I have sat on both ends of this document. Running LoginRadius meant answering enterprise security questionnaires continuously, several hundred of them, some running past four hundred questions. Running the security and compliance program meant sending them.

The two experiences are so different that the two sides barely recognize they are discussing the same artifact.

Two numbers that frame the whole argument

Verizon put third-party involvement at 48% of breaches in 2026, with supply chain breaches up 60% year over year. That is the strongest available case that reviewing suppliers is worth doing.

Gartner put 67% of B2B buyers as preferring a rep-free evaluation. That is the strongest available case that the review should be answerable from published material rather than from a bespoke document.

Read together they describe the actual opportunity here. The demand for supplier assurance is rising fast and the preferred delivery mechanism is self-service. The questionnaire is the wrong artifact for both trends, and it persists because changing it requires two organizations to move at once.

What a questionnaire actually is

It is a cost transfer with a compliance justification attached.

Sending one costs the buyer close to nothing: a template, an email, and a deadline. Answering one costs the vendor days of a specialist's time, because the questions span security, legal, privacy, and engineering, and because a wrong answer creates contractual exposure.

Because the sender bears no cost, questionnaires only ever grow. Nobody has ever been criticized for adding a question. Every security team that has been through an incident adds the questions that incident would have caught, and the document ratchets.

That is the mechanism. Everything else follows from it.

Why the compliance framing is wrong

The stated purpose is third-party risk discovery. Measured against that purpose, the instrument performs badly.

The answers are self-reported and almost never verified. Very few buyers check a single response against evidence. The questions are generic, so they ask about controls that may be irrelevant to the actual integration while missing the one thing that matters, which is usually what data crosses the boundary and who can reach it. And the response arrives as free text, which means it cannot be compared across vendors without a human reading all of it.

An instrument that is unverified, generic, and uncomparable is not doing risk discovery. It is producing a record that diligence occurred.

What it is actually good at

Three things, all real:

Establishing a contractual record. The answers become representations. If a vendor said they encrypt at rest and they did not, that is now a contract problem rather than a surprise. This is genuine value and it is the strongest argument for the practice.

Filtering on maturity. A vendor who cannot answer a standard questionnaire inside two weeks is telling you something accurate about their operational maturity, regardless of what the answers say.

Applying pressure. The one nobody says out loud. A questionnaire arriving late in a deal cycle is a negotiating instrument. It costs the vendor time they do not have against a quarter-end, and both sides know it.

What the cost actually looks like

Concrete numbers, because the argument for changing anything here depends on the arithmetic and almost nobody runs it.

A four-hundred-question enterprise questionnaire, answered properly, takes a specialist two to four days. Not because any single question is hard, but because roughly forty of them require checking with engineering, a dozen need legal review, and several need a decision nobody has made yet, which is the real time sink. A mid-size questionnaire of a hundred questions takes most of a day once the first one has been done and answers can be reused.

A company doing enterprise deals answers somewhere between fifteen and forty of these a year. At three days each and a loaded specialist cost, that is roughly sixty to a hundred and twenty thousand dollars annually, spent on a document that produces no artifact anyone reuses.

The comparison worth running: a well-built trust page with certifications, subprocessors, data flows, retention, and a completed standard questionnaire is two to three weeks of work up front and perhaps a day a quarter to maintain. If it deflects even half the volume, it pays for itself inside the first year, and everything after that is margin.

That is the whole business case. It does not need a strategic argument.

What the questionnaire cannot tell you

Worth being precise about the ceiling, because organizations keep expanding the instrument in the hope of crossing it.

It cannot tell you whether the controls described are operating. It records assertions on a date. A SOC 2 or ISO 27001 report at least involves a third party testing a sample, which is why buyers who can accept one should stop sending questionnaires alongside it.

It cannot tell you about the vendor's own vendors beyond one hop, and Verizon puts third-party involvement at 48% of breaches with supply chain incidents up 60% year over year. Your exposure runs deeper than the entity you are contracting with, and no question you write reaches past their subprocessor list.

It cannot tell you how the vendor behaves under pressure. Whether they notify you fast, whether the postmortem is honest, whether support answers at 2am during an incident. Those are the properties that determine your actual experience of a breach at a supplier, and none of them are knowable from a form.

The things it genuinely establishes are narrow: a contractual record, a maturity filter, and a starting point for the conversation you should be having instead.

