Enterprise software engineering

Your review starts when the file is complete

UC Berkeley puts a vendor security assessment at four to six weeks, starting from the day the supplier has handed over everything asked for. That date is the one you can move.

Tell us what your review asks for

Send the questionnaire, the gate list or just the date you have promised. A technical person answers.

The questionnaire, the gate list, or the date you have promised. Any one of the three is enough to answer against.

How we handle what you send is set out in our privacy notice.

Most of what lands in your inbox is not opinion. EDUCAUSE publishes the questionnaire that a lot of large institutions send, with Internet2 and REN-ISAC, and version 4.1.6 of it runs to 332 distinct questions. Of those, 85 ask the supplier to provide, attach or reference a document rather than tick yes or no. Seven of them, DOCU-01 to DOCU-07, name the document they want. So the honest description of a security review is not an interrogation. It is a request for a folder, and the folder either exists on the day it is asked for or it gets written while your date slips. Here is how those 332 questions are distributed by scope.

Show data table
EDUCAUSE HECVAT 4.1.6, all 332 questions. Scopes overlap, so the bars deliberately do not sum to 332.
Item Questions in scope
START HERE 22 questions
Organization 51 questions
Product 46 questions
Infrastructure 56 questions
IT Accessibility 23 questions
Case-Specific 68 questions
AI 37 questions
Privacy 189 questions

Privacy and Case-Specific carry the largest sets, and no single scope is the whole questionnaire.

HECVAT 4.1.6 questions by scope EDUCAUSE HECVAT 4.1.6, all 332 questions. Scopes overlap, so the bars deliberately do not sum to 332. EDUCAUSE, with Internet2 and REN-ISAC, HECVAT 4.1.6

Two more sets sit behind a trigger. Twenty-nine questions fire when health data is in scope and twelve when cardholder data is, so an engagement that touches either is answering a longer questionnaire than the one it was quoted against.

Two institutions publish their own clocks, and they are worth reading separately rather than as a category average.

4 to 6 weeksUC Berkeley, once the file is complete

UC Berkeley Information Security Office, Vendor Security Assessment Service.

4 weeksUC Davis target

UC Davis published vendor security assessment guidance.

3 months aheadUC Davis submission advice

UC Davis published vendor security assessment guidance, its advice to its own requesters.

*Disclaimer: Industry figures published by other organisations, not Atyantik results.

UC Berkeley's sentence carries a clause most people skip. The four to six weeks run "starting from the date the Vendor has provided all the information requested". Before that date there is no clock at all, only email. UC Davis targets four weeks and separately tells the people inside its own organisation to submit at least three months before they need an answer, which is the gap between a target and a calendar. UC Davis also names what stretches it: how many requests arrive at once against the budget cycle, how long the NDA takes to negotiate, and submissions that come in incomplete. Read those three together and the picture is plain. Your assessor's queue is theirs, your NDA is shared, and the completeness of the file belongs to your supplier. That is the part anyone can actually move, and it is why we start by asking what your review will ask for.

What your review asks for, in order

The order six questions usually arrive in, and the artifact that answers each one.

  1. Is the file complete?

    Every questionnaire answer present, with the documents they reference attached rather than merely promised.

  2. Is it current?

    An existing HECVAT or SIG is accepted where the answers are still accurate, which saves real weeks.

  3. Does the evidence corroborate the answers?

    Test summaries, the vulnerability remediation policy and the SDLC methodology are read against what was claimed.

  4. Do the terms and the insurance hold?

    Legal reads the data security addendum, and risk reads the insurance cover behind it.

  5. Are the fourth parties known?

    Your assessor asks who else touches the system, and whether they can be assessed too.

  6. What is the residual risk, and who accepts it?

    Findings are written up, and a named owner signs for what is left over.

Nine functions read this file: your sponsor, procurement, vendor risk, an outsourced assessor where one is appointed, legal, privacy, the architecture review board, insurance and risk, and a CISO exception path. UC Berkeley publishes the exception route on its own service page, so a finding does not end the engagement, it routes it. Three things we bring on day one: our NDA, so that negotiation is not on your critical path; architecture and data-flow diagrams; and the TRS, which is the document your compliance team reads for design intent. The rest of that list is what your review asks for, and we answer it in your file rather than pointing at a badge. UC Berkeley also publishes the flip side. If the vendor is not responsive to the assessor, the assessment is delayed, and that is the failure mode we plan against.

Say it plainly, because you will have to repeat it upward. We hold no SOC 2, no GDPR certification and no HIPAA certification. What we do is engineer systems that pass your audits, and write the design intent down where your compliance team can check it. If your engagement genuinely requires a certified supplier, we will tell you that in the first conversation and point you somewhere else.

What each artifact actually proves

Read in the issuing bodies' own words, so you can quote them rather than us.

