> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Responding to a VISO TRUST Request: Vendor's Guide

> A guide for vendors and third parties who have received a security assessment request through VISO TRUST — what to prepare, how to respond, and what happens next.

You've received a request to complete a security and risk assessment through VISO TRUST — the third-party risk platform used by the organization assessing you. The good news: it isn't a 300-question spreadsheet. In most cases you simply upload the security documents you already have (such as your SOC 2 or ISO 27001 report) and VISO TRUST's AI reads them for you.

This guide walks through the process end to end. It usually takes 10–20 minutes.

## Before You Start

Have these on hand:

* **The invitation email** containing your secure collection portal link and one-time passcode
* **Your current security, privacy, compliance, resilience, and related risk documentation** — provide whichever materials are available and relevant to your organization and services. Examples include:
  * Independent assurance reports and certifications (e.g., SOC 1/SOC 2, ISO certifications and Statement of Applicability)
  * Penetration testing, vulnerability assessment, or other independent security testing reports
  * PCI DSS RoC/AoC or other industry/regulatory attestations
  * Information security, data protection, privacy, and compliance policies
  * Business continuity, disaster recovery, incident response, and operational resilience documentation
  * Artificial intelligence governance, security, or responsible AI policies
  * Cyber insurance certificates
  * BAAs, DPAs, or other relevant data protection/security agreements
  * Architecture, network, or data-flow diagrams
  * Risk assessments, security assessments, or audit reports
  * Any other documentation that demonstrates your security, privacy, compliance, AI governance, or resilience controls

**You do not need to provide every item listed above — share the documentation you currently have that is relevant to the services being assessed.**

<Tip>
  Don't have artifacts to provide — no reports, policies, or white papers? You can answer a questionnaire instead. The portal offers this option when you respond.
</Tip>

## Step-by-Step

<Steps>
  <Step title="Open your invitation">
    You'll receive an email with a secure link and passcode to your collection portal. Select **Respond to Request** to begin. VISO TRUST also sends reminder emails while the request is open.

    If you can't find the email, check your spam folder or ask your contact at the requesting organization to resend it.

    <img src="https://mintcdn.com/visotrust/mnoXd6Qjx86ZVkr7/images/Screenshot-2026-09-09-at-11.10.31-PM.png?fit=max&auto=format&n=mnoXd6Qjx86ZVkr7&q=85&s=508839a4f854cee64956397a62a506d7" alt="VISO TRUST assessment request email showing the one-time passcode and the Respond to Request button" width="1596" height="1484" data-path="images/Screenshot-2026-09-09-at-11.10.31-PM.png" />
  </Step>

  <Step title="Enter the collection portal">
    The **Welcome** page names the organization assessing you and summarizes what's being requested — the specific documents and any questions. There's no long questionnaire to fill in by hand. Select **Get started** to continue.

    A sidebar tracks your progress through the four stages: **Welcome**, **Upload artifacts**, **Provide information**, and **Submit**.

    <img src="https://mintcdn.com/visotrust/mnoXd6Qjx86ZVkr7/images/Screenshot-2026-09-09-at-11.20.26-PM.png?fit=max&auto=format&n=mnoXd6Qjx86ZVkr7&q=85&s=a2f2ff54e0af9baa9515e7b96be981fb" alt="Collection portal Welcome page with a Get started button and links to forward the request or opt out" width="2880" height="1300" data-path="images/Screenshot-2026-09-09-at-11.20.26-PM.png" />

    If the request is due to expire within a week, you'll see a **Need more time** option. Select it to extend the request by an additional week.
  </Step>

  <Step title="Upload your documents">
    On **Upload artifacts**, add each requested item by dragging and dropping a file or selecting **select files**. Each artifact type shows examples of what qualifies — hover an item such as **Third party audits** to see them. Each document is analyzed automatically once uploaded, so you don't answer questions the documents already cover.

