The practical answer

Describe the data and service being purchased, then request evidence about access, storage, support, recovery and deletion that applies to that scope. Assign qualified internal reviewers to assess the responses and record customer responsibilities as well as vendor controls.

Benefits reporting can involve employee identifiers and family enrollment information. A useful security questionnaire follows that information through the service and asks how the employer's chosen workflow is protected. The questions below are an original evaluation tool informed by NIST guidance, not a certification, legal determination or claim about a particular provider.

Define the data, users and service boundary

List the information the employer intends to provide: employee identity, employer context, offer facts, contributions and covered-person enrollment where applicable. The 2025 C-series instructions help identify the reporting fields, but the purchased service may also receive import files, support attachments and historical exports beyond the final form.

Draw the actual path from source export to upload, application review, transmission service, recipient handling and retained records. Identify other providers involved. Ask which parts are operated directly by the vendor and which depend on another service.

NIST SP 1300 emphasizes inventorying and classifying data and assessing supplier risks. Begin the questionnaire with that scope so the security reviewer can judge relevant evidence. A general corporate policy may not describe the particular application or support process being purchased.

Ask for evidence and assign a reviewer

ACA software security questionnaire excerpt
QuestionEvidence requestedInternal reviewer
Who can access employer and employee records?Role model, scoped demonstration and access review process.Security and benefits operations.
How is account access protected?Authentication options and required customer configuration.Identity or IT owner.
How are files protected during transfer and storage?Architecture description and relevant control evidence.Security reviewer.
When can support personnel view customer data?Access approval, attribution and support-file handling procedure.Security and service owner.
How are records retained and deleted?Schedule covering active data, exports, attachments and backups.Privacy or records reviewer.
How is service restored after disruption?Recovery commitments and relevant test evidence.Continuity or IT reviewer.
How are incidents communicated?Contractual process, contacts and responsibility allocation.Security and legal reviewers.

Add response date, applicable service, evidence period, limitations and unresolved questions to each row. Keep sensitive vendor evidence in the authorized review location.

Evaluate access in the purchased workflow

Ask whether authentication controls apply to administrators, ordinary users, support personnel and integrations. Record which protections the vendor enforces and which the customer must configure. A capability that is available but disabled in the purchased setup is a different result from an enforced control.

NIST's guide recommends restricting sensitive access to those who need it and using multifactor authentication where available. Turn those principles into a scoped demonstration: an authorized test user can inspect the intended employer, while a restricted user cannot perform a disallowed action through the normal workflow.

Ask how access is removed when a person changes roles or leaves. Include exported files and support attachments in the discussion, since removing application access does not necessarily remove copies already downloaded to another approved location. Assign the employer's part of that process explicitly.

Worked example: two different deletion periods

Fictional example: a vendor response says uploaded source files are removed from active storage 30 days after account closure, while backup copies age out after 90 days. The employer's reviewer initially records data deleted after 30 days. That summary omits a 60-day difference between the two stated periods.

The reviewer asks which data categories each statement covers, what access remains possible during backup retention, how a restoration affects deletion, and what evidence of completed removal is available. They also ask whether generated forms and support attachments follow either period or a separate schedule.

The outcome is a clarified data-lifecycle record, not a declaration that either period is inherently compliant or noncompliant. The employer's records and legal reviewers assess the agreed terms against applicable requirements. Before closure, operations separately verifies that necessary historical evidence has been exported and can be retrieved.

Read assurance documents in context

When a vendor offers an independent report or assessment, ask the reviewer to confirm the service scope, period covered, exceptions and customer responsibilities. A document covering a different product or an earlier operating model may need additional evidence. Record what was reviewed and what it actually supports.

Distinguish a policy, a contractual commitment, a configuration screenshot and a completed test record. They answer different questions. A recovery policy describes intended practice; relevant test evidence helps assess whether that practice was exercised. Do not mark a test completed merely because a plan exists.

Route legal applicability questions to the employer's qualified reviewer. Do not assume that a familiar acronym applies identically to every benefits reporting service. The questionnaire's job is to collect scoped evidence and identify responsibilities, not to invent a blanket compliance conclusion.

Close the review with conditions and accountable owners

Summarize accepted evidence, unresolved items and required customer settings. For each condition, identify who will configure or verify it and when the implementation can rely on it. If the employer accepts a limitation, record the decision and operating procedure through its normal review process.

Connect the results to the implementation plan. Authentication setup, access scopes, approved upload methods and historical exports should become actual tasks. Preserve the vendor's relevant responses and the employer's review decisions together.

Keep a clear contact path for security questions and service incidents after launch. Revisit the affected questionnaire items when the service boundary, data types or vendor arrangements change. A completed procurement questionnaire describes a reviewed point in time; it does not remove the need to manage later changes.

Follow benefits data through the vendor review

Follow benefits data through the vendor review: Source and upload; Application and support; Processing and retained copies; Exit and recovery
Conceptual review map. The actual service boundary and applicable requirements must be established for the employer's purchase.
Read the workflow as text
  1. Source and upload. Identify the facts, files, transfer path and authorized sender.
  2. Application and support. Review user scope, authentication and support access.
  3. Processing and retained copies. Identify downstream providers, outputs, attachments and backups.
  4. Exit and recovery. Clarify export, deletion, restoration and incident responsibilities.

Put this guide to work

ACA software security evidence questionnaire

Save the editable text worksheet and use it with your own records. Keep completed copies in your secure working files.

Download the worksheet TXT

Common questions

Is this questionnaire a security certification?

No. It is an evidence collection and review tool. The employer's responsible reviewers must assess the responses, scope and limitations. Completing the rows does not certify a vendor or establish compliance with every applicable requirement.

Should we request the same evidence for every provider?

Use a consistent core, then tailor it to the service and data path. A provider that handles recipient delivery or support attachments may introduce different questions from a tool used only for a controlled preview.

Does a policy prove that a control was tested?

No. A policy states intended practice. A test record, configuration demonstration or independent assessment supplies different evidence. Record the evidence type and what it supports instead of treating them as interchangeable.

Who decides how long historical records must be kept?

The employer's records, reporting and legal reviewers should establish the applicable requirements and policies. Ask the vendor what it actually retains and deletes, then reconcile those terms with the employer's decision.

What happens after the security review is accepted?

Translate customer responsibilities into implementation tasks, verify the relevant settings and retain the evidence and decisions. Revisit affected questions when the service, data scope or provider arrangements change.

Official sources and scope

Sources checked September 5, 2026. Use the edition for the tax year and filing method you are working with; later instructions may change thresholds, fields, or procedures.

  1. NIST SP 1300, Small Business Quick-Start Guide

    Supplier assessment, data inventory, access restrictions, multifactor authentication, backup testing and incident planning; February 2024.

  2. IRS 2025 Instructions for Forms 1094-C and 1095-C

    Reporting field context for identifying the benefits data in scope.