Your review starts when the file is complete
UC Berkeley puts a vendor security assessment at four to six weeks, starting from the day the supplier has handed over everything asked for. That date is the one you can move.
Tell us what your review asks for
Send the questionnaire, the gate list or just the date you have promised. A technical person answers.
Most of what lands in your inbox is not opinion. EDUCAUSE publishes the questionnaire that a lot of large institutions send, with Internet2 and REN-ISAC, and version 4.1.6 of it runs to 332 distinct questions. Of those, 85 ask the supplier to provide, attach or reference a document rather than tick yes or no. Seven of them, DOCU-01 to DOCU-07, name the document they want. So the honest description of a security review is not an interrogation. It is a request for a folder, and the folder either exists on the day it is asked for or it gets written while your date slips. Here is how those 332 questions are distributed by scope.
Show data table
| Item | Questions in scope |
|---|---|
| START HERE | 22 questions |
| Organization | 51 questions |
| Product | 46 questions |
| Infrastructure | 56 questions |
| IT Accessibility | 23 questions |
| Case-Specific | 68 questions |
| AI | 37 questions |
| Privacy | 189 questions |
Privacy and Case-Specific carry the largest sets, and no single scope is the whole questionnaire.
Two more sets sit behind a trigger. Twenty-nine questions fire when health data is in scope and twelve when cardholder data is, so an engagement that touches either is answering a longer questionnaire than the one it was quoted against.
Two institutions publish their own clocks, and they are worth reading separately rather than as a category average.
UC Berkeley Information Security Office, Vendor Security Assessment Service.
UC Davis published vendor security assessment guidance.
UC Davis published vendor security assessment guidance, its advice to its own requesters.
*Disclaimer: Industry figures published by other organisations, not Atyantik results.
UC Berkeley's sentence carries a clause most people skip. The four to six weeks run "starting from the date the Vendor has provided all the information requested". Before that date there is no clock at all, only email. UC Davis targets four weeks and separately tells the people inside its own organisation to submit at least three months before they need an answer, which is the gap between a target and a calendar. UC Davis also names what stretches it: how many requests arrive at once against the budget cycle, how long the NDA takes to negotiate, and submissions that come in incomplete. Read those three together and the picture is plain. Your assessor's queue is theirs, your NDA is shared, and the completeness of the file belongs to your supplier. That is the part anyone can actually move, and it is why we start by asking what your review will ask for.
What your review asks for, in order
The order six questions usually arrive in, and the artifact that answers each one.
- Is the file complete?
Every questionnaire answer present, with the documents they reference attached rather than merely promised.
- Is it current?
An existing HECVAT or SIG is accepted where the answers are still accurate, which saves real weeks.
- Does the evidence corroborate the answers?
Test summaries, the vulnerability remediation policy and the SDLC methodology are read against what was claimed.
- Do the terms and the insurance hold?
Legal reads the data security addendum, and risk reads the insurance cover behind it.
- Are the fourth parties known?
Your assessor asks who else touches the system, and whether they can be assessed too.
- What is the residual risk, and who accepts it?
Findings are written up, and a named owner signs for what is left over.
Nine functions read this file: your sponsor, procurement, vendor risk, an outsourced assessor where one is appointed, legal, privacy, the architecture review board, insurance and risk, and a CISO exception path. UC Berkeley publishes the exception route on its own service page, so a finding does not end the engagement, it routes it. Three things we bring on day one: our NDA, so that negotiation is not on your critical path; architecture and data-flow diagrams; and the TRS, which is the document your compliance team reads for design intent. The rest of that list is what your review asks for, and we answer it in your file rather than pointing at a badge. UC Berkeley also publishes the flip side. If the vendor is not responsive to the assessor, the assessment is delayed, and that is the failure mode we plan against.
Say it plainly, because you will have to repeat it upward. We hold no SOC 2, no GDPR certification and no HIPAA certification. What we do is engineer systems that pass your audits, and write the design intent down where your compliance team can check it. If your engagement genuinely requires a certified supplier, we will tell you that in the first conversation and point you somewhere else.
