A SIG is a Standardized Information Gathering questionnaire, published by Shared Assessments, that a buyer sends to a vendor to document how that vendor handles security and privacy. It arrived in your inbox because someone at your customer decided your product touches enough of their data to require a third-party risk assessment, and rather than write their own questions they used the industry template.
This article covers what the SIG actually is and who produces it, why the question count you read online will not match the file you were sent, the three tiers you might receive and how to tell which one you have, what changed in 2026 with the move to SIG Evolution, and the single most important thing to understand about a completed SIG: it is not a certification, and treating it like one will cost you the deal.
Who publishes the SIG, and what it is for
Shared Assessments is a membership organization that maintains third-party risk management tooling, and the SIG is its flagship product. The questionnaire exists so that a bank assessing forty vendors does not write forty different sets of questions, and so that a vendor answering forty assessments does not answer forty different sets. That is the entire premise: one vetted question bank, reused across an industry.
The SIG is not free in the way a public standard is free. It requires agreement to terms and conditions plus either a Shared Assessments membership or an annual subscription. This matters to you as a vendor in a specific and slightly absurd way: the buyer holds the licence, sends you the file, and you fill in a document you do not have your own copy of. If you want to work ahead of demand and prepare answers before a questionnaire arrives, you either subscribe yourself or you build your own internal answer bank and map it across when a real SIG lands.
The underlying content library is large. Shared Assessments puts it at 1,855 risk control questions, from which buyers scope a specific assessment. Nobody sends all of them.
Why the question count you read will not match your file
Search for the SIG and you will find confident, contradictory numbers. SIG Core is cited at 825 questions in one place and 855 in another. The risk domain count appears as 18, 19, and 21 depending on who is writing. SIG Lite is given as 126, as 128, and as 150.
These are not all errors. The SIG is on an annual release cycle, so a number that was right for the 2022 release is wrong for 2026, and much of the published commentary was written once and never revisited. But the deeper reason is that the SIG is designed to be scoped. A buyer selects risk domains, control families, or a regulatory scope, and generates a questionnaire from the library. Two customers can both send you "a SIG Core" and you can receive two different files.
The practical instruction is short. Do not plan your effort around a number you read in an article, including this one. Open the file, count the rows, look at which domains are populated, and size the work from that. A vendor who quotes a two-week turnaround based on a blog post and then opens a 900-row workbook has already set an expectation they will miss.
The three tiers, and telling them apart
Shared Assessments structures the SIG in three tiers, and knowing which you received tells you what the buyer thinks of your risk profile.
SIG Lite is the high-level pass. Shared Assessments describes the 2023 SIG Lite as 126 risk control questions designed to give a basic level of assessment due diligence. You get it when the buyer has categorised you as lower risk, or when they are running a preliminary screen before deciding whether to go deeper. It is broad and shallow by design.
SIG Core is the full assessment, meant for third parties that store or manage highly sensitive or regulated information. If you have received a Core, the buyer believes your product touches material they are accountable for. This is the tier where answers get read carefully and where a vague response generates a follow-up rather than a tick.
SIG Detail is the deepest level, drawn from the full library when a buyer wants to go beyond the standard scoping into specific control families.
You can also receive a hybrid. The scoping tool lets a buyer mix levels per domain, so a questionnaire can be Lite across most areas and Core on the two domains they actually care about. If the file you received is short overall but suddenly dense in one section, that section is what the assessment is really about, and it is where your answers should be strongest.
What changed in 2026
Two things, if your last SIG was a year or more ago.
The first is where the questionnaire lives. On 17 March 2026, at its 19th Annual Third-Party Risk USA Summit in Nashville, Shared Assessments launched SIG Evolution, or SIG EV, which moves building, sending, reviewing and scoring an assessment into the browser. For you as the vendor the practical effect is smaller than the announcement suggests. The Excel route is still open: answer offline, and the buyer imports what you send back. SIG EV also reads old files, works out which version it is looking at, and takes workbooks from the current year and the two before it as a starting point, so the fortnight you spent on a 2024 questionnaire is not written off.
