How to run an LMS vendor security assessment — SIG and CAIQ questionnaires, SOC 2 and ISO 27001 scope, DPAs, pen-test attestations, and exit terms.
Got an LMS decision on your plate?
45-minute call. Plain-English audit. Fixed-price quote if there's a fit, or a "no" if there isn't. No deck. No pitch.
A practical SOC 2 due-diligence checklist for LMS buyers — what to ask for, what to read, and what SOC 2 doesn't cover.
How to read an ISO 27001 LMS certificate — what the ISMS covers, how scope can mislead, ISO 27001 vs SOC 2, and what stays your responsibility.
What LMS data ownership actually means in your contract, and how to keep control of training records you are legally required to produce.
An LMS vendor security assessment is the process your security and procurement teams run before handing a third party the personal data and compliance records of your workforce. Done well, it is not a formality: it is how you find out whether a vendor's marketing claims survive contact with a signed contract and an audited report. Done as a checkbox, it leaves you carrying risk you never actually evaluated.
This guide lays out a practical LMS vendor security assessment for a mid-market organization: the questionnaires to send, the reports and certificates to read (and how to read their scope), the contractual terms that matter, and how ownership changes the amount of assessment work you have to do. It is general guidance, not legal advice; your counsel should own the contractual language.
Rather than inventing your own list, lean on an industry-standard questionnaire. Two are widely used:
Sending a recognized questionnaire does two things. It gets you comparable answers across vendors, and it tells you how mature a vendor is by how readily they can complete one. A vendor that already has a filled SIG or CAIQ on hand has been through this before. A vendor that stalls on basic control questions is telling you something.
Almost every SaaS LMS will say it is SOC 2 compliant. The badge is the start of the conversation, not the end. Ask for the actual report under NDA and read it, because the details decide whether it means anything for your data:
Our SOC 2 due-diligence checklist for LMS buyers walks through reading a report line by line if you want the deeper version.
If a vendor holds ISO 27001, ask for the certificate and, importantly, the Statement of Applicability. ISO 27001 certifies an information security management system, but the certificate applies only to a defined scope. A vendor can be certified for its corporate operations while the specific platform or data center holding your training data sits outside that scope. The certificate names the certification body and the scope statement; both are worth reading rather than trusting the logo. Our guide to what ISO 27001 certification of an LMS means covers how to interpret scope and why it matters.
Security controls are only half the assessment. The contract is where obligations become enforceable.
Have your counsel confirm:
Use a simple structure to keep vendors comparable rather than assessing each in isolation.
The table is a filter, not a verdict. It surfaces which vendors are worth the deeper read and which are not.
Here is the structural point most buyers miss: much of vendor security assessment exists because you are trusting a chain of third parties you do not control. A typical SaaS LMS sits on a stack of sub-processors, each of which your security team must, in principle, vet and re-vet.
When you own your platform outright (a bespoke build or Moodle Workplace you host yourself), that chain gets much shorter. There are fewer external sub-processors touching your workforce data, the hosting and region are your choice, and the controls (encryption, access, logging, patching cadence) are configured and operated inside your own environment rather than accepted from a vendor. You still assess your build partner and your hosting provider, but you are no longer inheriting an entire chain of parties whose roadmaps and sub-processor changes you cannot influence. This is a core part of the case for owning rather than renting your LMS: the platform you control is the platform you can actually assess and prove.
A good assessment does more than approve or reject a vendor. It tells you how much residual risk each option leaves on your books. For many mid-market organizations, the least-risk answer is not the vendor with the best questionnaire, but the platform where far fewer third parties touch the data at all.