Skip to content

Third-party and vendor security questionnaires: from criticality to contract

For purchasing staff, operations coordinators, IT and security staff and managers who choose or renew suppliers that handle the organization's data or connect to its systems. No prerequisite course, though 'Procurement, RFPs and security questionnaires' covers the other side (answering a customer's questionnaire). You'll rate how critical a supplier is, send proportionate questions that ask for evidence, review the answers for gaps and contradictions, turn gaps into decisions and contract requirements, and plan reassessment. It draws on NIST SP 800-161r1 (US), the NCSC's supply chain security principles (UK), CISA's ICT supply chain guidance (US) and the ICO's guidance on processors under UK GDPR. It is not legal advice: contract wording goes through your legal or procurement team, and your organization's risk appetite decides what can be accepted.

Level
Intermediate
Length
About 110 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Rate a supplier's criticality from the data and access it will have and how much depends on it, and choose a proportionate level of security assessment
  • Write vendor security questionnaire questions that ask for evidence and fit the supplier's risk
  • Review a completed vendor questionnaire against its evidence and identify gaps, contradictions and unsupported answers
  • Choose a response to each gap: accept, require a fix or contract term, or escalate, including incident reporting, sub-contractor and data return terms
  • Plan reassessment of a supplier through the relationship, including the changes that should trigger an early review

Course outline

  1. 1.Rate a supplier's criticality and choose a proportionate level of assessmentLesson · 20 min
  2. 2.Write vendor security questionnaire questions that ask for evidenceLesson · 20 min
  3. 3.Review a completed vendor questionnaire against its evidenceLesson · 20 min
  4. 4.Choose a response to each gap, including contract terms for incidents, sub-contractors and data returnLesson · 18 min
  5. 5.Plan reassessment of a supplier through the relationshipLesson · 12 min
  6. 6.Third-party and vendor security questionnaires: from criticality to contract: knowledge checkKnowledge check · 14 questions
  7. 7.Third-party and vendor security questionnaires: from criticality to contract: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.