Guides

RFPs, DDQs & security questionnaires, explained

Practical guides to how these processes work, the frameworks behind them, and how to respond faster without sacrificing accuracy.

Due diligence

What is a DDQ (due-diligence questionnaire)?

A due-diligence questionnaire (DDQ) is a structured document one organisation sends another to evaluate it before a deal, investment, or partnership. It gathers standardised information on operations, finances, security, compliance, and risk, so the requester can make an informed decision and document why they trusted the other party.

Read the guide
Due diligence

DDQ vs RFP: what is the difference?

A DDQ and an RFP are both structured documents full of questions, which is why they get confused, but they answer different questions for the sender. A DDQ (due-diligence questionnaire) is about trust: is this organisation safe to work with? An RFP (request for proposal) is about selection: which product should we buy? The overlap is real, and one good answer library can serve both.

Read the guide
RFPs

RFP vs RFI vs RFQ: what is the difference?

An RFI, RFQ, and RFP are three procurement documents used at different stages of a buying process. An RFI (request for information) gathers early market and vendor information. An RFQ (request for quotation) compares price for well-defined requirements. An RFP (request for proposal) asks vendors to propose how they would solve a need, scored on more than price alone.

Read the guide
RFPs

The RFP response process: a step-by-step guide

An RFP (request for proposal) response is a structured reply to a buyer's formal request that shows how your product meets their requirements, terms, and pricing. A repeatable process, from a clear bid or no-bid decision through drafting against a content library to a reviewed, on-time submission, lets a small team win more bids without adding headcount.

Read the guide
RFPs

How to build an RFP content library

An RFP content library is a maintained, reusable store of approved answers to the questions that recur across RFPs, DDQs, and security questionnaires. Instead of rewriting standard responses each time, your team searches the library, reuses the best current answer, and adapts it, so responding becomes matching rather than writing from scratch.

Read the guide
RFPs

The bid/no-bid decision: when to respond to an RFP

The bid/no-bid decision is a deliberate go or no-go call your team makes before investing in an RFP response. It weighs fit, the realistic chance of winning, the value of the deal, and whether you have the capacity to do it well, so effort goes to the opportunities you can actually win.

Read the guide
Security questionnaires

How to respond to security questionnaires faster

A security questionnaire is a structured set of questions a customer's security or procurement team sends to check how you protect their data before they buy. The way to answer them faster is to stop starting from scratch: keep your approved answers in one reusable library, map them to the common frameworks like SIG and CAIQ, and verify each reused answer against its source before it goes out.

Read the guide
Security questionnaires

SIG vs CAIQ vs VSAQ: the security questionnaires explained

SIG, CAIQ, and VSAQ are the three standard security questionnaires you are most likely to be handed. SIG is the broad, all-industries one, CAIQ is the cloud-specific one, and VSAQ is the lighter, engineer-friendly one. They overlap a lot, so a single well-written answer can usually satisfy all three if you map it carefully.

Read the guide
Security questionnaires

Vendor security assessment checklist

A vendor security assessment checks that a supplier protects your data well enough to be trusted with it. A good checklist works in two directions: it tells the buyer what to request and verify before onboarding, and it tells the vendor what to have ready so the review does not stall. The areas below cover what most assessments examine.

Read the guide
Compliance

SOC 2 vs ISO 27001: what is the difference?

SOC 2 and ISO/IEC 27001 are the two attestations customers ask for most when they want proof you handle data securely. The short version: SOC 2 is an audit report on your controls, written for the US market, while ISO 27001 is a certification of your information security management system that is recognised worldwide. Many companies end up with both.

Read the guide
Compliance

ISO 27001 readiness checklist: how to prepare for certification

ISO 27001 certification is less about a single audit and more about standing up an information security management system (ISMS) and proving it runs. This checklist walks the work in order: define scope, assess risk, write the Statement of Applicability, implement controls and policies, gather evidence, run an internal audit, then pass the Stage 1 and Stage 2 audits.

Read the guide
Compliance

SOC 2 for startups: a practical guide

For most startups, SOC 2 is the first compliance report a customer asks for, usually right when a bigger deal is on the line. This guide covers what SOC 2 means for a small team, whether to start with Type I or Type II, the practical steps to get there, realistic cost and timing, and the mistakes that slow startups down.

Read the guide
Compliance

GDPR compliance for SaaS: a practical guide

The GDPR governs how you process the personal data of people in the EU and UK. For a SaaS company it means having a lawful basis for processing, honouring data-subject rights, securing the data you hold, managing your processors under Article 28, and being able to demonstrate all of it. This guide covers the essentials.

Read the guide
Compliance

HIPAA compliance for software vendors

HIPAA is the US law that protects health information. If your software touches protected health information (PHI) on behalf of a healthcare customer, you are usually a business associate, and you take on the Security Rule safeguards, a business associate agreement, and a documented risk analysis. This guide covers what that means in practice.

Read the guide
Compliance

PCI DSS compliance, explained

PCI DSS is the security standard for any organisation that stores, processes, or transmits payment card data. It sets requirements across network security, data protection, access control, and monitoring. How you validate depends on your card volume: a Self-Assessment Questionnaire for smaller volumes, or an audit by a Qualified Security Assessor for larger ones.

