Third-party and vendor security questionnaires: from criticality to contract
For purchasing staff, operations coordinators, IT and security staff and managers who choose or renew suppliers that handle the organization's data or connect to its systems. No prerequisite course, though 'Procurement, RFPs and security questionnaires' covers the other side (answering a customer's questionnaire). You'll rate how critical a supplier is, send proportionate questions that ask for evidence, review the answers for gaps and contradictions, turn gaps into decisions and contract requirements, and plan reassessment. It draws on NIST SP 800-161r1 (US), the NCSC's supply chain security principles (UK), CISA's ICT supply chain guidance (US) and the ICO's guidance on processors under UK GDPR. It is not legal advice: contract wording goes through your legal or procurement team, and your organization's risk appetite decides what can be accepted.
- Level
- Intermediate
- Length
- About 110 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Rate a supplier's criticality from the data and access it will have and how much depends on it, and choose a proportionate level of security assessment
- Write vendor security questionnaire questions that ask for evidence and fit the supplier's risk
- Review a completed vendor questionnaire against its evidence and identify gaps, contradictions and unsupported answers
- Choose a response to each gap: accept, require a fix or contract term, or escalate, including incident reporting, sub-contractor and data return terms
- Plan reassessment of a supplier through the relationship, including the changes that should trigger an early review
Course outline
- 1.Rate a supplier's criticality and choose a proportionate level of assessmentLesson · 20 min
- 2.Write vendor security questionnaire questions that ask for evidenceLesson · 20 min
- 3.Review a completed vendor questionnaire against its evidenceLesson · 20 min
- 4.Choose a response to each gap, including contract terms for incidents, sub-contractors and data returnLesson · 18 min
- 5.Plan reassessment of a supplier through the relationshipLesson · 12 min
- 6.Third-party and vendor security questionnaires: from criticality to contract: knowledge checkKnowledge check · 14 questions
- 7.Third-party and vendor security questionnaires: from criticality to contract: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NIST SP 800-161r1-upd1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (May 2022, updated November 2024)
- NCSC: Supply chain security guidance, principles 1-3 (understand the risks)
- NCSC: Supply chain security guidance, principles 4-9 (establish control)
- NCSC: Supply chain security guidance, principle 10 (check your arrangements)
- CISA: ICT Supply Chain Program Basics
- ICO: A guide to data security (what to do when a processor is involved)
- ICO: Personal data breaches: a guide (processors must inform the controller)
- ICO: Information security checklist (written agreements with service providers and processors)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.