SaaS Ranking

Buying guide / Review

SaaS security questionnaire: ask for evidence

Use this questionnaire to organise a vendor conversation around evidence. A public transparency score can point you to documents, but it cannot decide whether a service is suitable for your data or workflow. Give each question an owner, request an artefact with a date and record what remains unresolved. The downloadable worksheet leaves the answers and decisions empty for your team.

By SaaS Ranking ยท Reviewed

Download the checklist (CSV)

Describe the purchase before sending questions

Write down the product, edition, deployment region and intended workflow. Identify the information you intend to upload and which users, integrations and administrators will access it. A response about another edition or a different hosting arrangement may be accurate and still irrelevant to your purchase. Send this short scope with the questionnaire so the vendor knows what to answer. Your internal reviewer should decide which questions are mandatory and which are informational before responses arrive.

Ask for a demonstration as well as a statement

For access controls, ask the vendor to show how an administrator enables stronger authentication, removes a user and limits a service account. For logging, ask for a sample showing an access change and an export, including timestamps and actor identity. Request the plan requirements and retention period for the demonstrated capability. Keep the result of the demonstration separate from the vendor statement: one describes what your team observed in a trial, the other what the vendor says applies to the purchased service.

Read the boundary of every document

A certificate name on a page is a starting point for a follow-up, not a conclusion about your service. Request the relevant document through the vendor process and have the reviewer check the named organisation, scope, applicable product and dates. Do the same for processing locations and subprocessor lists: note which service and activity the text describes. On SaaS Ranking, a retained quote and its source tell you what we found. They do not replace the underlying document or establish that a control is operating effectively.

Make an unavailable answer actionable

A document behind a sign-in, an unreachable source and a question the vendor has not answered are different situations. Record the reason, the requested next step, a named owner and a due date. Do not fill a blank response with a negative judgement about the supplier. If a document can only be shared under an agreement, record the request path and let the appropriate reviewer decide how to handle it. Keep sensitive vendor responses in your own review system; the worksheet is downloaded and completed there.

Close the review with a scoped decision

For every mandatory item, record who reviewed the answer and whether the evidence addresses the intended use. A conditional approval needs a condition that can be checked, an owner and a review date. A decision to defer needs the missing evidence stated precisely. Avoid turning the number of yes answers into a new security score: ten easy answers do not resolve one critical question. Revisit the file when the product scope, integration or data handling changes, and retain the original evidence date alongside the later decision.

Your working checklist

The download contains these questions plus blank fields for your answer, evidence URL, review date, owner, due date and decision. Complete it in your own spreadsheet.

  1. Scope

    Which product, edition, region and legal entity does this answer cover?

    Ask for: Service scope and order form.

  2. Authentication

    How can we enforce MFA and manage privileged accounts?

    Ask for: Configuration guide and demonstration.

  3. Account lifecycle

    How do provisioning, deprovisioning and service accounts work?

    Ask for: Lifecycle demonstration.

  4. Audit trail

    Which customer-visible events are logged and for how long?

    Ask for: Sample logs and retention settings.

  5. Vulnerabilities

    How are reported vulnerabilities triaged and customers informed?

    Ask for: Disclosure and remediation process.

  6. Secure development

    What evidence describes the development and update process?

    Ask for: Current development documentation.

  7. Assurance scope

    Which organisation and services do assurance documents cover?

    Ask for: Current scoped report or certificate.

  8. Data handling

    Which processing locations and subprocessors apply to our service?

    Ask for: Dated service-specific documentation.

  9. Recovery

    What recovery process can we test for our records?

    Ask for: Recovery procedure and trial result.

  10. Incidents

    Who contacts us during an incident, through which channel?

    Ask for: Incident communication procedure.

Source and scope

CISA encourages software customers to ask manufacturers about product security, including authentication, vulnerability handling and evidence of secure development. Our worksheet is an editorial starting point, not a certification or a complete security assessment.

CISA: Secure by Demand. Reviewed 2026-10-02.

Put the next step in your file

Read certification evidence and its limits, then keep the source, date and your decision together.

Compare SaaS costs

Continue your review