Back to blog
Guides

How to Respond to a SIG Questionnaire: A Practical Guide

The SIG CORE is 855 questions. The SIG Lite is still 261. Here's how to approach either one without losing your mind — or your deal.

VerityOps Team·

The Shared Assessments SIG (Standardized Information Gathering) questionnaire is one of the most comprehensive security questionnaires your team will encounter. The SIG CORE has 855 questions. The SIG Lite has 261. Both are extensive. Both are manageable with the right approach.

This guide breaks down how to tackle a SIG questionnaire systematically — whether you're doing it manually or using automation.

Understanding the SIG Structure

The SIG questionnaire is organized into domains, each covering a different area of security and compliance:

  • A: Enterprise Risk Management
  • B: Security Policy
  • C: Organizational Security
  • D: Asset and Info Management
  • E: Human Resources Security
  • F: Physical and Environmental Security
  • G: IT Operations Management
  • H: Access Control
  • I: Application Security
  • J: Cybersecurity Incident Management
  • K: Operational Resilience
  • L: Compliance and Ethics
  • M: Network Management
  • N: Privacy
  • O: Threat and Vulnerability Management
  • P: Server Security
  • Q: End User Device Security
  • R: Network Security
  • S: Application/Services Criticality
  • T: Artificial Intelligence

The SIG Lite is a subset — typically covering A through P, skipping Q, R, S, and T.

The Evidence-First Approach

Before you answer a single question, inventory your evidence. You need:

  1. Your SOC 2 report (Type II preferred) — covers a large portion of the controls-oriented questions
  2. Security policies — information security policy, acceptable use, access control, etc.
  3. Recent penetration test summary
  4. Business continuity/disaster recovery plan
  5. Incident response plan
  6. Vendor/subprocessor list
  7. Data classification policy
  8. Architecture overview

Most SIG questions — especially in domains A through N — map to one of these seven document types.

Domain-by-Domain Strategy

High-volume domains (H, I, M, O, P)

Domains H (Access Control), I (Application Security), M (Network Management), O (Threat and Vulnerability Management), and P (Server Security) have the most questions and the most technical depth.

For H and P, your SOC 2 report and access control policy will cover 70%+ of the questions. Focus your manual effort on the operational questions — "How do you provision/deprovision access?" and "What's your password policy?" — which need specific, current answers.

For I and M, your architecture overview and any security scanning documentation are key evidence.

Policy-heavy domains (B, C, E)

Domains B (Security Policy), C (Organizational Security), and E (Human Resources Security) are primarily answered by your policy documents. If you have an up-to-date information security policy that covers policy review cadence, roles and responsibilities, and security awareness training — these domains go quickly.

The harder domains (K, L, N)

Domain K (Operational Resilience) requires specific answers about your RTO/RPO, backup testing, and BCP exercises. If you haven't formalized these, this is where questionnaires expose gaps.

Domain L (Compliance and Ethics) requires answers about your legal and regulatory compliance program — relevant laws, audit history, and any findings.

Domain N (Privacy) has increased in scope as privacy regulations have expanded. If you handle personal data of EU residents, expect deep GDPR-related questions here.

Common Mistakes to Avoid

1. Inconsistency across questionnaires

If you tell one buyer you conduct annual penetration testing and another you conduct semi-annual testing — and you have evidence for one — you have a problem. Your canonical answers need to be consistent, evidenced, and regularly reviewed.

2. "Yes" without evidence

"Yes, we encrypt data at rest" without citing the specific encryption standard and key management approach creates follow-up questions. Answer completely: "Yes. All data is encrypted at rest using AES-256. Encryption keys are managed via [KMS]."

3. Ignoring the conditional questions

The SIG has many questions that apply conditionally — "If you use cloud infrastructure, answer questions X.1 through X.7." Read the instructions. Missing a conditional section looks like evasion.

4. Copying from last year's questionnaire without updating

Your SOC 2 certification date, penetration test date, and employee count all change. Make sure your answers reflect current state, not last year's state.

Speeding Up the Process

The fastest teams we've seen use a canonical answer library — a set of pre-approved, evidence-linked answers to the questions that appear in every questionnaire. Once your canonical library exists, a SIG Lite goes from 40+ hours of effort to a review-and-refine task.

That's exactly what VerityOps Evidence Vault is designed to enable: build the library once, cite evidence precisely, and let the AI do the mapping work when the next questionnaire arrives.


Want to see how VerityOps handles a real SIG questionnaire? Upload your first questionnaire free →

Ready to automate your security questionnaire workflow?

Join early access →