For buyers: send less, aimed better

Cut the standard template to the questions that map to how this vendor actually touches you. If they never receive customer data, the data-handling section is theatre.

Then add the questions that generic templates never include, because they are the ones that predict actual outcomes:

  • What is your process when a customer reports a vulnerability, and what is your median time to fix?
  • Which of your subprocessors can reach our data, and how do we learn when that list changes?
  • What happens to our data in the ninety days after we terminate?
  • Show us your last penetration test's remediation record, not the certificate.

Twenty questions like those tell you more than four hundred generic ones, and they take a serious vendor a day rather than a week, which improves the quality of the answers you get back.

For vendors: publish the answers before they are asked

The economics only improve one way, which is to move the cost from per-deal to once.

Publish a trust page carrying the certifications, the subprocessor list, the data flow description, the retention policy, and a completed standard questionnaire in a common format. The break-even is straightforward arithmetic: if answering costs three specialist days and you receive twenty questionnaires a year, you are spending sixty days annually on a document you could largely publish once and maintain quarterly.

Two things make this work in practice. Publish the exceptions honestly, because a trust page that claims everything gets read as marketing and buys nothing. And keep the completed standard questionnaire genuinely current, because a stale one is worse than none: it gets caught, and being caught on a security document costs more than the time it saved.

The reciprocity nobody applies

One asymmetry worth naming, because it is available to any buyer and almost nobody uses it.

The organizations sending four-hundred-question documents are frequently also vendors, answering someone else's four-hundred-question document. The security team that sends the questionnaire and the team that answers them are often the same team.

That means a security leader has standing to fix this on both sides at once, and the fix is symmetrical: publish your own trust material, then accept other people's. A buyer who says "we will accept your completed standard questionnaire and your trust page in place of ours, and here is ours for when you review us" removes cost from both organizations and loses almost nothing, because the generic questions were producing almost nothing.

The reason it does not happen is that the two activities sit in different parts of most companies. Vendor review lives in third-party risk. Answering questionnaires lives in sales engineering or compliance. Neither has visibility into the other's cost, so nobody makes the connection.

If you own both, you can make that decision in one afternoon. It is one of the very few genuinely free wins in this territory.

What changes the answer

Regulated buyers. Financial services and healthcare buyers frequently cannot accept a published trust page in place of a completed questionnaire, because their own regulator expects a vendor-specific record. Publishing still reduces the work; it does not eliminate it.

Very early companies. Below roughly twenty employees, publishing a trust page before you have the controls to describe is a liability. Answer the questionnaires manually, and build the page as the controls become real.

A deal that is already late. If a four-hundred-question document lands two weeks before quarter end, the answer is not to publish a trust page. It is to ask the buyer which twenty questions block signature and answer those first, in writing, with the rest to follow. Buyers say yes to that more often than vendors expect, because the security reviewer also wants the deal closed.

The twenty questions worth keeping

If you cut a four-hundred-question template down, this is roughly what survives. Offered as a starting point rather than a standard, because the right set depends on how the vendor touches you.

About the specific integration, not the company. What data crosses the boundary, where it lands, who at the vendor can reach it, and what happens to it after termination. Four questions that most templates bury behind three hundred generic ones.

About the vendor's own supply chain. Which subprocessors can reach your data, and how you find out when that list changes. Verizon put third-party involvement at 48% of breaches; your vendor's vendors are inside your exposure whether or not your template acknowledges them.

About demonstrated process rather than stated policy. Median time to remediate a critical finding. The remediation record from the last penetration test, not the certificate. What happened the last time a researcher reported something.

About the things that end deals. Whether they will accept your data processing terms, whether they carry the insurance your contract requires, and whether they can meet your notification window. Ask these first, not last. Discovering an unbridgeable contractual gap in week eight after both sides spent forty hours on a questionnaire is the most avoidable waste in this whole process.

Twenty questions, all of which a serious vendor can answer in a day, and all of which produce information you would actually act on.

What to do Monday

If you are buying: open your standard questionnaire and delete every question you would not act on. Count what remains. Most teams cut more than half and lose nothing, and the response quality improves because the vendor can afford to answer carefully.

If you are selling: count the questionnaires you answered in the last twelve months, multiply by the specialist days each consumed, and compare that number to the cost of building a trust page. The arithmetic usually settles the argument in one line.