vendor-questionnaire
Installation
SKILL.md
Vendor Security Questionnaire
Disclaimer: this skill supports a security assessment of vendors. Contractual and legal review (data-processing agreements, liability clauses, jurisdiction) requires legal. This skill does not replace contract-legal expertise.
When to use
Vendor Security Questionnaires are the standard mechanism organizations use to assess the security posture of their third-party providers. From both sides: you send them (as the buyer) AND receive them (as a provider serving B2B customers). This skill covers both roles.
Triggers on:
- A question like "which questionnaire do we use for this vendor", "fill out this SIG-Lite for customer X", "build CAIQ answers", "what is a reasonable questionnaire for a low-risk SaaS", "evidence reuse across questionnaires".
- A new vendor onboarding (sender side).
- An incoming security questionnaire from a customer (receiver side).
- A handoff from
supply-chain(SBOM side),dora(Art 28-30 third-party risk),nis2(Art 21(4) supply-chain security),policy-drafter(vendor management policy). - Annual re-review of existing vendors.