The second is what the questions map to, and that changes the answers you have to write. Shared Assessments deepened four reference points in the 2026 release. ISO/IEC 42001 is now referenced, which makes AI management a standing subject rather than an occasional aside: expect to be asked what data trains a model, how it reaches production, and who watches it afterwards, and to answer even when the model is someone else's, reached through an API. The NIST SP 800-171 mapping is more granular, which matters if you serve the defence supply chain or touch Controlled Unclassified Information and is background noise if you don't. Alignment with the Business Resilience Council's Operational Resilience Framework is the one most likely to catch a small SaaS off guard, because it pushes resilience past "do you have a disaster recovery plan" toward whether you can keep operating through a disruption at all, which means knowing your own critical dependencies and therefore your vendors' vendors. And the older ISO 27001 mappings were brought up to ISO 27001:2022 and its restructured Annex A, so a certificate on the current revision lines up more cleanly than it used to; our ISO 27001 readiness guide covers what earning one involves.
A mapping is a filing convenience for the buyer, not a credential for you. It lets one answer close out a control in two frameworks. It does not make you compliant with anything referenced, and the reviewer reading your file knows that even if the person who forwarded it doesn't.
A completed SIG is not a certification
This is the misunderstanding that does the most damage, and it runs in both directions.
Returning the file is testimony, not a verdict. What you hand back is a record of what you say your controls are, with evidence attached wherever the buyer asked to see it. The judgment happens afterwards and on their side of the table: someone reads your answers against the risk their organisation is willing to carry, then decides whether to ask you to explain, ask you to fix, accept a different control that reaches the same place, or write the gap down as a risk they will hold. Submission triggers none of that. It only starts the reading.
Which means two things. First, do not describe yourself as "SIG certified" anywhere, because there is no such thing, and a security reviewer who sees that phrase on your website will read everything else you claim more sceptically. Second, an honest "no, and here is the compensating control" is a legitimate answer that assessments are designed to accommodate. Reviewers are used to gaps. What they are not used to is a yes that unravels under a follow-up question, and the follow-up is where a deal actually stalls.
A large share of what a SIG asks about is data protection rather than pure security: which subprocessors touch customer data, what the contractual chain looks like, how long data is retained, how a deletion request is handled, what happens on breach. Those are GDPR artifacts, and if you already maintain them, a meaningful part of the questionnaire is transcription rather than research. Our guide to subprocessors under GDPR covers the inventory that several of those answers draw on.
Common mistakes when answering a SIG
Quoting a turnaround before opening the file. The tier and scoping vary per buyer. Open the workbook, count the populated rows, then commit to a date.
Claiming to be "SIG certified." No certification exists. The SIG produces assertions, not a pass, and the phrase signals to a reviewer that you have not read the framework you are citing.
Answering yes where the honest answer is "not yet, and here is what compensates." Reviewers expect gaps and have a process for them. What they escalate is an answer that collapses on follow-up.
Treating each SIG as a fresh writing project. The overlap between assessments is high. Answering ad hoc every time is how a two-day task becomes a two-week one for the fourth quarter in a row.
Assuming the mappings do the compliance work. A question mapped to ISO 27001 does not make you ISO 27001 certified. The mapping saves the buyer from asking the same thing twice, nothing more.
FAQ
What does SIG stand for?
Standardized Information Gathering. It is a questionnaire product published by Shared Assessments, a membership organization focused on third-party risk management, and it is used by buyers to assess the security and privacy controls of their vendors.
How many questions are in a SIG questionnaire?
It depends on the tier and how the buyer scoped it. Shared Assessments puts the full content library at 1,855 risk control questions and describes the 2023 SIG Lite as 126. Because buyers scope assessments by risk domain and control family, two files described as the same tier can differ, so count the file you received rather than relying on a published figure.
What is the difference between SIG Lite and SIG Core?
SIG Lite is a high-level screen for lower-risk third parties. SIG Core is the deeper assessment used for vendors that store or manage highly sensitive or regulated information. Receiving a Core means the buyer considers your product material to data they are accountable for.
Do I have to pay to answer a SIG?
Not to answer one your customer sends, since they hold the licence and supply the file. Using the SIG yourself, to prepare in advance or to assess your own vendors, requires Shared Assessments membership or an annual subscription.
Closing thought
The first SIG is always the expensive one, because the work is not really answering questions. It is discovering what you actually do, in enough detail to state it in writing, for the first time. The second one is cheaper only if you kept the answers somewhere better than the completed workbook in a shared drive, which is where most small teams leave them.
The parts a buyer asks about most often are the parts you can publish once and point at rather than retype: your subprocessor list, your DPA, how data subject requests are handled, where data lives, what your security posture actually is. ComplyDog gives you a hosted compliance portal on your own domain that keeps those current and public, which turns a recurring set of questionnaire answers into a link. It will not fill in a 900-row SIG for you. It will mean that the fifteen questions every buyer asks are already answered before the workbook arrives.