyer treats a completed VSAQ as sufficient due diligence.

FrameworkMaintained byWhat it producesWhat "complete" meansIndependently verified?
SOC 2AICPA (via licensed CPA firms)Type I/II attestation reportReport covers a defined observation period against chosen TSC categoriesYes — by a CPA firm
ISO/IEC 27001International Organization for StandardizationCertification against an ISMSCertificate covers the scope in the Statement of ApplicabilityYes — by an accredited certification body
CAIQ / CCMCloud Security AllianceSelf-assessment mapped to 197 CCM controlsAll applicable CCM domains answeredNo — self-reported (optional STAR Registry listing)
VSAQOriginally Google, now open sourceSelf-assessment questionnaire (4 templates)Vendor completes the applicable template(s)No — self-reported
NIST SP 800-53 Rev 5NISTControl catalog (not a certification)Used as a mapping target, e.g. by AICPA TSC mappingsN/A — reference catalog

AICPA also publishes formal mappings between the TSC and ISO 27001, NIST SP 800-53, and the CSA CCM (AICPA & CIMA, Trust Services Criteria mappings), which is why a single control (say, encryption at rest) can usually answer the same underlying question across three or four different questionnaire formats — if the stored answer is written against the control, not against one buyer's specific phrasing.

Building content that survives more than one questionnaire

  1. Inventory the last 12 months of actual questions received, not a generic template. The recurring core — encryption, access control, subprocessors, breach notification, data residency, retention — is usually 60–80% of any new questionnaire.
  2. Map each recurring question to the control or evidence that answers it, not to a hand-written paragraph in isolation. "We encrypt data at rest with AES-256" is a claim; the SOC 2 control reference or the cloud configuration screenshot behind it is the evidence a reviewer can check.
  3. Assign an owner and a backup per category (security, privacy, infrastructure, product) who can explain the control, not just repeat the stored sentence. Reviewers ask follow-ups; canned text that nobody can defend is what produces the 84% follow-up rate.
  4. Attach an expiration date to every piece of evidence, not just the answer. A SOC 2 Type II report has an observation-period end date; an ISO certificate has a surveillance-audit cycle. The evidence, not the prose, is what goes stale first.
  5. Version every stored answer with a last-reviewed date and reviewer name. Treat more than a couple of stale answers surfacing in a live response as a process failure to fix, not an individual's mistake.
  6. Route new or one-off questions through a single intake queue so the same question never gets two different answers from two different reps in the same quarter.
  7. Re-certify the highest-risk sections — data handling, subprocessor list, breach notification, regional data residency — on a cadence tied to your actual audit and certification calendar, not an arbitrary review date picked at random.

What this content can't do

A completed questionnaire is not a substitute for a real audit. CAIQ and VSAQ are explicitly self-reported — nothing forces the answers to match reality, which is exactly why buyers in regulated industries ask for the underlying SOC 2 report or ISO certificate instead of, or in addition to, a filled-in form. Even where there is independent verification, it has a boundary: a SOC 2 Type II report attests to a past observation window, not to controls as they operate today, and an ISO 27001 certificate covers only the scope stated in the Statement of Applicability — not necessarily the specific product or environment a buyer is evaluating. Content built from either source is only as current as the artifact behind it, and it should be labeled that way rather than presented as a permanent state of fact.

Compliance posture also changes for reasons that have nothing to do with the review cycle: a new subprocessor, a new hosting region, a remediated finding, an expired certificate awaiting renewal. None of that shows up in stored questionnaire content unless something explicitly triggers a review. Teams that treat the content bank as "done" once it's built are the ones re-litigating the same stale answer with every new deal.

Where nqzai fits — and where it doesn't

nqz.ai is not a GRC platform, and it doesn't fill out a CAIQ, hold your SOC 2 report, or make security claims on your behalf — that content has to stay owned by security and legal, reviewed against the actual controls, and never generated wholesale by a marketing tool. Where the same content-freshness problem shows up in nqz.ai's own lane is the non-security half of a questionnaire response: current product-capability language, positioning against specific alternatives, and case-study proof points that sales and RFP teams pull in alongside the compliance answers. That content decays for the same underlying reason — a feature ships, a customer reference goes out of date, a competitive claim stops being true — and nqz.ai's content workspace is built to keep that half current and easy to retrieve so the security team's evidence-backed answers aren't the only accurate section of the response.

FAQ

Is a completed questionnaire the same as passing an audit?

No. SOC 2 and ISO 27001 involve independent verification by a CPA firm or accredited certification body; CAIQ and VSAQ are self-assessments with no built-in independent check. A buyer relying solely on a self-assessment is trusting the vendor's own account of its controls.

How is CAIQ different from a SOC 2 report?

CAIQ is a standardized yes/no self-assessment mapped to the CSA Cloud Controls Matrix, built specifically for cloud services. SOC 2 is an independently audited attestation report against the AICPA's Trust Services Criteria and applies more broadly than cloud infrastructure alone. Some buyers ask for both.

Do we need ISO 27001 and SOC 2, or is one enough?

It depends on the buyer base. SOC 2 is more common with North American buyers; ISO 27001 is more commonly requested by international and enterprise buyers, especially in Europe. AICPA's published mappings between the TSC, ISO 27001, and NIST 800-53 mean a single control set can usually support both, even if the certifications themselves are pursued separately.

How often should questionnaire content actually be reviewed?

Tie review dates to the underlying evidence's own expiration, not a fixed calendar: a SOC 2 Type II observation period, an ISO surveillance-audit date, a subprocessor list change. Reviewing everything quarterly regardless of what changed wastes SME time on sections nothing happened to.

What's the actual risk of reusing an old answer?

Beyond the audit-defensibility issue, it's operational: Whistic's 2025 data shows 84% of vendor assessment responses already require a follow-up round before acceptance. Answers built on expired evidence are a common cause of that follow-up, adding a full review cycle to a deal that's often already time-boxed by the buyer's own close date.

Can AI draft questionnaire answers?

It can accelerate drafting from an approved source of truth, and Whistic reports 69% of vendors expect AI to significantly affect the response process this year. But the underlying evidence and control mapping still need a human owner who can defend the answer under follow-up questioning — AI speeds up assembly, it doesn't replace the review step.