Read the guide
Compliance

The NIST Cybersecurity Framework, explained

The NIST Cybersecurity Framework (CSF) is a voluntary, widely used way to organise and improve how you manage cybersecurity risk. Version 2.0 groups the work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is outcome-based, so you use it to assess maturity and prioritise improvement rather than to pass a fixed test.

Read the guide
Compliance

ISO 42001, the AI management standard, explained

ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). It is the governance equivalent of ISO 27001, but for organisations that build or use artificial intelligence. Rather than testing a fixed checklist, it certifies that you run a managed, repeatable process for developing and using AI responsibly.

Read the guide
Compliance

ISO 27017 and ISO 27018: cloud security and privacy, explained

ISO 27017 and ISO 27018 are the cloud extensions to ISO 27001. ISO 27017 adds cloud-specific security controls and guidance; ISO 27018 adds controls for protecting personal data (PII) in public clouds. Both build on an ISO 27001 management system rather than replacing it, so they are usually pursued alongside or just after ISO 27001.

Read the guide
Compliance

ISO 22301 and business continuity, explained

ISO 22301 is the international standard for a business continuity management system (BCMS). It certifies that you run a managed, repeatable process for keeping your priority activities going through disruption: understanding what matters most, setting recovery objectives, and putting strategies, plans, and exercises in place to meet them.

Read the guide
Compliance

DORA, explained

DORA, the EU Digital Operational Resilience Act, sets harmonised rules for the digital resilience of EU financial entities and their critical ICT providers. It has applied since January 2025 and is built on five pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing.

Read the guide
Compliance

Cyber Essentials, explained

Cyber Essentials is the UK government-backed scheme, run under the NCSC, built on five technical controls that protect against the most common internet-based attacks. Base Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent, hands-on technical audit of the same five controls.

Read the guide
Compliance

The CCPA and CPRA, explained

The CCPA, as amended by the CPRA, is California privacy law. It gives California consumers rights over their personal information and places obligations on the businesses that handle it. It is not a certification but a law, so the goal is operationalised rights and demonstrable accountability rather than a certificate.

Read the guide
Compliance

NIST 800-53, explained

NIST SP 800-53 is the US federal catalogue of security and privacy controls. It is not a certification but a control set: federal systems select a baseline based on impact level, then implement and assess those controls under the Risk Management Framework. It also underpins the FedRAMP baselines for cloud services.

Read the guide
Compliance

NIST 800-171 and CMMC, explained

NIST 800-171 sets the requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. CMMC is the US Department of Defense programme that verifies contractors meet them. In short, 800-171 is the control set, and CMMC is the certification built on top of it for the defense supply chain.

Read the guide
Compliance

FedRAMP, explained

FedRAMP is the US government programme that standardises how cloud services are assessed and authorised for federal use. It is built on NIST 800-53 baselines, requires assessment by an accredited 3PAO, and imposes ongoing continuous monitoring. It is an authorisation granted by the government, not a self-declared certificate.

Read the guide
Compliance

HITRUST CSF, explained

HITRUST CSF is a certifiable security framework, widely used in US healthcare, that harmonises HIPAA, ISO 27001, NIST, and other standards into one prescriptive control set. It is often requested because a HITRUST certification gives independent assurance that HIPAA-relevant controls are genuinely in place.

Read the guide
Financial regulation

BSA/AML, explained

BSA/AML is the US anti-money-laundering regime: the Bank Secrecy Act (31 U.S.C. 5311 and following) and its implementing rules in 31 CFR Chapter X. Covered institutions must run a written AML programme with a designated officer, internal controls, training and independent testing, verify who their customers are, monitor transactions, and report suspicious and large cash activity.

Read the guide
Financial regulation

The FATF 40 Recommendations, explained

The FATF 40 Recommendations are the international standard for anti-money-laundering and counter-terrorist financing. FATF is an intergovernmental body, not a legislature, so the Recommendations are not directly binding on firms. Countries write them into national law, and FATF then assesses how well each country has done through peer mutual evaluations.

Read the guide
Financial regulation

MiFID II and MAR, explained

MiFID II (Directive 2014/65/EU) and MiFIR govern how investment firms and trading venues operate in the EU: how clients are treated, how orders are executed, and what has to be reported. MAR (Regulation 596/2014) sits alongside them and governs market integrity: insider dealing, unlawful disclosure of inside information, and market manipulation.

Read the guide
Financial regulation

Consumer credit and fair lending, explained

Consumer credit compliance is the set of rules governing how you advertise, underwrite, price, service and collect consumer loans, and fair lending is the part that forbids discrimination in any of it. In the US the core is ECOA, TILA, FCRA, HMDA, the prohibition on unfair, deceptive or abusive acts, and the debt-collection rules.

Read the guide
Due diligence

Third-party risk management (TPRM): a practical guide

Third-party risk management (TPRM) is how an organisation assesses and keeps an eye on the outside vendors it depends on, so that a supplier's weakness does not quietly become its own. It usually runs as a lifecycle: screen a vendor before onboarding, assess them with questionnaires and evidence, set the right contract terms, and then re-check them on a schedule.

Read the guide

Comparing tools, not just processes?

See how the major RFP and questionnaire platforms stack up on pricing, AI accuracy, and data residency in the comparison hub, or look up a term in the glossary.