{{TOP_BAR}}
{{ORG_NAME}}{{ORG_NAME}}
Vendor Security Questionnaire
Version {{VERSION}} {{FRAMEWORKS}} 22 Sections · 89 Questions
0 of 89 answered
Navigation
  • —Vendor Info
  • 01Data Governance
  • 02Data Location
  • 03People & Access
  • 04Devices & Endpoints
  • 05Network Security
  • 06DNS & DDoS
  • 07Vulnerability Mgmt
  • 08Application Security
  • 09Monitoring & SOC
  • 10Your Vendor Risk
  • 11Incident Response
  • 12Business Continuity
  • 13Assessments & Audits
  • 14Compliance & Certs
  • 15Governance
  • 16Authentication
  • 17Access Control
  • 18Training
  • 19Prior Incidents
  • 20Insurance
  • 21AI Governance
  • 22Change Notification
  • —Attestation
Answered 0 / 89

Completion Instructions

Complete all fields in the Vendor Information section below.

For each question, select Yes, No, or N/A.

Use the Evidence / Comments field to support your response — especially where explanation or documentation is requested.

Attach supporting documentation where referenced (data protection agreement, SOC 2, pen test report, BCP attestation, etc.).

Questions marked PII relate specifically to Personally Identifiable Information, including Nonpublic Personal Information (NPI) under GLBA. Vendors handling {{ORG_SHORT}} PII must have an executed data protection or confidentiality agreement on file prior to engagement.

An authorized representative must complete and submit the Attestation at the end. Return to your designated {{ORG_SHORT}} {{CONTACT_TEAM}} contact securely.

Vendor Information

Required

1. Data Governance & Privacy PII

Q1–5
#  QuestionResponseEvidence / Comments

2. Data Location & Storage PII

Q6–9
#  QuestionResponseEvidence / Comments

3. People & Access Controls

Q10–14
#  QuestionResponseEvidence / Comments

4. Devices & Endpoint Security

Q15–19
#  QuestionResponseEvidence / Comments

5. Network Security

Q20–25
#  QuestionResponseEvidence / Comments

6. DNS & DDoS Protections

Q26–27
#  QuestionResponseEvidence / Comments

7. Vulnerability Management

Q28–32
#  QuestionResponseEvidence / Comments

8. Application Security

Q33–36
#  QuestionResponseEvidence / Comments

9. Monitoring & SOC

Q37–40
#  QuestionResponseEvidence / Comments

10. Your Vendor Risk (TPRM)

Q41–44
#  QuestionResponseEvidence / Comments

11. Incident Response PII

Q45–49
#  QuestionResponseEvidence / Comments

12. Business Continuity & DR

Q50–54
#  QuestionResponseEvidence / Comments

13. Assessments & Audits

Q55–58
#  QuestionResponseEvidence / Comments

14. Compliance & Certifications PII

Q59–61
#  QuestionResponseEvidence / Comments

15. Governance & Program Maturity

Q62–65
#  QuestionResponseEvidence / Comments

16. Authentication & Privileged Access

Q66–68
#  QuestionResponseEvidence / Comments

17. Access Control

Q69–71
#  QuestionResponseEvidence / Comments

18. Security Awareness & Training PII

Q72–74
#  QuestionResponseEvidence / Comments

19. Prior Security Incidents PII

Q75–77
#  QuestionResponseEvidence / Comments

20. Insurance

Q78–79
#  QuestionResponseEvidence / Comments

21. Artificial Intelligence (AI) Governance PII

Q80–86
#  QuestionResponseEvidence / Comments

22. Material Change Notification PII

Q87–89
#  QuestionResponseEvidence / Comments

Vendor Attestation & Signature

By signing below, the authorized representative of the vendor organization attests that the information provided in this questionnaire is accurate and complete to the best of their knowledge, that the vendor organization will promptly notify {{ORG_NAME}} of any material changes to the information provided, and that the vendor understands its obligations under any executed data protection, confidentiality, or service agreement with {{ORG_NAME}}.
  • The information provided in this questionnaire is true, accurate, and complete to the best of my knowledge.
  • I am authorized to provide this information on behalf of my organization.
  • My organization will notify {{ORG_NAME}} within 24 hours of any confirmed or suspected incident affecting {{ORG_SHORT}} customer data, PII, or {{ORG_SHORT}} systems.
  • My organization acknowledges its obligations under any executed data protection, confidentiality, or service agreement with {{ORG_NAME}}.
  • My organization will notify {{ORG_NAME}} of material changes to this questionnaire's responses within 30 days of such change.
{{ORG_NAME}} — Third-Party Risk Management Program
Return completed form securely to your designated {{ORG_SHORT}} {{CONTACT_TEAM}} contact. Version {{VERSION}}. Questions: {{CONTACT_EMAIL}}
✓
{{ORG_NAME}} TPRM
Third-Party Risk Management Program

Questionnaire Submitted

Thank you — your Vendor Security Questionnaire has been received by {{ORG_NAME}} {{CONTACT_TEAM}}. A member of our TPRM team will review your responses and contact you within {{REVIEW_DAYS}} business days. If a data protection agreement is required, our Privacy Officer will reach out separately.

Submission Summary
Vendor
—
Submitted
—
Representative
—
Questions Answered
—
0

Cybersecurity. Technology. Resilience. One Partner.

(800) 881-5694

Copyright © 2026 Reactforce, LLC - All Rights Reserved

Privacy Policy