Obsidian Ridge

Compliance

The SIG Lite questionnaire: what it is and how to answer it

What the SIG Lite questionnaire is, who sends it, how it differs from SIG Core, and how a small business answers it honestly without a security team.

SMB

Somewhere in your inbox is a spreadsheet or portal invite called a "SIG Lite," sent by your biggest customer's risk team, with a deadline attached to a contract you care about.

This guide covers what it is, why you got it, how it is structured, and how to answer it honestly when nobody at your company has "security" in their job title.

Disclosure: Obsidian Ridge sells a fixed-fee engagement that produces evidence packs for exactly these questionnaires. The method below is complete on its own — you can do all of it without us.

What a SIG Lite actually is

The SIG — Standardized Information Gathering questionnaire — is published by Shared Assessments, a third-party-risk industry body, and updated annually.

It exists so that every enterprise does not have to invent its own vendor security questionnaire, and so vendors can answer one standard instead of four hundred bespoke ones. In practice you will still see bespoke ones, but the SIG is the closest thing vendor risk has to a common language.

It comes in two sizes:

  • SIG Core is the full instrument — several hundred questions, used for vendors whose failure would seriously hurt the customer.
  • SIG Lite is the condensed, program-level version — on the order of 125 to 130 questions in recent releases. Exact counts change every year, so treat the copy you were sent as the authority, not a blog post. Ours included.

Both cover the same territory: roughly twenty risk domains including:

  • Security policy
  • Organizational security
  • Access control
  • Network and endpoint security
  • Application security
  • Cloud hosting
  • IT operations
  • Operational resilience
  • Incident management
  • Threat management
  • Human resources security
  • Privacy

Getting the Lite version is mildly good news. It usually means their risk model classified you as a smaller or lower-risk vendor, and program-level answers will satisfy them.

Why you specifically received one

Three common triggers:

  1. Your service touches their data. You host it, process it, back it up, or can see it.

  2. Your service touches their network or identity. Remote access, an integration, an agent, a shared credential.

  3. Their own obligations flow down. Their regulator, carrier, or enterprise customers require them to assess vendors, so they assess you.

    The FTC Safeguards Rule, HIPAA, and most cyber insurance applications all contain a vendor-oversight requirement — you are downstream of someone else's compliance program. We wrote about the other side of this in vendor and third-party risk for SMBs.

The blunt commercial reality: the questionnaire is a gate. Nobody reads it for pleasure, and a stalled SIG Lite stalls the contract behind it.

How it is structured, and how to read a question

SIG questions are mostly closed-form — yes, no, not applicable — organized by risk domain, with room for comments and evidence. The skill is not in the format; it is in reading what the question is actually asking. Three patterns cover most of the document:

  • "Do you have a documented X?" — policy questions. The honest yes requires a written, dated document someone could produce on request. An undocumented habit is a no with a comment, not a yes.
  • "Is X enforced for all users / all systems?" — scope questions. The word all is doing the work. MFA on email but not on the admin VPN account is not "all." Answer the scope you can prove and state the exception in the comment field.
  • "How often do you X?" — cadence questions. "When we remember" is Never/Not regularly. A calendar entry and a record makes it Annually or Quarterly.

If this sounds familiar, it should: it is the same discipline a cyber insurance questionnaire demands, asked by a customer instead of a carrier.

The controls overlap almost completely — MFA scope, EDR coverage and monitoring, backup immutability and restore testing, incident response, security awareness training. Answer one instrument rigorously and you have answered most of the other.

The method: three columns, then evidence

Take the questionnaire and sort every question into three columns:

  1. True everywhere. You can prove it today. Answer yes and attach the proof.
  2. True in places. Real but partial — MFA on email, not on the firewall admin account. Answer with the accurate scope and a one-line comment naming the gap and, if you have one, the date you intend to close it.
  3. Not really. Answer no. A no with a compensating control ("no SIEM; endpoint and identity events are monitored 24/7 by a managed SOC") reads as a mature answer, not a failure.

Then attach evidence for the yeses that matter most to a reviewer:

  • MFA configuration export from your identity provider, including admin accounts
  • EDR or MDR agent coverage — how many endpoints, and who watches the alerts at 3 a.m.
  • The most recent backup restore-test record: date, system, elapsed time, who ran it
  • The incident response plan, with a revision date inside the last twelve months
  • Training completion and phishing-simulation records

Exports and screenshots beat policy prose. A reviewer can verify an export; a policy document only tells them what you intended.

What not to do

Do not answer aspirationally. SIG answers get attached to contracts, and contracts have representation clauses.

The failure mode is the same one that voids insurance policies — we documented a carrier rescinding a $1M cyber policy over a misrepresented MFA answer on the questionnaire page.

A customer who discovers an aspirational yes during an incident is a former customer with a legal theory.

Do not dump your entire policy binder as a response. Reviewers triage dozens of these. Answer the question asked, attach the specific artifact, move on.

Do not leave the comment fields empty on partial answers. The comment is where a small company wins: it shows you know your own environment, which is the thing the questionnaire is really probing for.

Do not miss the deadline silently. If the answers need three weeks of remediation first, say so. Risk teams extend deadlines for vendors who communicate; they escalate on the ones who go quiet.

If you would rather not do this alone

The three-column sort, the gap-closing, and the evidence pack are exactly what our Cyber Insurance Readiness Sprint produces — it was built for carrier questionnaires, and a customer security questionnaire is the same job with a different reader.

Fixed fee, seven business days, and the evidence pack answers the next questionnaire too, because there will be a next one.

Or answer it yourself with the method above — it is complete. Either way, the deadline on that email is real, and the contract behind it is the point.

Last updated

August 24, 2026. We refresh this content as the threat landscape and tools evolve.

FAQ

Questions readers usually ask next

What is a SIG Lite questionnaire?

SIG Lite is the shortened version of the Standardized Information Gathering (SIG) questionnaire published by Shared Assessments. Larger organizations send it to vendors to assess security posture before or during a business relationship.

It asks program-level questions across roughly twenty risk domains — access control, endpoint security, incident response, resilience, and others — rather than the deep control-by-control detail of the full SIG Core.

Who sends a SIG Lite and why did my business receive one?

A customer's or prospect's third-party risk team sends it, usually because your business will touch their data, their network, or a process they depend on.

Receiving SIG Lite rather than SIG Core generally means they classified you as a lower-risk or smaller vendor. Answering it is usually a condition of winning or keeping the contract.

How is SIG Lite different from SIG Core?

Same publisher, same risk domains, different depth.

SIG Core runs to several hundred questions for high-risk vendor relationships; SIG Lite condenses that to a program-level assessment on the order of 125 to 130 questions in recent releases.

Exact counts change with each annual release, so verify against the version you were actually sent.

Can I answer no to questions on a SIG Lite and still win the deal?

Yes. Risk teams read a small vendor's honest no with a compensating control or a dated remediation plan far more favorably than a yes that falls apart during verification or an incident.

What kills deals is the answer that cannot survive an audit — the same way a misrepresented control can void a cyber insurance policy.

What evidence should be attached to SIG Lite answers?

The same artifacts a cyber insurance underwriter asks for: MFA configuration exports, EDR agent coverage and who monitors it, backup and restore-test records, the dated incident response plan, and training completion records.

Screenshots and exports beat policy prose — reviewers can verify the first and can only trust the second.

Full bio & provenanceSee related service

Related reading