Home/Blog/The review

Founder's guide

What happens in a vendor security review

Founders tend to picture the security review as a document. It is a process, run by people with different jobs, and knowing its shape is most of what makes it survivable. This is what happens on the other side of the table, stage by stage, and where the weeks actually go.

Elsewhere on this blog we cover the individual artifacts: the questionnaire, the audit report, the test report, the letter. This piece is the map they sit inside.

Who is actually reading

Three readers, three questions, and they rarely talk to each other as much as you would hope.

  • Procurement owns the file. Their question is "is this complete?" They are not evaluating your architecture; they are checking that every box has something in it and that the something is dated and signed.
  • The security reviewer owns the risk. Their question is "can I verify this?" They have read a great many confident paragraphs and are looking for the ones backed by something checkable.
  • Legal or privacy owns the terms. Their question is "what happens to our data, and who else touches it?" Subprocessors, retention, breach notice windows.

An answer that satisfies procurement can still stall with the security reviewer, which is the most common way a deal quietly loses a month.

The six stages

StageWhat happensTypical time
1. Intake and tieringThey classify how risky you are. This decides everything after it.Days
2. QuestionnaireAnywhere from 40 to 300 questions, sent as a spreadsheet or through a portal.1 to 2 weeks
3. Evidence requestThey ask for the documents behind your answers.Days, if you have them
4. Technical reviewA security engineer reads your evidence and pushes back on the thin parts.1 to 3 weeks
5. Legal and privacyDPA, subprocessors, retention, breach notice.1 to 4 weeks, often in parallel
6. Approval or conditionsApproved, approved with conditions, or deferred pending remediation.Days

Two to four weeks end to end is a good outcome with a mid-market buyer. Six to twelve is normal at a large enterprise or in a regulated industry, because more people have to sign and each of them has a queue.

Tiering decides your review before it starts

Stage one is the one nobody tells you about, and it is the one that matters most. Buyers sort suppliers by blast radius: how sensitive the data is, how much system access you get, how many of their users depend on you being up.

A low tier might clear on a short questionnaire and your word. A high tier can make an audit report mandatory and require that a named accredited firm has tested you, in which case no amount of good technical evidence substitutes. Whether you actually need SOC 2 is really a question about which tier you are in.

Ask this on the first call

"What tier does this land in, and what does that tier require?" Nobody minds the question, procurement usually knows the answer, and it converts a month of guessing into a checklist.

What each stage asks for

Where deals actually stall

Not usually on a failed control. On these:

  1. An unverifiable claim. "We follow best practices" invites a follow-up, and a follow-up is a week.
  2. Evidence that does not exist yet. You answer in three days, then spend a month scheduling a test because the report was requested at stage three and you started at stage three.
  3. A stale document. A report from eighteen months ago with no re-test reads as "we did this once".
  4. An answer that contradicts another answer. Reviewers cross-check, and inconsistency costs more trust than a known gap does.
  5. Silence. A week of no reply moves you to the bottom of a queue you cannot see.

The one lever you control

Two levers, strictly. The other is answering the repeatable questions once, on a trust page, so stages two and three start further along.

You do not control the tier, the queue, or how many people have to sign. You control whether the evidence exists when it is asked for.

Preparing the pack before the first questionnaire arrives compresses stages three and four from weeks into days, because your answers arrive already backed. That is the whole argument for having a current test report, a re-test after you fix, and a dated letter on file: not because the document is impressive, but because it removes the round trip. Continuous scanners are fast but generally will not sign anything, which is a gap worth understanding before you rely on one; we wrote about what to look for in that category separately.

Have the evidence before they ask.

Vulnytics runs exploit-verified testing on your external surface, gives you a reproducible proof for every finding, re-tests after you fix, and issues a dated attestation letter. The pack a reviewer asks for at stage three, ready at stage one.

Common questions

What is a vendor security review?
The process an enterprise runs before it lets a new supplier touch its data or connect to its systems. It usually combines a questionnaire, a request for evidence such as an audit report or a test report, a technical review of your answers, and a legal pass over data processing terms. It is run by the buyer, not by you, and the buyer decides what is enough.
How long does a vendor security review take?
For a mid-market buyer, two to four weeks is common once you respond promptly. At a large enterprise, or in a regulated industry, six to twelve weeks is normal because more teams have to sign. Most of the elapsed time is waiting on one side or the other, which is why having evidence ready is the single biggest lever you control.
Who actually reviews your answers?
Usually three different readers with three different questions. Procurement checks that the file is complete. A security reviewer checks whether your claims can be verified. Legal or privacy checks the data terms. An answer that satisfies one can still stall with another, so write for all three.
What is vendor tiering and why does it matter?
Buyers sort suppliers into tiers by how much damage a compromise would do, typically based on data sensitivity, system access and how many of their users depend on you. The tier is set early and it decides everything that follows: which questionnaire you get, whether an audit report is mandatory, and whether a named accredited firm has to have tested you. Ask which tier you are in during the first call.

Keep reading: How to pass a security questionnaire · What is a security attestation letter? · Do you need SOC 2 to sell to enterprise?

Stage names, sequences and timings describe how enterprise vendor security reviews commonly run and will differ by buyer, industry and regulator; your buyer's own policy governs. This is general guidance, not legal or compliance advice. Vulnytics combines exploit-verified automated assessment with hands-on expert review by a person. We are not an accredited penetration-testing firm, so our report complements, and does not universally replace, one from an accredited firm where a buyer specifically requires it.