Preparation checklist

100 common SaaS security questionnaire questions

Use this bank to prepare owners and evidence before a customer deadline. It is not a universal questionnaire, and a framework reference does not prove your company performs a control.

Governance and assurance

  1. Do you maintain a documented information security program?Evidence: approved program charter or security policy.
  2. Who is accountable for information security?Evidence: responsibility matrix, role description, or governance charter.
  3. How often are security policies reviewed?Evidence: policy review history and approval record.
  4. Do you perform formal security risk assessments?Evidence: current methodology and completed assessment record.
  5. How are identified security risks tracked and treated?Evidence: risk register and treatment workflow.
  6. Do you maintain independent security certifications or attestations?Evidence: current report or certificate with scope and period.
  7. Are security responsibilities included in employee roles?Evidence: role descriptions and policy acknowledgements.
  8. How are security exceptions approved and reviewed?Evidence: exception procedure and sampled approval.
  9. Do executives review security performance?Evidence: governance cadence and meeting record.
  10. How do you communicate material security changes to customers?Evidence: notification procedure and contractual terms.

Identity and access management

  1. Is multifactor authentication required for privileged access?Evidence: access policy and configuration record.
  2. Is multifactor authentication available or required for customer users?Evidence: product documentation and tenant configuration.
  3. How are new workforce accounts approved and provisioned?Evidence: joiner workflow and sampled ticket.
  4. How quickly is access removed after termination?Evidence: offboarding standard and completed records.
  5. How frequently are access rights reviewed?Evidence: review procedure and latest completed review.
  6. Are privileged accounts separated from standard accounts?Evidence: administrative access design and account inventory.
  7. Do you enforce least privilege?Evidence: role model, approval process, and review evidence.
  8. How are service accounts governed?Evidence: inventory, ownership, credential, and rotation controls.
  9. Do you support single sign-on?Evidence: product documentation and supported protocols.
  10. How are authentication and authorization events logged?Evidence: logging standard and example event fields.

Infrastructure and cloud security

  1. Which cloud and hosting providers process customer data?Evidence: architecture and subprocessor register.
  2. In which regions may customer data be stored?Evidence: deployment design and contractual documentation.
  3. How are production environments separated from development?Evidence: architecture and account or network boundaries.
  4. How are cloud configurations reviewed for security?Evidence: configuration standard and review output.
  5. Are infrastructure changes managed through code and review?Evidence: change workflow and repository controls.
  6. How are secrets stored and rotated?Evidence: secrets-management standard and configuration.
  7. How is production administrative access restricted?Evidence: privileged access policy and technical configuration.
  8. How are network boundaries and traffic flows controlled?Evidence: architecture, firewall, or security-group standards.
  9. Do you monitor cloud activity for suspicious behavior?Evidence: logging sources, alert rules, and response ownership.
  10. How are unsupported systems and components retired?Evidence: lifecycle standard and asset records.

Application security and software development

  1. Do you maintain a documented secure development lifecycle?Evidence: engineering security standard.
  2. Are code changes reviewed before production?Evidence: branch protection and pull-request rules.
  3. Do you perform automated code or dependency scanning?Evidence: configured tools, coverage, and triage workflow.
  4. How are open-source dependencies inventoried?Evidence: dependency inventory or software bill of materials process.
  5. How are application vulnerabilities prioritized and remediated?Evidence: severity policy and remediation records.
  6. Do you conduct penetration tests?Evidence: latest test period, scope, and remediation summary.
  7. How are security requirements included in product design?Evidence: design-review or threat-modeling procedure.
  8. How is production deployment access controlled?Evidence: CI/CD permissions and approval gates.
  9. How do you protect against common web application risks?Evidence: engineering standard, testing, and platform controls.
  10. How are emergency changes reviewed after deployment?Evidence: emergency-change procedure and sampled record.

Data protection and cryptography

  1. Is customer data encrypted in transit?Evidence: transport security standard and endpoint configuration.
  2. Is customer data encrypted at rest?Evidence: storage architecture and encryption configuration.
  3. How are encryption keys managed?Evidence: key-management standard, ownership, and rotation controls.
  4. How is customer data logically separated?Evidence: tenancy architecture and authorization design.
  5. Do you classify information by sensitivity?Evidence: classification policy and handling requirements.
  6. How is sensitive data prevented from entering logs?Evidence: logging standard, filtering, and testing.
  7. How is production data controlled in non-production environments?Evidence: environment and test-data policy.
  8. How are data exports authorized and audited?Evidence: product permissions and audit-event documentation.
  9. How is removable media restricted?Evidence: endpoint or media-handling standard.
  10. How is data securely deleted?Evidence: deletion standard, provider capability, and workflow records.

