Practice

Security questionnaires or security ratings: what each one can actually see

Not a replacement decision. A row-by-row account of which instrument can answer which question about a vendor, what only a questionnaire can tell you, and what no questionnaire ever will.

In short
Security questionnaires and security ratings answer different questions and neither replaces the other. A rating observes internet-facing evidence continuously and independently, but sees nothing behind the perimeter. A questionnaire reaches inside to encryption, access control, staff vetting and recovery testing, but describes a single date and depends on the vendor answering honestly.

This question is usually posed as a replacement decision, and answered as one by whichever vendor is in the room. It is not a replacement decision. The two instruments look at different things from different positions, and the programmes that go wrong are the ones using one of them to answer the other's questions.

This page is written by a company that sells continuous monitoring. The useful thing it can offer is therefore the honest boundary — the list of things a questionnaire tells you that no rating ever will.

Outside-in and inside-out

A security rating is calculated from what an attacker could also see: internet-facing systems, their configuration, and observable evidence of compromise. Nothing is installed, nobody is asked, and the subject need not cooperate or even know. That is what makes it independent, and it is exactly what limits it — the rating has no view whatsoever of anything behind the perimeter.

A questionnaire is the opposite instrument. It reaches inside — policies, access management, staff vetting, encryption of data at rest, recovery testing, sub-processor arrangements — and reaches them in the only way available to an outsider, which is by asking. The answers are as good as the answering organisation is honest and well-informed about itself.

What each one can actually tell you

What you need to knowQuestionnaireContinuous ratingAudit or certification
Is their TLS configuration current, and their certificates valid?ClaimedObservedObserved once
Are machines on their network communicating with known-malicious infrastructure?NoObservedNo
What has changed in the last six weeks?NoObservedNo
Is personal data encrypted at rest?Only sourceInvisibleEvidenced
Who holds privileged access, and how is it reviewed?Only sourceInvisibleEvidenced
Has recovery actually been tested, and did it work?ClaimedInvisibleEvidenced
How is their staff vetted and trained?Only sourceInvisibleEvidenced
Which sub-processors do they use, and where?Claimed, usually partialPartly mappedListed
What have they contractually committed to?The record itselfNoNo
The same question, across four hundred vendorsIn principleYesNo
Which instrument can answer which question. 'Only source' means the vendor is the only party who can tell you, which is a description of the evidence and not a criticism of it.

Read down the middle column and the shape of the argument is clear enough: a rating is excellent on the top three rows and useless on the next four. Anyone presenting it as a general answer to vendor risk is selling past the evidence.

What only a questionnaire can do

Reach inside the perimeter

Encryption at rest, privileged access review, joiner-mover-leaver process, background checks, tested recovery. These are real controls, they are what a breach usually turns on, and there is no external signal for any of them. A vendor is the only available source, and a poor source is better than none.

Create a contractual record

A completed questionnaire is a statement made by the vendor, on a date, that can be referred to later. That has value independent of its accuracy: it establishes what was represented at the point of contracting, which is the ground on which a subsequent dispute is actually argued. An observed rating establishes nothing about what anyone promised.

Satisfy an obligation that names it

Some obligations require the assessment itself rather than the assurance behind it. Where a regulator, a customer contract or a certification scheme requires that suppliers be assessed and the assessment retained, a rating dashboard does not discharge it however good the data is.

What only continuous measurement can do

Produce evidence rather than assertion

An expired certificate is observed. An exposed database is observed. Machines beaconing to a command-and-control host are observed. None of these depends on the vendor's candour, self-knowledge or willingness to reply, and all three are the kind of finding a questionnaire is structurally unable to surface.

Detect change

A questionnaire describes a date. The useful signal in vendor risk is usually a trajectory — a supplier whose external posture degrades sharply over six weeks is telling you something, and an annual cycle cannot hear it. This is the single largest functional gap between the two instruments.

