SIG Lite
SIG Lite is a shortened version of the Standardized Information Gathering (SIG) questionnaire developed by the Shared Assessments Program to evaluate a vendor's cybersecurity, privacy, and related risk practices. It provides a broad, high-level view of a third party's controls using fewer questions than the full SIG, making it well suited for lower-risk vendors or an initial assessment. Organizations often use it to streamline vendor risk reviews when a comprehensive deep-dive is not required.
SIG Lite is a streamlined third-party risk assessment questionnaire maintained by the Shared Assessments Program that consolidates the core domains of the standard (Core) SIG into a reduced set of questions, cited in the evidence as approximately 126 questions, to obtain a broad, program-level view of a vendor's security, privacy, and ESG posture. It is typically applied to vendors assessed as less risky or as a scoping and triage step, with escalation to the fuller SIG Core when deeper, control-level assurance is warranted. The specific question count and applicability may vary by version and by the assessing organization's risk criteria, and SIG Lite supports risk evaluation but is one input to a broader third-party risk management process rather than a standalone assurance or certification.
Why it matters
Third-party risk has become a central concern for security leaders because vendors, suppliers, and service providers frequently have access to sensitive data or systems, yet the assessing organization retains accountability for how that risk is managed. SIG Lite matters because it gives organizations a practical way to gain a broad, high-level view of a vendor's security, privacy, and related practices without imposing the full burden of the more comprehensive SIG Core questionnaire. For lower-risk vendors or for an initial triage step, this can make vendor risk reviews faster and more scalable across a large third-party portfolio.
The trade-off is that breadth comes at the cost of depth. SIG Lite provides a program-level snapshot rather than control-level assurance, so relying on it alone for a high-risk or data-intensive vendor may leave meaningful gaps unexamined. A common expert correction is to treat a completed SIG Lite as evidence of certification or guaranteed control effectiveness; it is not. It is one input into a broader third-party risk management process, and its value depends on the honesty of the responding vendor, the appropriateness of the risk tier assigned, and the assessing organization's follow-up on responses that warrant escalation.
For security leaders, including those serving in a virtual or fractional CISO capacity, SIG Lite is useful as part of designing a tiered vendor assessment approach: matching assessment depth to assessed risk rather than applying a single heavyweight questionnaire to every vendor. Used well, it helps allocate limited assessment effort where it matters most; used carelessly, it can create a false sense of assurance.
Who it's relevant to
Inside SIG Lite
Common questions
Answers to the questions practitioners most commonly ask about SIG Lite.