The difference between a SIG Lite and a SIG Core is not really length. It is what the buyer decided about you before they hit send. A Lite means they categorised you as lower risk and want a broad confirmation. A Core means they believe your product touches data they are accountable to a regulator for, and the answers will be read line by line.
This article covers how to identify which tier actually landed in your inbox, why the file may not match either template cleanly, what the buyer's choice signals about the deal, how the effort and staffing differ between the two, and what to do if you have received a Core and think the scope is wrong.
Identifying which one you received
Do not go by the filename. Buyers rename files, and a workbook called "Vendor Assessment 2026" tells you nothing. Three checks settle it in about five minutes.
Count the populated rows. Shared Assessments describes the 2023 SIG Lite as 126 risk control questions. If your file sits roughly in that range, you have a Lite or something close to it. Several hundred rows means Core or a scoped equivalent. The full content library runs to 1,855 questions, so nothing you receive will be everything.
Look at the shape of the coverage. A Lite touches many risk domains with a handful of questions each. A Core goes several levels deeper inside each domain, asking not just whether you have a control but how it is implemented, who reviews it, and how often. If a domain has one question, that is Lite behaviour. If it has fifteen, that is Core behaviour.
Check whether the question text asks for narrative. Lite questions tend to resolve to yes, no, or not applicable. Core questions frequently expect a description alongside the answer, and that expectation is the bulk of the extra work.
If you are still unsure, ask the buyer directly. "Is this scoped as a SIG Lite or a Core?" is a normal question that costs nothing and gets an answer.
Why your file may match neither
The SIG is built to be scoped, and this is the part that surprises people who read about the tiers and then open the workbook.
A buyer generates an assessment by selecting risk domains and control families. They can mix scope levels per domain, which means a single questionnaire can be Lite across most areas and Core in the two domains they actually care about. This is not an edge case; it is how experienced third-party risk teams use the tool.
That has a useful consequence. The dense sections tell you what the assessment is really about. If your file is broadly shallow but suddenly detailed on data retention and subprocessors, the reviewer has a specific concern about data retention and subprocessors, and those answers deserve disproportionate care. Treating a scoped questionnaire as uniform — spreading effort evenly across every section — is how vendors write beautiful answers about physical security for a datacentre they do not operate while giving a thin answer to the question the whole review exists to settle.
There is also a third tier. SIG Detail draws from the full library for buyers who want to go beyond standard scoping into specific control families. It is uncommon for small vendors and usually appears in regulated industries.
What the tier tells you about the deal
The tier is a risk classification, and it is worth reading as commercial information.
A Core means you are in scope for something the buyer is regulated on. Shared Assessments positions Core for third parties that store or manage highly sensitive or regulated information — payment data, health data, and similar. Receiving one means the buyer has decided your product handles material they answer for. That is a burden and also a signal: nobody spends a security analyst's week on a vendor they are lukewarm about.
A Lite can mean two very different things. Sometimes it means genuinely low risk and a routine box to tick. Sometimes it is explicitly a preliminary screen before a deeper review, which Shared Assessments names as one of its intended uses. The second case matters, because a vendor who treats the Lite as the whole engagement is unprepared when the Core arrives three weeks later. If a Lite arrives early in a large enterprise deal, ask whether a fuller assessment follows.
A hybrid means someone thought about it. Scoped assessments take effort to build, which usually means a real risk function rather than a procurement checklist. Expect follow-up questions on the dense sections.
How the effort differs
The gap is wider than the question count suggests, and it is not linear.
A Lite is mostly transcription. Broad yes-or-no questions across many domains map cleanly onto facts you either know or can find in an afternoon. For a company with existing documentation, a Lite is realistically a day or two of one person's time.
A Core is a different category of work, for three reasons. The narrative expectation means writing rather than ticking. The depth means questions where the honest answer requires a decision about what your architecture actually does — which is engineering judgment, not documentation. And Core answers attract follow-ups, so you should budget for a second round after submission.
The staffing follows from that. A Lite can be owned end to end by one non-technical person with an engineer on call for a handful of questions. A Core needs the split properly: a coordinator running the document and a senior engineer working a flagged subset in a bounded session. Our guide to answering a security questionnaire without a security team covers how to run that split so it takes hours of engineering time rather than weeks.
When the Core is the wrong scope
Occasionally you receive a Core that does not fit — most often when your product is narrow and the buyer's default assessment was built for a vendor that hosts everything.
The tell is a large "not applicable" count. If you are working through a questionnaire marking forty questions N/A because they ask about datacentres you do not operate, hardware you do not own, or business lines you are not in, the assessment was scoped for a different kind of company.
Raise it, early, in a specific way. Not "this is too long," which reads as reluctance, but "roughly a third of these questions cover physical datacentre operations. We run entirely on managed cloud infrastructure and can supply our provider's own attestations for that domain. Would you like us to complete those sections as N/A with a reference, or would you prefer to rescope?"
That framing is doing real work for the reviewer, who does not want forty meaningless N/A rows either. Buyers frequently narrow the assessment. What they will not do is narrow it on day nine, after you have already answered half of it.
Common mistakes with SIG tiers
Judging the tier by filename or by an article's question count. Open the file, count populated rows, and look at how deep the coverage goes inside each domain.
Spreading effort evenly across a scoped questionnaire. The dense sections are what the review is about. Weight your care accordingly.
Treating a SIG Lite as the end of the process. Shared Assessments lists preliminary screening as an intended use. Ask whether a deeper assessment follows.
Answering a Core with Lite-depth responses. Core questions expect narrative. A bare yes where a description was expected generates a follow-up round and delays the deal further than writing it properly would have.
Silently marking forty questions N/A. If the scope is genuinely wrong, say so in the first days with a concrete alternative. Buyers rescope early and refuse to rescope late.
FAQ
How many questions are in SIG Lite versus SIG Core?
Shared Assessments describes the 2023 SIG Lite as 126 risk control questions. SIG Core is substantially larger and third-party sources cite differing figures, partly because the SIG is on an annual release cycle and partly because buyers scope assessments themselves. Count the file you received rather than relying on a published number.
Which SIG will a buyer send me?
It depends on how they have classified your risk. Lite goes to lower-risk third parties or is used as a preliminary screen. Core goes to vendors that store or manage highly sensitive or regulated information. Buyers can also generate a scoped hybrid that is Lite in most domains and Core in a few.
Is SIG Core harder than SIG Lite?
Meaningfully, yes, and not only because of length. Core questions typically expect narrative descriptions rather than yes-or-no answers, they go deep enough to require engineering judgment, and they attract follow-up questions after submission.
Can I ask a buyer to send a SIG Lite instead of a Core?
You can ask, and it sometimes works when the scope genuinely does not fit your product — for example when a large portion of the questionnaire covers infrastructure you do not operate. Raise it in the first few days with a specific alternative rather than as a general objection to length.
Closing thought
The tier question is worth answering carefully because it is the cheapest planning information you will get. Five minutes counting rows and reading section depth tells you whether this is a two-day task or a two-week one, whether you need an engineer, and how much the buyer cares. Vendors who skip that step commit to a date first and discover the shape of the work afterwards, which is how a routine security review becomes a missed deadline in a deal that was going well.
Whichever tier arrives, a consistent slice of it is data protection documentation rather than security engineering: your subprocessor list, your DPA, retention periods, deletion process, where data sits. ComplyDog keeps those on a hosted portal at your own domain, current and public, so that portion of a Core is a link rather than a fortnight. The rest still needs your engineer. There is simply less of it.