Join our Newsletter — 33% off our NHI Course

SIG Core

SIG Core is the deeper Shared Assessments questionnaire used to evaluate third parties that store or manage sensitive or regulated information. It is designed to reveal how a vendor secures data, supports services, and maintains control maturity. Teams use it when simple due diligence is not enough to understand material risk.

Expanded Definition

SIG Core is a structured third-party assessment questionnaire used to examine how a supplier protects sensitive or regulated information, supports service delivery, and demonstrates control maturity. In practice, it sits between lightweight due diligence and a full on-site audit, giving security, risk, procurement, and compliance teams a deeper view into operational safeguards. Unlike a simple yes or no vendor checklist, SIG Core is meant to surface how controls are implemented, evidenced, and governed across business, technology, and oversight functions. That distinction matters because organisations often need more than policy statements to judge whether a third party can safely handle material data or critical services. Its use is broadly aligned to control-based evaluation approaches such as NIST SP 800-53 Rev 5 Security and Privacy Controls, although SIG Core is a questionnaire, not a control framework. Usage in the industry is still evolving, and different organisations may tailor the scope, scoring, and evidence thresholds to their own risk models. The most common misapplication is treating SIG Core as a pass or fail certification, which occurs when teams accept questionnaire responses without validating evidence, ownership, or remediation commitments.

Examples and Use Cases

Implementing SIG Core rigorously often introduces review burden and follow-up effort, requiring organisations to weigh better risk visibility against slower vendor onboarding and more detailed evidence collection.

  • A financial services firm uses SIG Core to assess a payment processor that stores customer records, comparing the vendor’s answers to internal risk appetite before contract approval.
  • A healthcare organisation sends SIG Core to a SaaS provider that processes regulated data to understand incident response, access governance, subcontractor oversight, and data retention practices.
  • A procurement team uses SIG Core during renewal for a critical outsourcing partner to determine whether prior assurances still match the supplier’s current control maturity.
  • A security team maps questionnaire responses to internal requirements inspired by NIST control expectations to spot gaps in logging, recovery, and privileged access handling.
  • A risk manager uses SIG Core to compare multiple vendors consistently when the same service is offered by different providers with different security architectures and operating models.

Because SIG Core is evidence-driven, the value comes from how teams interpret the answers, not from the questionnaire alone. Organisations often pair it with contracts, attestations, and targeted follow-up interviews when a vendor’s response is incomplete or ambiguous.

Why It Matters for Security Teams

SIG Core matters because third-party risk is rarely visible from marketing claims or high-level security summaries. For security teams, the questionnaire provides a repeatable way to evaluate whether a supplier can actually maintain confidentiality, integrity, availability, and governance over sensitive information. It is especially useful where a vendor becomes part of a broader trust chain, such as hosting regulated workloads, processing customer data, or supporting identity-related operations. That makes SIG Core relevant to identity and access decisions as well, since vendors that manage credentials, authentication services, or privileged workflows can create downstream exposure if their controls are weak. Teams should also remember that a questionnaire does not replace continuous monitoring, and it cannot prove that controls are working unless the responses are tested against evidence. For that reason, the most effective use of SIG Core is as part of a broader third-party lifecycle that includes onboarding, periodic reassessment, contractual enforcement, and remediation tracking, alongside sources such as NIST SP 800-53 Rev 5. Organisations typically encounter the operational impact of SIG Core only after a vendor issue, audit request, or breach investigation, at which point the questionnaire becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022, DORA and NIS2 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 ID.SC-4 NIST CSF addresses supplier risk management and third-party dependencies.
NIST SP 800-53 Rev 5 SA-9 NIST SP 800-53 covers external system services and supplier control expectations.
ISO/IEC 27001:2022 A.5.19 ISO 27001 includes information security in supplier relationships.
DORA Article 28 DORA formalises ICT third-party risk oversight for financial entities.
NIS2 Article 21 NIS2 requires risk management and supply-chain security measures.

Use SIG Core results to document supplier risks, oversight gaps, and remediation actions in your supply chain program.