HackproofHacks
Linkable checklist

Vendor Security Review Checklist: What SaaS Buyers Actually Ask

A vendor security review checklist covers seven areas an enterprise buyer's security team checks before approving a SaaS purchase: data handling and encryption, access control, independent security testing, compliance reports, incident response, subprocessors and data residency, and uptime and business continuity. Most reviews stall not because a vendor is insecure, but because nobody has the answers written down and ready to send.

Somewhere between a demo and a signed contract, almost every enterprise SaaS deal hits the same wall: a security questionnaire, sometimes fifty questions long, sometimes a formal review call with someone whose job is to say no. Sales teams often see it for the first time when it lands in their inbox with a two-week deadline attached.

The questions are more predictable than they feel in the moment. Here is the checklist most buyers actually work from, organized so you can prepare answers before the questionnaire arrives instead of scrambling once it does.

The seven things every review checks

  • Data handling and encryption: where customer data lives, whether it's encrypted at rest and in transit, and whether it's ever used to train models or shared with third parties.
  • Access control: who inside your company can reach customer data, whether access is logged, and whether you enforce multi-factor authentication and least-privilege access.
  • Independent security testing: whether you've had a penetration test in the last twelve months, and whether you can produce the report, not just say testing happens.
  • Compliance reports: a SOC 2 Type II report is the single most requested document; ISO 27001 is the common alternative for buyers outside the US.
  • Incident response: whether you have a documented plan, how fast you commit to notifying customers of a breach, and whether you've had a reportable incident before.
  • Subprocessors and data residency: which third-party services touch customer data (hosting, email, analytics), and whether data stays in a specific region if the buyer requires it.
  • Uptime and business continuity: your SLA, backup strategy, and what happens to the buyer's data if your company shuts down or is acquired.

How to actually be ready

The fastest reviews happen when a vendor has a folder, not a scramble: a current SOC 2 report or equivalent, a recent penetration test report, a one-page data-handling summary, and a named security contact who can answer follow-up questions without going quiet for a week.

The single biggest thing that stalls a review is a vendor claiming to test for vulnerabilities without evidence. "We take security seriously" is not an answer a buyer's security team can put in its own audit file. A dated, named penetration test report is.

Where a penetration test report fits

Item three on the checklist, independent security testing, is usually the one vendors are least prepared for, because it cannot be answered with a policy document. A buyer's security team wants to see a report: a named methodology, findings rated by severity, and evidence that anything serious was fixed.

Having that report ready before the first questionnaire arrives, not after, is what turns a two-week security review into a two-day one.

Building your own vendor security file

A simple security file you can send on request covers four documents: your most recent SOC 2 or ISO 27001 report (or a readiness timeline if you don't have one yet), your latest penetration test report, a one-page summary of your data handling and subprocessors, and a named point of contact for follow-up questions.

Keep it current. A penetration test report older than twelve months, or a SOC 2 report that has lapsed, raises more questions than having no report at all, because it signals the program was a one-time project rather than something you maintain.

Frequently asked questions

What is a vendor security review?

A vendor security review is the process an enterprise buyer runs to assess a SaaS vendor's security posture before signing a contract: usually a questionnaire, a document request, or both, handled by the buyer's security or procurement team rather than the person you've been selling to.

What is a security questionnaire template?

A security questionnaire template is the standardized list of questions a buyer's security team sends a vendor during procurement. Common frameworks include SIG (Standardized Information Gathering) and CAIQ (Consensus Assessments Initiative Questionnaire), though many enterprise buyers use their own custom version covering the same core areas.

Do we need SOC 2 to pass a vendor security review?

Not always, but it makes reviews dramatically faster. Without a SOC 2 or ISO 27001 report, expect a longer manual review where you answer every question individually instead of pointing to a single document.

How often should we refresh our penetration test report?

Annually, at minimum, and buyers will ask for the date on the report. A test from two years ago prompts a follow-up question asking for something more recent, a delay you can avoid by testing on a yearly cycle.

What happens if we fail part of the review?

Most reviews are not pass or fail on a single item. A gap, like a missing SOC 2 report or an overdue penetration test, is usually answered with a remediation timeline rather than an automatic rejection, especially if the rest of the file is strong.

Related guides

Related services

Ready to scope your test?

Book a free 30-minute scoping call. We agree the scope, timeline, and a fixed price up front, with no obligation and no surprises for your deadline.