SaaS review can become a contest to see who owns the longest questionnaire. Length does not rescue a question that does not affect the decision. Start with the use, then request evidence proportionate to the risk. NIST SP 1326 provides a compact, risk-based set of supplier due-diligence questions for that purpose.

Run the assessment

WORKBOOK

SaaS security assessment workbook

Scope the proposed service, set the risk tier, inventory evidence, assess architecture, data, identity, encryption, logging, development, vulnerabilities, incidents, resilience, privacy, contracts, and exit planning, then assign follow-ups and document the decision.

Download workbook
  1. Scope the proposed use. Record business context before requesting vendor evidence.
  2. Work through the evidence. Follow How to evaluate a new vendor's security for the complete process.
  3. Keep the method consistent. Use the security review methodology for evidence states, limitations, tiering, and decisions.
  4. Preserve citations and gaps. A blank answer remains pending. It does not become a pass because the deadline arrived.

Supply the business context

Record intended use, data flows, users, sensitivity, exposure, privileges, criticality, compensating controls, risk appetite, contracts, and decision ownership. These facts determine which checklist items are deal breakers and which are merely preferred.

Do not grade documents by weight

A SOC 2 report can offer disciplined CPA audit evidence that controls were implemented and operating as claimed. A penetration test can show how a defined target resisted a defined exercise. Neither proves the complete system is effective for your particular threat model. Evaluate the controls, test scope, exceptions, and business fit yourself.

Make the process proportionate

Not every SaaS product needs every artifact. Use tiering based on data, privilege, exposure, integration, and criticality. The lighter path should still document why it was light. "Low risk" is a conclusion that needs a reason.

Sources and further reading

Managing repeated SaaS reviews

Can I Run That? can organize vendor evidence, citations, follow-ups, decision history, and reassessment across many reviews. Your team still defines requirements, adds business context, validates material conclusions, and owns the decision.

About Brian Semrau

Brian Semrau is an information security consultant, board-certified digital forensics examiner, and expert witness with more than 20 years of experience in security and investigations.