SideGuy North County San Diego
SideGuy Compliance Field Guide Β· Updated 2026

SIG Lite Questionnaire (2026): Structure, Fields & How to Answer It Fast

⚑ SIG Lite: Quick Answer

SIG Lite is the condensed third-party-risk questionnaire from Shared Assessments β€” the same ~19-21 risk-domain skeleton as the full SIG Core, at roughly a third of the question count. Every question row carries the same fields: question ID, risk domain, question text, a Yes/No/N-A response, a free-text Additional Information field, and mappings to frameworks like ISO 27001 and NIST. If a customer sent you one: you don't need to buy anything β€” build an answer library from your existing SOC 2 / ISO evidence and answer it in days.

A security assessment questionnaire is a data structure, not a test. Once you see the structure β€” domains β†’ questions β†’ constrained responses β†’ mappings β€” answering stops being scary.

SIG Lite vs SIG Core
PJ Magalong β€” SideGuy
PJ explains this page
Tap my face for the 30-second breakdown
I'll walk you through how a SIG Lite is actually built β€” the risk domains, what each question row contains, and the answer-library trick that turns a two-week fire drill into a two-day task. Still stuck? Text me the questionnaire.
Text PJ for help

What a SIG Lite Actually Is

The SIG (Standardized Information Gathering) questionnaire is published annually by Shared Assessments and is one of the two dominant vendor security questionnaire formats (the other being CAIQ for cloud). Enterprises use it to assess third parties before and during a vendor relationship. It ships in tiers: SIG Core β€” the full several-hundred-question library for high-risk vendors β€” and SIG Lite β€” the condensed top-level version for lower-risk vendors or first-pass screening. Buyers can also scope a custom SIG anywhere in between.

Practical translation: if you are a small SaaS vendor and a Fortune-1000 prospect sent you a SIG Lite, that is usually GOOD news β€” you got the lighter tier. Answer it well and quickly and you look like a bigger operation than you are.

The Structure: Risk Domains

Recent SIG releases organize questions into roughly 19-21 risk domains (the exact list shifts slightly each annual release β€” recent additions include AI and Nth-party/supply-chain risk). The domains you will see:

Domain clusterWhat the questions probe
Governance & riskEnterprise risk management, security policy, organizational security, compliance management
People & physicalHuman resources security, physical & environmental security
Core technicalAccess control, network security, application security, server/endpoint security, cloud hosting
OperationsIT operations management, incident event & communications management, threat management
Resilience & dataBusiness resilience / continuity, asset & information management, privacy
Extended riskSupply chain / Nth-party risk, ESG, artificial intelligence (newer releases)

The Fields in Every Question Row

Whether it arrives as a spreadsheet or through a TPRM portal (OneTrust, ProcessUnity, Archer, Venminder…), each SIG Lite question carries the same field structure:

FieldWhat goes in it
Question ID / numberStable identifier (e.g., a domain-prefixed number) β€” use it to key your answer library
Risk domain / categoryWhich of the ~19-21 domains the question belongs to
Question textThe control question itself, phrased for a Yes/No answer
ResponseConstrained field: Yes / No / N/A (some portals add 'Yes with exceptions')
Additional InformationFree text β€” context, compensating controls, scope caveats. Your honesty lives here
Framework referencesMappings to ISO 27001, NIST, PCI DSS etc. β€” how the buyer traces your answer back to standards

SIG Lite vs SIG Core

DimensionSIG LiteSIG Core
DepthTop-level question per topic β€” roughly a third the sizeFull drill-down library, several hundred questions
Who gets itLower-risk vendors Β· initial screeningHigh-risk vendors handling sensitive data at volume
Time to answer (prepared)Days with an answer library1-3 weeks even when prepared
Time to answer (cold)1-2 weeks of painA month of pain and internal chasing
StructureSame domains, same fieldsSame domains, same fields β€” just more rows

The Operator-Honest Way to Answer One

Build the answer library ONCE: export every question, answer each honestly, and attach the evidence pointer (your SOC 2 report section, policy doc, or screenshot) next to it. Then every future questionnaire β€” SIG Lite, CAIQ, custom β€” is a lookup job, not a research project. Three rules that keep you out of trouble: (1) never answer Yes to a control you don't run β€” "No, compensating control: β€¦" in the Additional Information field beats a discovered lie every time; (2) use N/A aggressively and explain why in one sentence β€” a 40-person SaaS legitimately N/As big chunks of physical-security and mainframe questions; (3) don't volunteer scope you weren't asked about. Turn it around inside a week and you'll beat 80% of the vendors in the queue.

FAQ

What is the SIG Lite questionnaire?
SIG Lite is the condensed version of the Shared Assessments SIG (Standardized Information Gathering) questionnaire β€” a third-party risk assessment used by enterprises to vet vendors. It keeps the same risk-domain structure as the full SIG Core but asks a reduced, higher-level question set, and it is typically sent to lower-risk vendors or used as an initial screen before deeper diligence.
How is a SIG Lite questionnaire structured?
It is organized by risk domain β€” the recent SIG releases span roughly 19-21 domains covering areas like enterprise risk management, access control, application security, network security, incident management, business resilience, cloud hosting, privacy, supply chain / Nth-party risk, and AI. Each row is one question inside a domain, and every question carries the same field set.
What fields does each SIG Lite question contain?
Each question row typically carries: a question ID/number, the risk domain and category it belongs to, the question text itself, a constrained response field (Yes / No / N/A), a free-text Additional Information field for context or compensating controls, and framework reference mappings that tie the question to standards like ISO 27001, NIST, and PCI DSS.
What is the difference between SIG Lite and SIG Core?
SIG Core is the full question library β€” several hundred questions deep, meant for high-risk or data-heavy vendor relationships. SIG Lite is roughly a third the size, asking the top-level question per topic instead of the detailed drill-downs. Same domains, same field structure, different depth. Buyers often scope a custom SIG between the two.
Do I need to buy a Shared Assessments license to answer a SIG Lite?
No. If a customer sends you their SIG Lite (usually as a spreadsheet or through a TPRM portal), you just answer it. The license is what the SENDER needs to build and distribute the questionnaire. As the vendor answering, your cost is time β€” which is why an answer library mapped to your SOC 2 / ISO evidence is the single best investment.
Related Resources
β–Ά
Text PJ Β· 858-461-8054
Done-for-you with SideGuy

Want your security questionnaires answered for you?

We build the answer library, map every response to your actual SOC 2 / ISO evidence, draft the Additional-Information context in plain honest English, and turn SIG Lites around in days β€” without a compliance-consultant retainer.

Text PJ your questionnaire β†’
⭐ Leave SideGuy a Google Review
Serving North County
Solana Beach Encinitas Leucadia Cardiff Del Mar
Staring at a SIG Lite a customer just sent you?
Text PJ β€” real human, honest answer, fast. No consultant pitch.
πŸ’¬ Text PJ β€” 858-461-8054
Text PJ
Text PJ
858-461-8054

Related Decisions β€” Compliance

πŸ“Š Compliance comparisons Β· explore the full cluster