A vendor security team fills out a SIG Lite for a prospective customer’s procurement process. 128 questions, four hours of a Tuesday afternoon, mostly cutting and pasting from the last one. Access controls: yes. Encryption at rest: yes. Incident response plan: yes, tested annually. The form gets signed, PDF’d, and emailed back. The deal closes.
Fourteen months later that vendor gets breached — not because anything on the SIG Lite was false when they answered it, but because the environment underneath those answers changed and nobody re-asked the questions. The customer who reviewed that questionnaire during procurement has no idea any of this happened, because nothing about how SIG Lite works would tell them. The document did exactly what it was built to do, and what it was built to do stopped being true a long time before anyone found out.
That gap — not the questionnaire itself — is the actual subject of this article.
What SIG Lite actually is
SIG Lite is the short-form version of the Standardized Information Gathering (SIG) questionnaire, published and maintained by Shared Assessments. It’s the most common format enterprise procurement and vendor risk teams send to vendors they’re evaluating, and it’s the format most SMB security teams end up filling out on the receiving end long before they ever send one themselves.
All three are the same underlying question bank at different depths — access control, encryption, incident response, data handling, business continuity, compliance posture. Lite is a screening pass. Core is the depth most vendor risk programs standardize on for Tier-1 and Tier-2 vendors. Detail is reserved for the vendors carrying the most risk, or for regulated buyers (financial services, healthcare) whose examiners expect granular, line-item evidence rather than a checkbox.
Speed. A 627-question SIG Core can take a vendor a week to complete properly; a 128-question SIG Lite takes an afternoon. Buyers on a procurement deadline reach for Lite first and only escalate to Core or Detail if the vendor is handling something sensitive enough to justify the slower cycle.
What a completed SIG Lite actually proves — and what it doesn’t
This is the part that gets glossed over, and it’s the whole reason the questionnaire exists in a slightly uncomfortable middle ground between “useful” and “theater.”
What it proves:
- Someone at the vendor, in writing, attested to these specific controls
- The attestation is dated — you know exactly when it was made
- The vendor was willing to put their name on a standardized, comparable format
- A baseline exists that can be compared against a future SIG if one is sent
What it doesn’t prove:
- That the controls are still true today, or were verified rather than self-reported
- That anything changed in the vendor’s environment since signing
- That the person answering understood the question the way the drafter intended
- Anything at all about a subprocessor the vendor added after the form was signed
Neither column is a knock on SIG Lite specifically — SIG Core and SIG Detail have the exact same structural gap, just with more questions asked before the clock starts. Every static, self-reported questionnaire format shares it. The form measures a moment. It has no mechanism for measuring anything after that moment, because measuring after the moment was never the job it was designed to do.
A vendor risk program that treats “SIG Lite on file” as a closed item — reviewed once at onboarding, filed, forgotten — is measuring the day it was signed and calling it current. The questionnaire didn’t fail. The program treating a point-in-time artifact as an ongoing state did.
Where SIG Lite is genuinely the right tool
None of this is an argument against using SIG Lite. For what it’s built for, it’s the right tool and arguably the correct default:
- Screening a Tier-3 vendor — a utility vendor with no access to customer data doesn’t justify a 627-question SIG Core. Lite is proportionate.
- Fast procurement cycles — when a deal has a deadline and the vendor relationship is lower-risk, Lite’s speed is the point.
- A standardized starting point — because it’s an industry-standard format, both sides know what’s being asked, which beats a custom 90-question spreadsheet built from scratch.
- Being on the receiving end — if an enterprise customer sends your company a SIG Lite, filling it out well and fast closes deals. That’s covered in the questionnaire response side of this in more depth.
The failure mode isn’t choosing SIG Lite. It’s treating a SIG Lite on file — of any depth, Lite through Detail — as equivalent to knowing a vendor’s current posture, indefinitely, with no refresh cadence attached.
Filling it out: template vs. platform
Everything above is about the vendor’s answers going stale. The same structural problem exists on the other side of the desk — when your company is the one filling out a SIG Lite for an enterprise customer, and the honest question is whether your answers are current, not just whether they were true the last time someone typed them.
A free SIG Lite template pulled off the web costs nothing and gives full control over wording — genuinely the right call for a one-off questionnaire from a customer who’ll never send a second one. It stops being the right call the moment a company starts getting these regularly, because a blank template has no memory. Every send starts from zero, which means the answer to “do you enforce MFA” gets worded three different ways across three questionnaires depending on who filled out which one and when — and an enterprise reviewer comparing this quarter’s answers against last year’s SIG on file will notice the drift before they notice the substance.
The standard fix is an answer library — a spreadsheet of standardized responses, reused across questionnaires. It works, and it’s a real improvement: most teams find 70–80% overlap between any two questionnaires once a library exists (covered in more detail in the questionnaire response guide). What it doesn’t solve is who updates the library when a control actually changes. The company rotates identity providers, or finally turns on MFA everywhere, or lets a SOC 2 certification lapse for a quarter — and the answer library keeps saying whatever it said the day someone last touched it, because updating a spreadsheet isn’t anyone’s job description. It goes stale exactly the way a vendor’s SIG Lite goes stale. The mechanism is identical; it’s just running on your side now.
