Questionnaire standards

The VSA questionnaire, and why it is shorter than the rest

The Vendor Security Alliance questionnaire was written by security teams at companies that buy a lot of software, with a stated goal of asking fewer questions that matter more.

In short

VSA is the deliberately opinionated option: shorter than CAIQ or SIG, focused on the controls its authors consider most predictive of actual risk, and updated as that view changes. It ships in a fuller and a core version. Because it is shorter, individual answers carry more weight — a vague response has nowhere to hide.

VSA at a glance

Published byThe Vendor Security Alliance, a group of companies that assess many vendors
VersionsA fuller questionnaire and a shorter core version for lighter-touch assessments
Typical sizeMarkedly shorter than CAIQ or the full SIG — tens rather than hundreds of questions in the core version
FormatExcel workbook
Who asks for itTechnology companies with in-house security teams running their own vendor reviews
EmphasisFewer questions, less tolerance for non-answers; several items ask for specifics rather than a yes or no

How the file is put together

The file is simpler than its peers, but the same structural traps apply.

An introduction or scope tab usually precedes the questions.
Questions are grouped by topic with a reference column, and several ask for a described process rather than a yes/no.
Response columns expect substance — the format assumes an explanation, not a checkbox.
Some buyers trim or extend the standard file before sending it on.

What Compliance Concierge does with a VSA

The question tab is selected automatically, and you can switch tabs yourself if the file is unusual.
Descriptive controls are handled as questions rather than skipped.
Every draft carries its evidence, which matters more here: with fewer questions, each answer gets read properly.
Where your documents cannot support a specific claim, the answer is held back for a human instead of being generated.
Approved answers are written back into the workbook you were sent.

None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.

Frequently asked

How does VSA compare to CAIQ?+

CAIQ is comprehensive and maps to a full control framework; VSA is selective and asks fewer, harder questions. If you have a completed CAIQ, most of the underlying evidence carries over — but the VSA answers usually need to be more specific than the equivalent CAIQ line.

Can I send my CAIQ instead?+

Sometimes, and it is worth asking. A buyer who accepts a CAIQ or a shared trust page in place of their own form saves you both a round. If they decline, the evidence you gathered for the CAIQ still answers most of the VSA.

Why do short questionnaires take longer per question?+

Because each one is doing more work. "Describe how you segregate customer data" cannot be answered from a control matrix; it needs the actual architecture, and a reviewer will notice if the answer is generic.

What happens to questions our documents do not cover?+

They are marked as needing evidence and left for you. That is deliberate: a confident-sounding answer with nothing behind it is the failure mode that costs a deal when the reviewer asks for the underlying document.

Other assessments we cover: CAIQ v4, SIG & SIG Lite, HECVAT. For the process itself, see the guide to answering security questionnaires.

Answer your VSA with evidence

Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.