v3ndor.io

Vendor Questionnaire Generator

Free tool

Vendor Questionnaire Generator.

Answer six questions about the vendor and get the questions worth asking them — grouped, with the reason for each one, so you can defend it when they push back.

If they already have a current SOC 2 or ISO 27001, the generator drops the questions that report answers and tells you which ones — re-asking them is how a review turns into a 300-question blast nobody reads.

Runs entirely in your browser — nothing you enter is stored or sent anywhere. A starting point for your own review, not legal advice.

1. How much do you depend on this vendor?
2. What data can they reach?
3. Where does the service run?
4. Do they hold an independent security audit?
5 & 6. Scope

Your questionnaire

17questions

A 17-question set scoped to this vendor's criticality and data access.

5 ask for a document alongside the answer.

Not asked — their SOC 2 or ISO 27001 already answers these

  • Is multi-factor authentication enforced for all staff access to systems holding our data?
  • How quickly is access revoked when someone leaves, and how is that verified?
  • Is our data encrypted in transit and at rest, and who manages the keys?
  • How are code changes reviewed and approved before reaching production?

Ask for the report instead, and check its scope covers the service you are buying.

Governance

  1. Who is accountable for information security in your organisation, and what is their role?

    Establishes there is a named owner. A vendor that cannot answer this rarely has the rest.

  2. Provide your current SOC 2 Type II or ISO 27001 certificate, including the scope and observation period.Evidence

    Scope and period are the part that matters — a report that excludes the service you are buying, or that expired, answers nothing.

  3. List the complementary user entity controls (CUECs) from your SOC 2 report and confirm which ones apply to us.

    CUECs are the controls the report assumes YOU operate. Skipping them is how a buyer assumes a vendor has security covered while silently owning half of it.

Access Control

  1. Which of your staff can access our data in production, and on what basis is that access granted and reviewed?

    Vendor-side access to your data is the exposure you cannot see. Never covered adequately by a certificate alone.

Data Protection

  1. What personal data will you process for us, for what purpose, and for how long will you retain it?

    The Art 30 record you will be asked for in an audit starts with this answer.

  2. In which countries will our data be stored or accessed from, including by support staff?

    Support access from a third country is the transfer most often missed in a residency review.

  3. Will you sign our data processing agreement, and can you meet GDPR Art 28(3) terms including audit rights, breach notification, and return or deletion on exit?Evidence

    As controller you are required to have these terms in place — this is not a nice-to-have.

  4. How do you support data subject access, correction, and erasure requests we receive?

    You carry the statutory deadline; if the vendor cannot act quickly you cannot meet it.

Sub-processors

  1. List every sub-processor that will handle our data, their location, and their function.Evidence

    Your fourth-party exposure is invisible until you ask for the list.

  2. How will you notify us before adding or replacing a sub-processor, and can we object?

    Without a notice-and-object term your approved list quietly stops being accurate.

Incident Response

  1. Within what timeframe will you notify us of a security incident affecting our data, and through which channel?

    Your own regulatory clock starts when the vendor tells you — a vague answer here is a real liability.

  2. Describe a security incident you have handled and what changed as a result.

    Distinguishes a rehearsed process from a document nobody has opened. Hard to fake, easy to answer honestly.

Resilience

  1. What are your recovery time and recovery point objectives for this service, and when did you last test them?

    An untested RTO is an aspiration. The test date is the part worth asking for.

Secure Development

  1. When did you last commission an independent penetration test, and can you share the summary and remediation status?Evidence

    The remediation status matters more than the finding count.

  2. How quickly do you patch critical vulnerabilities, and how do you track known-exploited CVEs?

    Known-exploited is the set that is actually being used against you right now.

Exit

  1. On termination, how and in what format will our data be returned or destroyed, and within what period?

    The cheapest question to ask now and the most expensive to answer later.

  2. Can you provide a certificate of data destruction on request?Evidence

    Turns a contractual promise into evidence you can file.

How the set is chosen

Each question in the bank carries the conditions under which it earns its place — criticality, data access, hosting model, sub-processor use, and GDPR scope. A question that does not apply is not asked, and a question a current SOC 2 or ISO 27001 already answers is moved to the "not asked" list rather than sent. The domains mirror the frameworks a reviewer will recognise: SOC 2 common criteria, ISO 27001 Annex A, and GDPR Art 28 for the processing terms. Model version public-questionnaire-1.0.

This is a starting point sized for a first review, not an exhaustive assessment and not legal advice. Where a regulator or your own policy sets required terms — GDPR Art 28, PCI DSS, DORA — treat those as the floor and have the contract reviewed.

Sending It Is the Easy Part.

The platform sends the questionnaire, chases the answers, scores the responses against the evidence, and tells you when it is time to ask again — so the review is a cycle rather than a spreadsheet.