Fill out an information security questionnaire online — any format, any framework
Complete any information security questionnaire online using AI. Upload the buyer's assessment in any format, add your company docs, and get source-cited answers in minutes.

"Please complete this security questionnaire and return it by Friday."
The email arrives with an Excel attachment. Sometimes it's 50 questions. Sometimes 300. Sometimes it follows a standard framework (SIG, CAIQ, ISO 27001). Usually it's a custom format unique to that buyer.
Whatever they call it — "security questionnaire," "vendor assessment," "infosec review," "security due diligence" — the process is the same. Here's how to complete it online in minutes.
The problem with information security questionnaires
They're repetitive but never identical. You've answered "Describe your encryption at rest" fifteen times, but every buyer's spreadsheet puts it in a different row, with different wording, expecting a different level of detail.
The typical process:
- Open the buyer's spreadsheet
- Open your last completed questionnaire
- Ctrl+F for each question topic
- Copy, paste, rephrase to match the new format
- Chase engineering for product-specific answers
- Chase legal for privacy and compliance answers
- Review the whole thing for consistency
- Submit 2 days late
If this sounds familiar, you're doing the same work every time with no compounding benefit.
How to complete any security questionnaire online
Step 1: Identify the questionnaire type
Most information security questionnaires fall into one of these categories:
| Type | Characteristics | Common question count |
|---|---|---|
| Custom DDQ | Buyer's own format, mixed topics | 50–300 |
| SIG (Shared Assessments) | Standardized, 18 risk domains | 800+ (Core) or ~100 (Lite) |
| CAIQ | CSA cloud security, control IDs | 260+ |
| ISO 27001-based | 93 Annex A controls | 80–200 |
| SOC 2-based | Trust service criteria | 40–150 |
| Hybrid | Mix of standard + custom | Varies |
Identifying the type helps you match the right source documents and set accuracy expectations.
Step 2: Gather your knowledge sources
The quality of your answers depends entirely on the quality of your source documents:
- SOC 2 Type II report — Your single most valuable source. Covers encryption, access control, monitoring, incident response, availability, and processing integrity.
- Security policies — Information security, access control, data classification, incident response, acceptable use, data retention.
- Prior questionnaire responses — Gold. Past answers in questionnaire format, already reviewed and approved.
- Architecture docs — Data flow diagrams, infrastructure overview, deployment architecture.
- Compliance certifications — ISO 27001, HIPAA, GDPR DPA, PCI DSS (if applicable).
- Sub-processor list — Buyers always ask. Keep it current with DPA status.
Step 3: Complete with AI assistance
FillBase automates the entire process:
- Upload the questionnaire — Any format: Excel, Word, PDF. FillBase identifies questions, detects the framework, and maps them to your knowledge base.
- Auto-fill with citations — ~88% of questions answered automatically with source references. "AES-256 at rest via AWS KMS… Ref: SOC 2 §CC6.1, Encryption Policy §3.1."
- Review flagged questions — The ~12% FillBase can't answer are flagged for manual input. These are typically product-specific or company-specific questions.
- Export in original format — The completed questionnaire returns in the buyer's exact format. No reformatting.
Why information security questionnaires aren't going away
Some companies try to eliminate questionnaires with trust centers, pre-published security pages, or proactive sharing. These help — but enterprise buyers still send their own questionnaires because:
- Procurement process requires it — The completed questionnaire is a formal artifact in their vendor approval workflow
- Custom questions — They have concerns specific to their industry, data, or use case
- Legal record — Your written responses become contractual representations
- Audit trail — The buyer's security team needs documentation for their own auditors
The questionnaire isn't going away. The question is whether you spend 8 hours or 30 minutes on each one.
The compounding advantage
Here's what changes when you use FillBase:
- Questionnaire 1 — Upload SOC 2, 3 policies, company URL. ~85% auto-fill.
- Questionnaire 3 — Knowledge base includes 2 prior questionnaire responses. ~90% auto-fill.
- Questionnaire 5 — Knowledge base is rich. ~93% auto-fill. New questionnaires take 15 minutes.
- Questionnaire 10+ — Almost everything auto-fills. You review edge cases and submit.
Every completed questionnaire becomes a knowledge source for the next one. The template approach doesn't compound — FillBase does.
Common information security questionnaire topics
Regardless of format, these topics appear in virtually every questionnaire:
- Encryption — At rest, in transit, key management
- Access control — Authentication, authorization, privileged access, MFA
- Incident response — Process, SLAs, notification, post-mortems
- Business continuity — DR plan, RTO/RPO, backup strategy
- Compliance — SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS
- Data handling — Classification, retention, deletion, cross-border transfer
- Vulnerability management — Scanning, pen testing, patching cadence
- Vendor management — Sub-processors, third-party assessments, DPAs
- Employee security — Background checks, training, offboarding
- Monitoring — Logging, SIEM, alerting, audit trails
If your knowledge base covers these 10 topics well, you'll auto-fill 85–90% of any information security questionnaire.
Try it free
Upload an information security questionnaire at fillbase.app — any format, any framework. FillBase fills up to 50 questions free with source citations. No account required.
Use the information security questionnaire tool to get started, or browse all questionnaire types including DDQ, SIG, and SOC 2.
Related tools & resources
Related articles