    <img src="https://mintcdn.com/visotrust/mnoXd6Qjx86ZVkr7/images/Screenshot-2026-09-09-at-11.23.14-PM-1.png?fit=max&auto=format&n=mnoXd6Qjx86ZVkr7&q=85&s=aaf4b62705ae63db80d07a7e214c2ca7" alt="Upload artifacts page listing requested artifact types with a tooltip showing third-party audit examples" width="2922" height="792" data-path="images/Screenshot-2026-09-09-at-11.23.14-PM-1.png" />
  </Step>

  <Step title="Handle anything you don't have">
    You can't leave a request blank. For any document you don't have or can't share, mark the attestation that you do not have, or will not provide, that item — this lets the assessment proceed.
  </Step>

  <Step title="Answer any additional questions">
    On **Provide information**, answer any questions the requesting organization included. All questionnaires appear on a single page, organized into sections, with a navigation panel showing each section's progress. Complete all required questions before submitting — if any are missing, the portal jumps you to the first unanswered question.
  </Step>

  <Step title="Certify and submit">
    On **Submit**, certify that the information you've provided is accurate and submit. This records your formal attestation and time-stamps it.
  </Step>

  <Step title="What happens next">
    **Follow up Questionnaires:** If controls remain unvalidated after initial review, a client may send a focused follow-up questionnaire — a few targeted questions, not a full re-do. All questionnaires in the request appear on a single page, organized into sections — the standard VISO TRUST questionnaire followed by any supplemental questionnaires. A navigation panel beside the questions lists each section with its answered count and progress, and highlights the section currently in view. <br />If any responses are missing, the portal jumps to the first unanswered question so the vendor can fill in the gaps. <br />The portal shows a Certify and Submit page in the end.

    **Remediation Request**: If more information/artifacts are required, a client may send a remediation request. You receive an email from VISO TRUST with link and passcode and the remediation request(s) listed and the target due date. You'll receive the remediation email again 30 days before the target due date. Once you submit the required information, you're done.
  </Step>
</Steps>

## If You're Not the Right Person

Two options are available from the **Welcome** page:

* **Forward the request** — send it to the right colleague. They receive a new email with their own secure link and passcode.
* **Opt out** — use this only if your organization is no longer doing business with the requesting organization. Opting out ends the assessment and can't be undone.

## What Happens Next

**Follow-up questionnaires.** If controls remain unvalidated after the initial review, the requesting organization may send a focused follow-up questionnaire — a few targeted questions, not a full re-do. You typically have 7 days to respond. The portal experience is the same as the initial request.

**Remediation requests.** If specific control gaps need to be closed, the requesting organization may send a remediation request. You'll receive an email from VISO TRUST with a link, a passcode, the requested items, and a target due date, plus a reminder 30 days before that date. Once you submit the required information, you're done.

## Quick FAQ

**Do I need a password or account?** No account is needed. Access is through the secure link and passcode provided in your invitation email — just follow the portal's prompts.

**Which documents should I send?** Whatever the request lists — commonly a SOC 2 or ISO 27001 report, a pen test summary, key policies, and insurance. Provide what you have and attest for what you don't.

**Our documents are confidential.** Uploads go through a secure portal, and VISO TRUST maintains strict data protection practices:

* **Encryption** — all data is encrypted in transit and at rest using industry-standard protocols.
* **Access control** — only authorized personnel can access your data, governed by strict access controls to prevent unauthorized use or sharing.

Information submitted is subject to the terms and conditions of VISO TRUST's [Vendor Agreement](https://visotrust.com/vendor-agreement/).

**We don't have a SOC 2.** That's fine — provide the equivalent evidence you do have (e.g., ISO 27001, third-party independent audit reports, policies).

**Who sees our information?** Your submission goes to the requesting organization's team via VISO TRUST.

**How long does it take?** Usually 10–20 minutes if your documents are to hand.

**I'm not the right person to answer this.** Forward the request to a colleague directly from the portal. The updated recipient receives a new email with their own access.

**Need help?** For portal or technical issues, contact VISO TRUST support at [support@visotrust.com](mailto:support@visotrust.com). For any other questions, contact your point of contact at the requesting organization.

## Related Pages

* [Assessments](/third-parties/assessments) — how the requesting organization runs the assessment
* [Questionnaire Answering](/trust-and-questionnaires/questionnaire-answering) — more detail on the collection portal and follow-up questionnaires
* [Trust Profiles](/trust-and-questionnaires/trust-profiles) — keep your documentation in one place so future requests answer themselves