What each artifact actually proves
Read in the issuing bodies' own words, so you can quote them rather than us.
| Question | An ISO certificate | A SOC 2 report | What some suppliers publish | What we send you |
|---|---|---|---|---|
| Who issues it | An ISO certificateAn external certification body, never ISO itself | A SOC 2 reportAn examination report, not a certificate | What some suppliers publishThe supplier, as a badge on its own site | What we send youUs, written for your assessor to read |
| What it covers | An ISO certificateA management system for security risk | A SOC 2 reportThe service organisation's own system | What some suppliers publishA claim of compliance, not the report | What we send youYour build: the TRS, diagrams, questionnaire answers |
| Who may see it | An ISO certificateAnyone shown the certificate | A SOC 2 reportSpecified parties with sufficient knowledge of the system | What some suppliers publishAnyone with a browser | What we send youEveryone in your review who has to read it |
| What it says | An ISO certificateNothing directly; certification is a separate choice | A SOC 2 reportNothing about your project specifically | What some suppliers publishCompliance, a term never used in SOC 2 examinations | What we send youDesign intent your compliance team can verify |
ISO is blunt about the first row: it does not perform certification or issue certificates, so nobody is certified by ISO. An external certification body issues the certificate. The second row matters more. ISO says conformity with 27001 means a system to manage risk is in place, which is a management system rather than a statement about any piece of software. ISO also says outright that implementing 27001 and certifying against it are separate choices. On the SOC 2 column, the AICPA's own journal notes that compliance is a term never used in SOC 2 examinations, and that a report is restricted to specified parties who already understand the system. A badge on a website is not that report. What we send you is the fourth column, and it is the file: the TRS, the diagrams, and answers written against your questionnaire.
Your security team did not get stricter for sport. Verizon's annual breach report counts how often a third party was involved in a confirmed data breach, and that share has moved across three consecutive editions.
Show data table
| Stage | Share of confirmed breaches |
|---|---|
| 2024 DBIR | 15% |
| 2025 DBIR | 30% |
| 2026 DBIR | 48% |
Third-party involvement in confirmed breaches has risen across three consecutive editions.
Read the denominator carefully, because it is what makes the number usable in your own meeting. This is confirmed breaches, not incidents and not organisations, and Verizon's measure covers three different ways a third party can be in the story. One figure from the 2026 edition sharpens it. Where cloud MFA credentials were exposed through a third party, 23 percent of those third parties fully remediated, out of 7,513 cases. So the question your review is really asking is not whether a supplier can be a risk. It is what the supplier does once something is found.
One question catches most suppliers flat: who else touches this system. Published guidance asks a supplier to help facilitate assessments of the fourth parties it significantly relies on. The UK government's own survey shows how unevenly organisations do this today, and how much further the large ones go.
Show data table
| Dimension | Immediate suppliers | Wider supply chain |
|---|---|---|
| Micro | 11% | 6% |
| Small | 21% | 11% |
| Medium | 32% | 15% |
| Large | 45% | 25% |
Large organisations review immediate suppliers at 45 percent, and the wider chain at 25.
Both series are UK survey figures about organisations in general, and neither is a result of ours. The useful part is the gap between the two bars in every size band. Far fewer organisations look past the supplier they signed with than look at the supplier itself, which is exactly the gap the newer questionnaires are written to close. If your review reaches that far, expect the question, and expect it to arrive late, after the schedule is already set.
The question that usually comes from one level up is why not give this to the firm you already have an MSA with. It is a fair question, and the honest answer is that an existing MSA transfers risk, it does not add capability. The review still happens, it just happens to a name procurement already knows.
The kind of environment we work in
A class of engagement rather than a named client, because our case studies stay anonymous.
The environment
Regulated finance and supply-chain platforms, where security audits are quarterly and downtime is measured in minutes.
The standard
OAuth and SSO implemented at the standard those domains expect, rather than the standard that ships by default.
The record
More than 50 enterprise engagements across seven countries, with the longest active one running over a decade.
The claim to test
On-time delivery against agreed scope since 2015, which is the claim your sponsor will want to test.
5Logins unified
Read the full case studyWe do not name clients, and that stays true regardless of who has given permission, so nothing above is a logo you can look up. What you can do instead is talk to people. References are available when you are ready to verify, and that is a better test than a story we control the telling of.
