Skip to main content

How-to

A 30-minute vendor security review using public evidence

The questions to answer before you email sales, in the order that saves the most time: registries first, vendor statements second, questionnaires last. With the numbers on why.

Solomon AmosPublished 30 Aug 2026Updated 18 Sep 202611 min read

A team working through documents at a table
Photo by Annie Spratt on Unsplash

Most vendor security reviews start with a questionnaire and end six weeks later. The public record answers a large share of the questions in half an hour, and it tells you which questions are worth asking at all. This is the order CertReports was built around: registries first, because a third party publishes them with a date; vendor statements second, because they are at least dated; questionnaires last, because they are neither. The numbers below explain why the order matters.

84%
of TPRM programmes use security questionnaires
Secureframe, third-party risk statistics 2026
37.3
assessment requests the average vendor answers each month
Up from 29.5 the year before
30%
of breaches involved a third party in the 2025 DBIR
Verizon, up from about 15 percent

Why questionnaires are slow and public evidence is not

A questionnaire is a conversation. It takes the vendor 10 to 40 hours to answer by hand, two to four weeks to turn around, and up to three quarters of vendors either do not answer or answer late. Meanwhile the FedRAMP Marketplace, the DPF participant list, the Visa registry and the CSA STAR registry publish the status of thousands of vendors every day with no request at all, and trust centres publish the report type, the certificate edition and the DPA. A review that starts with those sources spends its questionnaire budget only on what is genuinely unknown.

Security questionnaires are the most popular method of assessing third-party risk, with 84% of respondents using them.
How much of a standard questionnaire section public evidence can settle before the first email
  • Public-sector fit (FedRAMP)95%Marketplace
  • Transfer basis (DPF, SCCs)90%registry and DPA
  • Card data (PCI DSS)80%Visa and Mastercard lists
  • Subprocessors and AI use70%legal pages, when published
  • Health data (BAA)60%the offer is public; the terms need reading
  • Security programme (SOC 2, ISO)55%type, period, scope are public; the report is not

The percentages are the CertReports working estimate of how much of each questionnaire section can be answered from public, dated sources. They are a planning aid, not a measurement of any vendor.

A laptop with an analytics dashboard
The vendor page on CertReports is the thirty-minute review in one screen: registry rows, vendor statements, legal artefacts, dates and sources. · Photo by Luke Chesser on Unsplash

The 30 minutes

  1. 1

    Minutes 0 to 5: identity and scope

    Confirm the legal entity, the product and the domain. Open the vendor’s CertReports page from search: the header shows the category, the trust centre and the security page if they exist.
  2. 2

    Minutes 5 to 12: registry-verified rows

    FedRAMP, DPF, PCI DSS and CSA STAR rows come from registries the index mirrors nightly. Each is dated and links to the registry record. These need no follow-up beyond scope matching.

  3. 3

    Minutes 12 to 20: vendor-stated rows

    SOC 2 type and period, ISO 27001 edition and scope, HIPAA BAA offer, Cyber Essentials. Each links to the snapshot of the page that stated it. Note the ones older than a year; those become your first questions.

  4. 4

    Minutes 20 to 25: legal artefacts

    DPA with SCCs, subprocessor list, AI policy, security.txt. Missing artefacts are a signal in themselves; a vendor with no public subprocessor list will struggle with your questionnaire.

  5. 5

    Minutes 25 to 30: compare and decide what to ask

    Put the shortlist side by side on Compare and export the table with sources. The empty cells and the stale dates are your questionnaire; everything else is already answered.

