Vendor questionnaires

Answering the pentest questions in a vendor security questionnaire

A customer sent a security questionnaire, you reached the penetration testing section, and the honest answer is either “we haven’t” or a date you would rather not write down. This page covers what reviewers are actually checking and how to answer well.

If a deal is waiting on it, most of our engagements complete the same day, and your first one is free.

The five questions, and how to answer them

SIG, CAIQ and most bespoke enterprise questionnaires converge on the same handful of items.

"When was your last penetration test?"

The trap in this question is the date. An annual test means that for eleven months of the year the honest answer is a number that gets progressively worse. Reviewers notice, and a report older than about six months routinely triggers a follow-up.

A good answer: Give the date, the scope, and who performed it. If testing is continuous, say so and give the most recent run — that answer is materially stronger than any single date.

"Do you perform testing after significant changes?"

Most organisations answer yes and mean it aspirationally. If your testing is a scheduled annual engagement, a change shipped in month three is not tested until month twelve.

A good answer: Describe the actual trigger and cadence. "Tested on every release" is verifiable and much harder to challenge than "as required".

"Can you provide a summary of findings and remediation?"

Reviewers are rarely asking for the full report, which usually cannot be shared anyway. They want evidence that findings are tracked to closure rather than filed.

A good answer: An executive summary with severity counts, remediation status, and retest evidence. Full technical detail stays internal.

"Is testing performed by an independent party?"

Self-assessment by the team that built the system carries little weight. The reviewer is checking for organisational independence.

A good answer: Name the provider and their qualifications. Testing performed by an external platform or firm satisfies this; testing by your own developers generally does not.

"What is your remediation SLA for critical findings?"

This one is answered badly more often than any other, usually with a number nobody measures against.

A good answer: Give a target you can evidence from your own tracking. An honest "critical within 30 days, and here is our record" beats an unbacked "immediately".

Why the date is the whole problem

Every other answer in the section can be written well. The date cannot be written around. An annual engagement means that from month seven onward you are handing a prospective customer a report describing a system you have since changed repeatedly, and a reviewer who is paying attention will ask what has shipped since.

This is the practical case for continuous testing, and it is a commercial one rather than a security one: the most recent run is always days old, so the question stops being awkward.

What to attach as evidence

Executive summary

Dated, with severity counts and scope. Not the full technical report.

Remediation status

What was found, what is fixed, what is accepted and why.

Retest evidence

Confirmation that fixes were verified, not just claimed.

Frequently asked questions

Do I need a penetration test to complete a vendor security questionnaire?

Usually yes, if the questionnaire is a serious one. SIG, CAIQ and most bespoke enterprise questionnaires ask directly when your last penetration test was and what it covered. Leaving it blank or answering "not performed" is one of the fastest routes to a stalled review.

How recent does the test need to be?

There is no universal rule, but reviewers commonly expect testing within the last twelve months, and a report older than about six months often draws a follow-up question. Continuous testing sidesteps the issue: the most recent run is always days old rather than months.

Can I share the full penetration test report with a customer?

Rarely, and you generally should not. A full report is a detailed map of your weaknesses. Share an executive summary with severity counts and remediation status instead; that is what almost every reviewer actually wants.

How fast can I get a test done if a deal is blocked on it?

Most PentestMe engagements complete the same day they are started, and your first pentest is free. That is generally faster than the scoping and booking cycle for a traditional engagement, which is the usual reason a questionnaire stalls.

Which frameworks do the reports map to?

Findings are mapped to PCI DSS, ISO 27001 and SOC 2, and stand as evidence toward POPIA, so the same report answers questionnaire items across several frameworks.

Get a current report today

Run a real, validated pentest on your own target and answer the questionnaire with a date from this week. First pentest free, no credit card.

Start your free pentest