Certification artifacts compared by issuer, scope and access
QuestionAn ISO certificateA SOC 2 reportWhat some suppliers publishWhat we send you
Who issues itAn external certification body, never ISO itselfAn examination report, not a certificateThe supplier, as a badge on its own siteUs, written for your assessor to read
What it coversA management system for security riskThe service organisation's own systemA claim of compliance, not the reportYour build: the TRS, diagrams, questionnaire answers
Who may see itAnyone shown the certificateSpecified parties with sufficient knowledge of the systemAnyone with a browserEveryone in your review who has to read it
What it saysNothing directly; certification is a separate choiceNothing about your project specificallyCompliance, a term never used in SOC 2 examinationsDesign intent your compliance team can verify

ISO is blunt about the first row: it does not perform certification or issue certificates, so nobody is certified by ISO. An external certification body issues the certificate. The second row matters more. ISO says conformity with 27001 means a system to manage risk is in place, which is a management system rather than a statement about any piece of software. ISO also says outright that implementing 27001 and certifying against it are separate choices. On the SOC 2 column, the AICPA's own journal notes that compliance is a term never used in SOC 2 examinations, and that a report is restricted to specified parties who already understand the system. A badge on a website is not that report. What we send you is the fourth column, and it is the file: the TRS, the diagrams, and answers written against your questionnaire.

Your security team did not get stricter for sport. Verizon's annual breach report counts how often a third party was involved in a confirmed data breach, and that share has moved across three consecutive editions.

Show data table
Verizon DBIR, share of CONFIRMED DATA BREACHES with third-party involvement. Each point is a report edition, not a calendar year.
Stage Share of confirmed breaches
2024 DBIR 15%
2025 DBIR 30%
2026 DBIR 48%

Third-party involvement in confirmed breaches has risen across three consecutive editions.

Third party involved in confirmed data breaches Verizon DBIR, share of CONFIRMED DATA BREACHES with third-party involvement. Each point is a report edition, not a calendar year. Verizon Data Breach Investigations Report, 2024, 2025 and 2026 editions

Read the denominator carefully, because it is what makes the number usable in your own meeting. This is confirmed breaches, not incidents and not organisations, and Verizon's measure covers three different ways a third party can be in the story. One figure from the 2026 edition sharpens it. Where cloud MFA credentials were exposed through a third party, 23 percent of those third parties fully remediated, out of 7,513 cases. So the question your review is really asking is not whether a supplier can be a risk. It is what the supplier does once something is found.

One question catches most suppliers flat: who else touches this system. Published guidance asks a supplier to help facilitate assessments of the fourth parties it significantly relies on. The UK government's own survey shows how unevenly organisations do this today, and how much further the large ones go.

Show data table
UK DSIT Cyber Security Breaches Survey 2025, N=2,180 UK organisations. Percent of organisations, not of contracts.
Dimension Immediate suppliers Wider supply chain
Micro 11% 6%
Small 21% 11%
Medium 32% 15%
Large 45% 25%

Large organisations review immediate suppliers at 45 percent, and the wider chain at 25.

Formal supplier risk review by organisation size UK DSIT Cyber Security Breaches Survey 2025, N=2,180 UK organisations. Percent of organisations, not of contracts. UK Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025

Both series are UK survey figures about organisations in general, and neither is a result of ours. The useful part is the gap between the two bars in every size band. Far fewer organisations look past the supplier they signed with than look at the supplier itself, which is exactly the gap the newer questionnaires are written to close. If your review reaches that far, expect the question, and expect it to arrive late, after the schedule is already set.

The question that usually comes from one level up is why not give this to the firm you already have an MSA with. It is a fair question, and the honest answer is that an existing MSA transfers risk, it does not add capability. The review still happens, it just happens to a name procurement already knows.

The kind of environment we work in

A class of engagement rather than a named client, because our case studies stay anonymous.

The environment

Regulated finance and supply-chain platforms, where security audits are quarterly and downtime is measured in minutes.

The standard

OAuth and SSO implemented at the standard those domains expect, rather than the standard that ships by default.

The record

More than 50 enterprise engagements across seven countries, with the longest active one running over a decade.

The claim to test

On-time delivery against agreed scope since 2015, which is the claim your sponsor will want to test.

We do not name clients, and that stays true regardless of who has given permission, so nothing above is a logo you can look up. What you can do instead is talk to people. References are available when you are ready to verify, and that is a better test than a story we control the telling of.

Your organisation has a spend level above which IT approval, comparison shopping, legal review and a security assessment all fire at once. If this crosses that level, you are buying the review as well as the build. If it does not, say so on the form and we will tell you that in one reply rather than over six weeks. Nobody in this category prints a price, and we are not going to invent one. What we can do is show you the shape, so you can size it yourself. Buy discovery on its own, first and bounded. It ends with the BRD, FRD, SRS and TRS set, and those are the same documents your architecture review board and your assessor will ask for. That is the whole argument of this conversation: the documents that price the build are the documents your review opens with.

