vendor-questionnaire

Installation
SKILL.md

Vendor Security Questionnaire

Disclaimer: this skill supports a security assessment of vendors. Contractual and legal review (data-processing agreements, liability clauses, jurisdiction) requires legal. This skill does not replace contract-legal expertise.

When to use

Vendor Security Questionnaires are the standard mechanism organizations use to assess the security posture of their third-party providers. From both sides: you send them (as the buyer) AND receive them (as a provider serving B2B customers). This skill covers both roles.

Triggers on:

  • A question like "which questionnaire do we use for this vendor", "fill out this SIG-Lite for customer X", "build CAIQ answers", "what is a reasonable questionnaire for a low-risk SaaS", "evidence reuse across questionnaires".
  • A new vendor onboarding (sender side).
  • An incoming security questionnaire from a customer (receiver side).
  • A handoff from supply-chain (SBOM side), dora (Art 28-30 third-party risk), nis2 (Art 21(4) supply-chain security), policy-drafter (vendor management policy).
  • Annual re-review of existing vendors.

When NOT (handoff)

Installs
2
GitHub Stars
4
First Seen
May 18, 2026
vendor-questionnaire — roodlicht/accans-sec-skills