The checklist, by framework

FrameworkPublic sourceWhat settles itWhat still needs the vendor
SOC 2Trust centreType, period end, auditor, criteriaThe report itself, under NDA
ISO 27001Trust centre, certification bodyEdition, scope, sites, CB, accreditationLast surveillance date; Statement of Applicability
HIPAALegal pagePublic BAA offer and covered servicesThe signed BAA; configuration duties
GDPRDPF list, DPADPF status and usage end date; SCCs in the DPATransfer impact assessment on request
FedRAMPMarketplaceStatus, class, agency, assessorNothing for status; product mapping for scope
PCI DSSVisa and Mastercard registriesValidation date, services validated, QSAThe AOC; responsibility matrix
CSA STARSTAR registryLevel, date, underlying standardThe CAIQ answers if Level 1

Questions worth asking sales

Situation on CertReportsQuestion to send
SOC 2 period end more than 3 months agoPlease share the current report and a bridge letter dated after the period end.
ISO 27001 row without scopePlease share the certificate with the scope statement and covered sites.
HIPAA vendor-stated onlyPlease send the BAA and confirm the product tier and features it covers.
No public subprocessor listPlease provide the subprocessor list and the notice period for changes.
DPF listed for EU onlyFor UK data, which mechanism applies: the UK extension, IDTA or UK Addendum?
Framework row expiredHas the certificate or listing been renewed? Please share the current evidence.
Signing a document
A questionnaire with fewer, sharper questions gets answered. Failed programmes average 300 questions and 67 percent higher non-completion. · Photo by Scott Graham on Unsplash

Sizing the questionnaire you still need

The research on questionnaire design is consistent: shorter is answered, longer is not. Programmes whose questionnaires cover 12 to 15 core domains keep vendor completion under 20 hours; programmes that average more than 300 questions see 67 percent higher non-completion and lower risk detection. Fifty-seven percent of programmes use a custom questionnaire and 18 percent use an industry standard such as SIG, which is why vendors answering 37 requests a month cannot reuse their work. Pre-filling from public evidence is the cheapest way to cut the count.

What a public review cannot tell you

  • Whether the SOC 2 report contains exceptions on the controls you care about. Only the report says that.
  • Whether the ISO scope covers the specific team and system that handles your data, unless the scope statement is published.
  • Anything about penetration test results, which vendors almost never publish in detail.
  • Whether the vendor’s contract will accept your security addendum.
  • Whether the controls actually operate today, as opposed to during the last audit period.

Doing it for a list

For a vendor inventory rather than a single review, paste the list into the bulk check: twenty vendors free, five hundred on Buyer Pro with CSV export. Each cell is a dated state with a link to its evidence, and the table is the first draft of your third-party register.

Rule of the index

Every state on CertReports carries a date, a source and a snapshot. "No public evidence" is literally true and never means non-compliant; it means nobody published anything the index could capture, and the vendor can fix that in a day.

People also ask

What should a vendor security review include?

Identity and scope, the registry-verified frameworks (FedRAMP, DPF, PCI DSS, CSA STAR), the vendor-stated ones (SOC 2, ISO 27001, HIPAA), the legal artefacts (DPA, subprocessors, security.txt), and a short questionnaire covering only what the public record leaves open.

How long does a vendor security review take?

Thirty minutes on public evidence for the initial pass. A questionnaire adds two to four weeks of vendor turnaround and 10 to 40 hours of vendor effort, so it should be reserved for the gaps.

What is the difference between a vendor risk assessment and a security questionnaire?

The assessment is your judgement of the risk a vendor poses; the questionnaire is one input to it. Registry listings, reports and contracts are other inputs, and the public ones are available before any questionnaire is sent.

Which vendor security questionnaire is standard?

SIG and SIG Lite from Shared Assessments, CAIQ from the Cloud Security Alliance, and HECVAT in higher education. Only about 18 percent of programmes use a standard; most write their own.

Do I need a SOC 2 report for every vendor?

No. Match the evidence to the data. A vendor that never sees customer data needs less than one that stores credentials or health records. A public registry listing may be enough for low-risk tools.

How often should vendor reviews be repeated?

Annually for most vendors, and whenever a state changes. Following a vendor on CertReports sends an alert when a certificate lapses, a listing expires or a report period ages out, which turns the annual review into an exception process.

vendor reviewTPRMquestionnairechecklistthird-party risk
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like