Your organisation has a spend level above which IT approval, comparison shopping, legal review and a security assessment all fire at once. If this crosses that level, you are buying the review as well as the build. If it does not, say so on the form and we will tell you that in one reply rather than over six weeks. Nobody in this category prints a price, and we are not going to invent one. What we can do is show you the shape, so you can size it yourself. Buy discovery on its own, first and bounded. It ends with the BRD, FRD, SRS and TRS set, and those are the same documents your architecture review board and your assessor will ask for. That is the whole argument of this conversation: the documents that price the build are the documents your review opens with.
How the money is shaped
Discovery, bought first
Bounded, and bought first
Sized against the scope you send.
What it includes
- The BRD, FRD, SRS and TRS set.
- Milestone planning.
- Documented exit criteria.
Widens when more than one business unit owns the requirements, or the scope spans several systems.
The build
Against discovery milestones
Scope changes quoted beforehand.
What it includes
- Execution against the milestones discovery set.
- Scope changes quoted before the work rather than invoiced after.
- The same documents kept current as the build moves.
Widens when the number of gates it has to clear grows, or an outsourced assessor is in the loop.
The review work
Alongside the build
Answered from the discovery file.
What it includes
- Answering your questionnaire against the file discovery produced.
- Re-answering at renewal, because the assessment re-fires on renewals and renegotiated agreements.
- Answering for our own suppliers where your review brings them into scope.
Widens when health or cardholder data is in scope, or your data security addendum has to be taken unmodified.
Send us the scope and the list of gates you have to clear and we will size discovery against it. The form gets you a conversation with a technical person, not a quote and not a proposal deck.
Whether to call us
Where we fit
You have budget approved and a date promised, and the supplier decision is still open.
Your engagement has to clear a security assessment, an architecture review board or an outsourced assessor.
You want the requirements written down properly before anyone quotes a build.
Where we are the wrong call
Your contracting rules require the supplier itself to hold a certificate, and we hold no certificates at all.
You are bidding into UK central government, where Cyber Essentials is a condition under PPN 09/14 of 2014, so confirm the current position.
You need hardening, penetration testing or vulnerability remediation on a system that is already running in production today.
You need consent, retention, deletion and a regulator-facing position, which is data protection work rather than a security review.
You need the standard, the audit and the evidence pack for accessibility, which is an engagement of its own.
You need conformance work against WCAG specifically, which is measured against that standard rather than a customer questionnaire.
You need a response clock on something already live, which is a support arrangement rather than a one-off review.
Before you send the questionnaire
The six things people ask us before they ask us for anything else.
What do I tell our security team when you have no SOC 2?
- Tell them we engineer systems that pass your audits and document design intent in the TRS so your compliance team can verify it, and that the AICPA's own journal says compliance is a term never used in SOC 2 examinations.
- If your rules require a certified supplier, we will say so upfront and refer you.
How long does it take you to answer a security questionnaire?
Our security team will find things. What happens then, and who fixes them?
- Each one gets an owner, a remediation date and a written note of what is left, which is what your risk function needs in order to accept residual risk.
- UC Berkeley publishes a CISO exception path for exactly this, so a finding routes the deal rather than ending it.
- We fix what is ours in the build, and we tell you plainly when something is not.
Will you sign our contract as it is, or are you going to redline it?
Who are your subprocessors, and where does our data physically sit?
- If you have your own Git hosting, cloud accounts and storage, we work inside them.
- If you do not, we provision them, set them up and hand you the keys, so residency is your choice and stays under your control.
- Our team works from Vadodara, India.
Who owns the code and the documentation when we are done?
Send us your review
Send the questionnaire, the gate list, or the date you have promised somebody. Two outcomes, and both are useful to you.
Either we take the questionnaire and the document list off your desk, or we read it and tell you in one reply that this is not our work and who to ask instead. If your rules need a certified supplier, that is the reply you will get, and you will get it before you have spent a month finding out.
Tell us what your review asks for and what date you are working to. On request, a technical person joins within one business day.
No badge. Just the file your review opens with.

- What you send stays private
- A technical person answers
- No proposal deck
- We say no when it is not our work