VSAQ (Vendor Security Alliance Questionnaire)
VSAQ commonly refers to the Vendor Security Alliance questionnaire, available as VSA-Full and VSA-Core for standardized vendor security reviews.
Definition
VSAQ commonly refers to the Vendor Security Alliance questionnaire, a standardized assessment for reviewing a vendor's security and privacy practices. The Vendor Security Alliance publishes VSA-Full and VSA-Core versions. A separate archived Google project also uses VSAQ to mean Vendor Security Assessment Questionnaire, so buyers and vendors should confirm the publisher and version before responding.
Context
The Vendor Security Alliance describes VSA-Full as its deeper security questionnaire and VSA-Core as a shorter set of key security and privacy questions. The public VSA materials show dated versions, so teams should record the exact file, publisher, and release date they received instead of assuming that every document labeled VSAQ is interchangeable. Google's open-source VSAQ application supported third-party security reviews, but its repository was archived on November 25, 2022 and is not an official Google product.
Why it matters
The acronym is ambiguous in older security-review material. The Vendor Security Alliance questionnaire is an assessment instrument published by the VSA. Google's similarly named VSAQ is questionnaire software with bundled templates, not the same publisher or questionnaire. A reliable intake process preserves the original filename and source URL so reviewers know which artifact they are answering.
Before reusing a prior response, compare the questionnaire version, scope, and requested evidence. Security, privacy, software-supply-chain, and compliance questions can change between releases, and a buyer may modify the original workbook. Reuse should start from approved source material and then be reviewed against the exact received file.
VSAQ, SIG, CAIQ, and buyer-authored questionnaires overlap, but they are not substitutes for one another. Record the instrument and version, map each answer to current evidence, identify the responsible owner, and preserve reviewer changes. That produces a defensible response history without claiming that one questionnaire proves complete vendor security.
Reviewed primary sources
The definition above distinguishes the current publishers and artifacts using these primary sources.