How the money is shaped

  • Discovery, bought first

    Bounded, and bought first

    Sized against the scope you send.

    What it includes

    • The BRD, FRD, SRS and TRS set.
    • Milestone planning.
    • Documented exit criteria.

    Widens when more than one business unit owns the requirements, or the scope spans several systems.

  • The build

    Against discovery milestones

    Scope changes quoted beforehand.

    What it includes

    • Execution against the milestones discovery set.
    • Scope changes quoted before the work rather than invoiced after.
    • The same documents kept current as the build moves.

    Widens when the number of gates it has to clear grows, or an outsourced assessor is in the loop.

  • The review work

    Alongside the build

    Answered from the discovery file.

    What it includes

    • Answering your questionnaire against the file discovery produced.
    • Re-answering at renewal, because the assessment re-fires on renewals and renegotiated agreements.
    • Answering for our own suppliers where your review brings them into scope.

    Widens when health or cardholder data is in scope, or your data security addendum has to be taken unmodified.

Send us the scope and the list of gates you have to clear and we will size discovery against it. The form gets you a conversation with a technical person, not a quote and not a proposal deck.

Whether to call us

  • You have budget approved and a date promised, and the supplier decision is still open.

  • Your engagement has to clear a security assessment, an architecture review board or an outsourced assessor.

  • You want the requirements written down properly before anyone quotes a build.

Where we are the wrong call

  • Your contracting rules require the supplier itself to hold a certificate, and we hold no certificates at all.

    Talk to us anyway if you are unsure

  • You are bidding into UK central government, where Cyber Essentials is a condition under PPN 09/14 of 2014, so confirm the current position.

    Contact us

  • You need hardening, penetration testing or vulnerability remediation on a system that is already running in production today.

    Security engineering

  • You need consent, retention, deletion and a regulator-facing position, which is data protection work rather than a security review.

    Privacy engineering

  • You need the standard, the audit and the evidence pack for accessibility, which is an engagement of its own.

    Accessibility

  • You need conformance work against WCAG specifically, which is measured against that standard rather than a customer questionnaire.

    WCAG compliance

  • You need a response clock on something already live, which is a support arrangement rather than a one-off review.

    Support

Before you send the questionnaire

The six things people ask us before they ask us for anything else.

What do I tell our security team when you have no SOC 2?
No. We hold no SOC 2, GDPR or HIPAA certification.
  • Tell them we engineer systems that pass your audits and document design intent in the TRS so your compliance team can verify it, and that the AICPA's own journal says compliance is a term never used in SOC 2 examinations.
  • If your rules require a certified supplier, we will say so upfront and refer you.
How long does it take you to answer a security questionnaire?
We answer from the documents discovery already produced, so the honest number depends on how much of your questionnaire those cover. Reuse of a current HECVAT or SIG is accepted in published guidance and saves real time. What we commit to is that we do not go quiet: an unresponsive supplier is the published reason assessments get delayed.
Our security team will find things. What happens then, and who fixes them?
Expect findings.
  • Each one gets an owner, a remediation date and a written note of what is left, which is what your risk function needs in order to accept residual risk.
  • UC Berkeley publishes a CISO exception path for exactly this, so a finding routes the deal rather than ending it.
  • We fix what is ours in the build, and we tell you plainly when something is not.
Will you sign our contract as it is, or are you going to redline it?
We offer our own NDA on day one so that is not on your critical path. On your data security addendum, we read it and take it as written wherever we can operate under it, and where we cannot, we come back with the specific clause and the reason rather than a general redline. Legal negotiation is one of the named causes of assessment delay, so we treat it as schedule work.
Who are your subprocessors, and where does our data physically sit?
In the default shape there are none, because the work happens in your accounts.
  • If you have your own Git hosting, cloud accounts and storage, we work inside them.
  • If you do not, we provision them, set them up and hand you the keys, so residency is your choice and stays under your control.
  • Our team works from Vadodara, India.
Who owns the code and the documentation when we are done?
You do. The requirements set, the specifications and the TRS are yours, and they are written to be read by someone who was not in the room. That is the same file your compliance team uses to verify design intent, so ownership of it is not a detail.

Send us your review

Send the questionnaire, the gate list, or the date you have promised somebody. Two outcomes, and both are useful to you.

Either we take the questionnaire and the document list off your desk, or we read it and tell you in one reply that this is not our work and who to ask instead. If your rules need a certified supplier, that is the reply you will get, and you will get it before you have spent a month finding out.

Tell us what your review asks for and what date you are working to. On request, a technical person joins within one business day.

No badge. Just the file your review opens with.

Tirth Bodawala, co-founder and technical lead at Atyantik Technologies
Tirth BodawalaCo-founder and technical lead
  • What you send stays private
  • A technical person answers
  • No proposal deck
  • We say no when it is not our work

Tell us where you are

On request, a technical person joins within one business day.

How we handle what you send is set out in our privacy notice.