vendorshield-questionnaire-mcp
v1.0.0
Published
MCP server for automating security questionnaire responses — auto-answer SIG, CAIQ, and custom vendor questionnaires, map controls across frameworks, and assess vendor responses for risk gaps
Downloads
116
Maintainers
Readme
vendorshield-questionnaire-mcp
MCP server for automating security questionnaire responses. Auto-answer SIG Lite, CAIQ, and custom vendor security questionnaires. Map controls across SOC2, ISO 27001, NIST, HIPAA, PCI-DSS frameworks.
Part of VendorShield — AI-powered vendor risk management.
Tools
answer_security_question
Generate a compliance-appropriate answer to any security questionnaire question based on your organization's maturity level.
autofill_questionnaire
Auto-generate responses for a full questionnaire (SIG Lite, CAIQ, or custom) based on your organization's maturity profile across 16 security domains.
assess_vendor_responses
Review and score a vendor's questionnaire responses. Identifies gaps, calculates risk score, and generates remediation recommendations.
map_control_frameworks
Map controls across SOC2, ISO 27001, NIST CSF, NIST 800-53, HIPAA, PCI-DSS, and CIS frameworks.
questionnaire_gap_analysis
Generate a comprehensive gap analysis with phased remediation roadmap comparing current posture against target framework requirements.
Installation
npx vendorshield-questionnaire-mcpConfiguration
Claude Desktop / Cursor
{
"mcpServers": {
"vendorshield-questionnaire": {
"command": "npx",
"args": ["-y", "vendorshield-questionnaire-mcp"]
}
}
}Use Cases
- InfoSec teams: Auto-fill vendor security questionnaires in minutes instead of days
- Compliance officers: Map controls across frameworks for audit preparation
- Vendor management: Assess vendor responses and identify security gaps
- GRC platforms: Integrate automated questionnaire handling into existing workflows
- Audit prep: Generate gap analysis reports with prioritized remediation plans
Security Domains Covered
Access Control, Asset Management, Business Continuity, Change Management, Communications Security, Compliance, Cryptography, Data Protection, Human Resources, Incident Management, Operations Security, Physical Security, Risk Management, Secure Development, Supplier Relationships, Vulnerability Management
License
MIT
