We Parsed 146 Real Security Questionnaires. Here Is What They Actually Ask
Most advice about security questionnaires is written from memory. Somebody who has filled a few in writes down what they remember being asked, and the list comes out looking like a control framework: encryption, access control, incident response, in roughly that order.
We had a way to check. To regression-test our parser we keep a corpus of real vendor security questionnaires: files published by universities, public-sector purchasing consortia and companies that put their vendor assessment on the open web. It is 146 files and 17,697 questions, and it is parsed on every change to the parsing code.
The same parse answers a different question for nothing: across questionnaires that were actually sent to real vendors, what do buyers ask about, and how often?
The counts
Questions matching each topic, across all 146 files. One question can match more than one topic, and a few files ask the same thing on several tabs.
| Topic | Questions |
|---|---|
| Incident response | 465 |
| Business continuity and disaster recovery | 387 |
| Backup and restore | 313 |
| HIPAA and Business Associate Agreements | 264 |
| SSO and SAML | 197 |
| Physical security | 178 |
| Subprocessors | 176 |
| Security awareness training | 164 |
| Risk assessment | 162 |
| Vulnerability management | 146 |
| Change management | 145 |
| Multi-factor authentication | 137 |
| Offboarding and access revocation | 135 |
| Penetration testing | 131 |
| Software supply chain and SBOM | 127 |
| GDPR and data processing agreements | 108 |
| PCI DSS | 107 |
| AI and customer data | 103 |
| Encryption at rest | 99 |
| SOC 2 | 90 |
| Key management | 90 |
| Privacy notices | 87 |
| Logging and monitoring | 84 |
| Encryption in transit | 81 |
| Secure development | 79 |
| Breach notification | 75 |
| ISO 27001 | 69 |
| Uptime and SLA | 65 |
| Vendor risk management | 65 |
| Data retention and deletion | 64 |
| Background checks | 63 |
| Least privilege | 59 |
| Accessibility (VPAT, WCAG, Section 508) | 56 |
| Endpoint protection | 56 |
| Data classification | 51 |
Four things worth noticing
Resilience beats cryptography, by a lot. Incident response, business continuity and backups together account for more than a thousand questions. Encryption at rest and in transit, the two topics that dominate how people talk about this work, account for 180 between them. Buyers are much more interested in what happens when something breaks than in which cipher you chose.
Accessibility is asked more often than SOC 2 certification is named. VPAT, WCAG and Section 508 appear in 56 questions. This surprised us enough that we went and read them, and the explanation is structural: in higher education and government, one procurement office sends one file, so accessibility obligations ride along inside the security questionnaire. If you sell to universities you will be asked for an accessibility conformance report, probably in a document with "security" in its title, and no security policy you own can answer it.
HIPAA is the fourth most common topic and is almost never asked as "are you HIPAA compliant". It arrives as two narrower questions: does your product touch protected health information, and will you sign a Business Associate Agreement. Both are contract questions. Neither is answered by having good security.
The regulatory questions are not security questions. HIPAA, PCI DSS, GDPR and accessibility together account for over 500 questions, and every one of them is answered from a contract, an attestation or a scope decision rather than from a security control. For PCI in particular, most SaaS companies answering it have no cardholder data at all, and their strongest answer is not "yes" or "no" but "our scope is nil, and here is why".
How this was counted, and what it is not
The corpus is 146 files, gathered from organisations that publish their vendor questionnaires openly. We do not redistribute them: they are other organisations' documents, and the counts here are derived statistics, not copies.
Matching is by keyword, not comprehension, and the patterns are deliberately tight. The pattern is pci[ -]?dss rather than pci, which also matches unrelated words. That makes these counts a lower bound. Around a quarter of all 17,697 questions match one of the topics above; the rest are either bespoke to one buyer or phrased generically enough ("are policies documented and reviewed?") that no keyword catches them without catching everything else.
So read the table as evidence that a topic is live and roughly how live, not as a precise measurement. The ordering is robust. The exact numbers are not.
It is also one corpus. It skews towards organisations that publish their questionnaires, which means more higher education and public sector than a random sample of enterprise buyers would contain. That is very likely why accessibility ranks where it does. If your customers are all private-sector SaaS companies, expect a different shape.
Why we bothered
We sell a tool that answers these questionnaires from a company's own documents, and refuses to answer what those documents do not support. Deciding which questions to write guidance for was, until we did this, a matter of somebody's judgement about what gets asked a lot.
That judgement had a hole in it. We had pages on multi-factor authentication, penetration testing and SOC 2, and nothing at all on HIPAA, which is asked more often than any of them. We have written those pages since. The full set is at /questions, one page per question: what it is really asking, which document answers it, and the ways it usually goes wrong.