SIG vs SIG Lite: Which One You Should Be Answering
If a customer sends you a SIG, the first thing to establish is which SIG. The difference is enormous, and vendors routinely answer a longer version than they needed to.
The versions
SIG Core. The full questionnaire, running to thousands of questions across 21 risk domains. Designed for assessing critical vendors handling regulated data at scale. If you are a twenty-person SaaS company and someone sends you SIG Core, it is worth a conversation.
SIG Lite. A few hundred questions, drawn from Core, covering the same domains at lower depth. This is the appropriate instrument for most SaaS vendors and most procurement processes.
SIG Scoped / Custom. Increasingly common: the buyer selects the domains relevant to what you actually do. If you never touch cardholder data, the payment domains come out.
How to have the conversation
If you receive SIG Core and it is disproportionate, ask. The framing that works is not "this is too much work". It is scoping:
"Happy to complete this. Before I do: we're a cloud-only SaaS, we don't process cardholder data and we have no physical datacenters, so a large part of Core won't apply. Would SIG Lite, or a scoped Core covering [domains], give you what you need for this assessment?"
That is a reasonable question and procurement teams field it routinely. The worst outcome is they say no, and you complete Core.
What SIG asks that CAIQ does not
If you have already done a CAIQ, most of SIG will feel familiar. The areas where it goes further:
- Fourth-party risk. Not just your sub-processors, but theirs.
- Human resources. Background check policy, onboarding and offboarding specifics, training cadence.
- Physical and environmental security, in more depth. Often NA for cloud-only vendors, but you have to say so per question.
- Compliance mapping. Which frameworks you map to, and evidence of it.
The reuse point
SIG and CAIQ overlap substantially. "Do you encrypt data at rest?" appears in both, worded differently. So does almost every access control question.
If you answer them independently every time, you are doing the same work repeatedly and risking divergent answers going to different customers. If you keep a maintained set of answers keyed to the underlying question rather than the spreadsheet it came in, a second questionnaire is mostly a review.
That is the difference between security questionnaires being a recurring tax and being a fixed cost you paid once.
FillTrust matches incoming questions against answers you have already approved, whichever questionnaire they arrive in. See how it works.