Cover the whole estate, including the parts you did not list

Verifying one vendor's questionnaire properly takes days, which is why at four hundred vendors verification quietly stops happening and the questionnaire becomes a record that a question was asked. External measurement applies the same scrutiny to the four hundredth vendor as to the first, and can map fourth-party dependencies your vendors never declared.

Neither one is what a regulator asks for

Both instruments are frequently mis-sold as regulatory answers, and the Indian instruments are specific enough to make the mismatch visible.

  • A rating is not an audit. Where SEBI's CSCRF requires testing by a CERT-In empanelled information security auditing organisation, no ratings platform satisfies it and no auditor will accept one as a substitute.
  • A questionnaire is not continuous oversight. The RBI's outsourcing Directions place ongoing responsibility on the regulated entity for the outsourced activity; an annual attestation is evidence of an assessment, not of oversight between assessments.
  • Neither substitutes for a contract term. Rule 6(f) of the DPDP Rules requires appropriate security provisions in the contract with a Data Processor. That is a drafting obligation, and no amount of assessment or monitoring discharges it.

Using both without doing both badly

The reallocation that works is not a compromise between the two but a division of labour by tier. Continuous measurement runs across the whole vendor list, because its marginal cost per vendor is low and its value is early warning. Deep questionnaires and audits are reserved for the vendors where an inside view genuinely changes a decision — and are sent after the monitoring has run, so the questions are informed rather than generic.

The second-order benefit is that questionnaires get better when there are fewer of them. A thirty-question document aimed at a specific vendor, referencing what has actually been observed about that vendor, gets a more useful answer than a three-hundred-row spreadsheet sent to everyone. Third-party risk management for Indian BFSI sets out the tiering model and the rollout sequence in full.

Where BitScore fits, and where it does not

BitScore sells continuous measurement, and the four inside-the-perimeter rows in the table above are ones it cannot help with. If your programme's binding constraint is issuing, chasing and evidencing questionnaires, the product that fixes that is a questionnaire workflow platform, and Bitsight vs UpGuard works through that choice directly.

Where continuous measurement earns its place is the row no questionnaire reaches: knowing that something has changed, across every vendor, without asking. Most programmes already have the questionnaire half and are missing that one.

The capability table describes what each instrument can observe by its nature, not the feature set of any product. Regulatory references are summarised from the instruments covered on the linked pages, each of which cites the issuing notification directly. This page is general information, not legal advice. BitScore Cybertech LLP is an authorised Bitsight partner and sells continuous monitoring, which is disclosed at the top of the page as well as here.

Questions this page answers

Can security ratings replace vendor questionnaires?
No. A rating is calculated from externally observable signals, so it cannot see encryption at rest, privileged access review, staff vetting, recovery testing or sub-processor arrangements. Those are real controls that breaches usually turn on, and the vendor is the only available source for them. The two instruments answer different questions.
What can a rating tell you that a questionnaire cannot?
Three things: observed evidence rather than assertion, such as an expired certificate or a host beaconing to command-and-control infrastructure; change, because a questionnaire describes one date and degradation over six weeks is the useful signal; and coverage, because the same scrutiny applies to the four hundredth vendor as to the first.
Why do questionnaire programmes fail at scale?
Verifying a single vendor’s answers properly takes days. At four hundred vendors that verification quietly stops happening, and the questionnaire becomes a record that a question was asked rather than evidence of anything. The document still has value as a contractual record; it stops functioning as assurance.
Does either one satisfy an Indian regulator?
Neither, on its own. Where SEBI’s CSCRF requires testing by a CERT-In empanelled auditing organisation, no ratings platform satisfies it. An annual questionnaire is evidence of an assessment rather than of oversight between assessments. And Rule 6(f) of the DPDP Rules requires security provisions in the Data Processor contract, which is a drafting obligation neither instrument discharges.
How should the two be combined?
By tier. Continuous measurement runs across the whole vendor list, where its marginal cost per vendor is low and its value is early warning. Deep questionnaires and audits are reserved for vendors where an inside view changes a decision, and are sent after monitoring has run so the questions are specific rather than generic.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