The whole first half of this article is about a vendor’s SIG Lite measuring a moment instead of a state. A manually maintained answer library has the exact same failure mode, just self-inflicted. The fix looks the same too: not a better spreadsheet, but a knowledge base tied to your actual current business context — so when a control changes, the next questionnaire pulls the current answer automatically instead of whatever was true whenever the library was last touched. That’s the model vCISO Lite runs on for questionnaire response: answers generated from live business context, not a document someone has to remember to keep updated.
What closes the gap
Static questionnaires and continuous monitoring aren’t competing approaches to the same problem — they answer two different questions. SIG Lite answers “what did this vendor attest to on this date.” Continuous monitoring answers “is anything observable about this vendor’s posture different right now.” A vendor risk program that only asks the first question has a blind spot exactly as wide as the time between assessments — which, for most SMBs re-sending questionnaires annually, is up to twelve months.
Closing that gap doesn’t require replacing the questionnaire. It requires putting a refresh cadence and a monitoring layer on top of it: a defined re-assessment interval scaled to vendor tier, and outside-in signal (certificate posture, breach disclosure monitoring, domain/email security config) that can flag “something changed” between formal assessments instead of waiting for the next one to roll around on the calendar.
vCISO Lite’s vendor risk module runs the SIG Lite / SIG Core cycle for Tier-1 and Tier-2 vendors on a scheduled cadence rather than a one-time onboarding step, and layers continuous posture monitoring on top of the Tier-1 vendors where the gap matters most. The questionnaire still gets asked — it just stops being the only thing standing between a signed form and eighteen months of silence.
If you're the one who receives it, the job isn't done when it's filed
Everything so far assumes the only thing that can go wrong between assessments is time passing quietly. The harder case is when it doesn’t pass quietly — when a vendor you tiered, assessed, and filed a SIG Lite for has an actual incident six months before its scheduled re-assessment is due.
A refresh cadence doesn’t help here, because a refresh cadence is built to catch drift, not events. If a vendor’s identity provider gets breached on a Tuesday, the fact that their SIG Lite is scheduled for renewal in five months is irrelevant — the question isn’t “is it time to re-ask,” it’s “are we affected, right now, and what do we do about it.” That’s a different discipline than the one this article has been describing. Standing vendor risk management — tiering, SIG cycles, refresh cadence — is the program that runs continuously in the background. Vendor incident response is what takes over the moment a vendor actually breaks, and most companies that have a functioning version of the first have nothing built for the second.
The SIG Lite on file tells you what the vendor attested to on a specific date. It has no mechanism for telling you anything on the date their incident actually happens — that’s not a flaw in the format, it’s outside the job it was built to do. Sending an updated questionnaire mid-incident doesn’t help either: it gets queued behind every other customer’s identical request while the vendor’s legal team is still drafting the disclosure.
What actually answers “are we affected” within the hours it matters is a dependency map of which of your business functions touch that vendor and how, a way to estimate your specific exposure rather than the vendor’s general blast radius, and a decision framework for what to do next — stay, exit, or mitigate — that doesn’t depend on whoever’s most senior person happens to be in the room that day. And because vendors don’t have exactly one incident ever, the mitigations committed after the first incident need to actually get tracked to completion, or the second incident at the same vendor starts from the same blind spot as the first. This is the discipline the Someone Else’s Breach cluster covers in depth — it’s the part of vendor risk that starts exactly where the SIG Lite’s job ends.
vCISO Lite covers both halves of this: the standing SIG Lite / SIG Core cycle described above, and the incident-time discipline — dependency mapping, exposure estimation, and a decision framework with memory across incidents at the same vendor — for when a vendor actually breaks between cycles.
Bottom line
SIG Lite is a good, standard, appropriately fast tool for what it measures: a vendor’s attested posture on a specific date. It was never going to measure anything past that date, and no amount of asking more questions on the form fixes that — SIG Core and SIG Detail have the identical gap, just with a longer form in front of it. The fix isn’t a longer questionnaire. It’s not treating the questionnaire as the whole program.
Sources
- Shared Assessments SIG questionnaire family (SIG Lite 128 questions, SIG Core 627 questions, SIG Detail 1,936 questions): sharedassessments.org/sig
- Cloud Security Alliance CAIQ v4 (Consensus Assessments Initiative Questionnaire): cloudsecurityalliance.org/CAIQ
Where this matters next
Third-Party Risk Management for Growing Companies — the operational program SIG Lite is one input into — tiering, assessment cadence, and what to do with what the questionnaire tells you.
TPRM Software: 2026 Buyer's Guide — where SIG Lite/Core/Detail automation fits across the six platforms buyers actually compare.
The Security Questionnaire Survival Guide — the other side of the desk — building a response system for when your company is the one filling out the SIG.
Vendor Concentration Risk: The Dimension Per-Vendor TPRM Misses — the risk dimension no per-vendor questionnaire — SIG or otherwise — was ever built to see.
Someone Else's Breach: Why Vendor Incident Response Is Its Own Discipline — the discipline that takes over when a vendor you assessed with a SIG Lite actually has an incident — different job than the questionnaire, different cadence.
Mitigation Debt: The Silent Risk That Accumulates Between Vendor Incidents — why the second incident at the same vendor should be easier than the first, and usually isn't.
Platform: Vendor Risk — scheduled SIG Lite/Core cycles plus continuous Tier-1 posture monitoring, so the questionnaire stops being the only signal.
Use Case: Security Questionnaires — respond to SIG Lite, SIG Core, and CAIQ questionnaires sent to you, in a fraction of the time.