Privacy and data lifecycle

  1. What categories of personal data does the service process?Evidence: data inventory and privacy documentation.
  2. For what purposes is customer data processed?Evidence: service description, DPA, and internal data map.
  3. How long is customer data retained?Evidence: retention schedule and product behavior.
  4. Can customers configure retention periods?Evidence: current product documentation.
  5. How are deletion requests executed and verified?Evidence: request procedure and system workflow.
  6. Which subprocessors may process customer data?Evidence: current subprocessor register.
  7. How are international data transfers governed?Evidence: DPA and transfer mechanism documentation.
  8. How are privacy rights requests handled?Evidence: privacy request procedure and responsibility matrix.
  9. How are privacy impacts assessed for new processing?Evidence: assessment procedure and completed examples.
  10. How are customers notified of subprocessor changes?Evidence: notification process and contractual commitment.

Logging, detection, and incident response

  1. Which security-relevant events are logged?Evidence: logging standard and event catalog.
  2. How long are security logs retained?Evidence: retention configuration and policy.
  3. Who can access and alter security logs?Evidence: access model and integrity controls.
  4. How are alerts triaged and escalated?Evidence: monitoring runbook and ownership schedule.
  5. Do you maintain a documented incident response plan?Evidence: current approved plan.
  6. How often is the incident plan exercised?Evidence: exercise schedule and completed exercise record.
  7. How are incident severity levels defined?Evidence: classification and escalation criteria.
  8. How and when are affected customers notified?Evidence: notification procedure and contractual terms.
  9. How are incident lessons tracked to completion?Evidence: post-incident review and action tracker.
  10. How is forensic evidence preserved?Evidence: incident or evidence-handling procedure.

Resilience, backup, and recovery

  1. Do you maintain business continuity and disaster recovery plans?Evidence: current approved plans and ownership.
  2. What recovery time objective applies to the service?Evidence: approved service objective and scope.
  3. What recovery point objective applies to customer data?Evidence: approved service objective and backup design.
  4. How frequently are backups performed?Evidence: backup policy and production configuration.
  5. Are backups encrypted and access controlled?Evidence: backup architecture and permissions.
  6. Are backups isolated from the primary environment?Evidence: architecture and account boundaries.
  7. How often are restoration tests completed?Evidence: completed restore-test records, not procedure alone.
  8. How often are continuity plans exercised?Evidence: exercise records and tracked findings.
  9. How is service availability monitored?Evidence: monitoring design and operational ownership.
  10. How are customers informed about significant outages?Evidence: status and communication procedures.

People, devices, and physical security

  1. Are background checks performed where legally permitted?Evidence: people policy with geography and role scope.
  2. Do workers sign confidentiality obligations?Evidence: contract template and onboarding checklist.
  3. How often is security awareness training completed?Evidence: training policy and completion records.
  4. Is role-specific security training provided?Evidence: curriculum and assigned populations.
  5. How are company devices configured and managed?Evidence: endpoint standard and management coverage.
  6. Are endpoint encryption and screen-lock controls enforced?Evidence: device-management configuration.
  7. How are lost or stolen devices handled?Evidence: incident procedure and remote-management capability.
  8. How is remote work secured?Evidence: remote-access and endpoint requirements.
  9. Who is responsible for physical security at hosting facilities?Evidence: shared-responsibility and provider assurance documentation.
  10. How are office visitors and physical access controlled?Evidence: facility procedure for applicable locations.

Suppliers, product AI, and emerging risk

  1. How are critical vendors assessed before use?Evidence: vendor-risk procedure and completed assessment.
  2. How are vendor security changes monitored?Evidence: review cadence, alerts, and ownership.
  3. Are security requirements included in vendor agreements?Evidence: contractual standard and review process.
  4. How is vendor access to systems and data controlled?Evidence: access approvals, scope, and review records.
  5. Does the product use AI to process customer data?Evidence: architecture, feature behavior, and current subprocessors.
  6. Is customer data used to train shared AI models?Evidence: provider terms, configuration, and product policy.
  7. How are AI-generated outputs reviewed before external use?Evidence: workflow controls and reviewer responsibility.
  8. How are prompt injection and untrusted content risks addressed?Evidence: threat model, isolation, testing, and output controls.
  9. How is sensitive information prevented from appearing in AI outputs?Evidence: access controls, data boundaries, filters, and testing.
  10. How are AI features and model-provider changes governed?Evidence: change review, inventory, risk assessment, and customer communication.

Turn the bank into preparation work

Choose the questions most likely for your product and customer segment. For each one, record an owner, evidence source, scope, approval status, and review date. Do not pre-write a universal “yes” answer to all 100.

Fictional NimbusCore question: “Are restoration tests performed quarterly?”

Known evidence: A restoration procedure and one test record from the previous year.

Responsible preparation: Store the completed test as evidence of that event, but do not claim quarterly testing without records that establish the frequency.