DDQ Meaning: What the Acronym Stands For
DDQ stands for due diligence questionnaire. It is a document one private party sends another to verify that the second party is what it claims to be before money, data or a contract vehicle changes hands. In government contracting it usually arrives from a prime that is deciding whether to put you on a team.
The thing that makes a DDQ confusing is that it has no legal definition. There is no FAR part, no standard form, no numbering convention and no page limit. Whoever sends it decides what is in it. That is exactly why the useful question is not “what is a DDQ” but what is the sender actually trying to establish, because in federal work the answer is unusually specific and unusually checkable.
This guide covers what DDQ means and what the instrument actually is, how it differs from an RFI, an RFP and a vendor security questionnaire, who sends one and at what point in a deal, what a federal DDQ really asks for underneath the wording, the security and financial evidence to have assembled before one arrives, how long you get, why DDQ responses stall teaming deals, and how to keep an answer library that does not go stale.
The DDQ meaning that applies in government contracting is due diligence questionnaire: a structured set of questions sent by a party who is about to take on risk to a party who is about to be trusted with something. The questions ask for facts, and the facts are expected to be supported by documents.
The same three letters carry three other meanings in adjacent worlds, which is why searching for the term returns such a strange mixture of results:
- Private equity and fund management. A limited partner sends a DDQ to a fund manager before investing. The Institutional Limited Partners Association publishes a standardized version, ILPA DDQ 2.0, released 1 November 2021.
- Vendor security and procurement. A buyer sends a DDQ, often really a security questionnaire, to a software vendor before signing. This is the most common commercial use.
- Chemistry. DDQ is also 2,3-dichloro-5,6-dicyano-1,4-benzoquinone, an oxidizing reagent. It has nothing to do with any of the above and is the reason a search for the bare acronym returns a Wikipedia chemistry article.
- Government contracting. A prime, an agency or a teaming partner sends a DDQ to a company it is considering working with. This is the version this article is about, and short definitions for the terms used here are in the GovCon glossary.
All four are the same idea applied to different risks. Somebody is about to depend on you, and they want the dependency written down before they take it on.
What a Due Diligence Questionnaire Actually Is
Four properties define the instrument, and each one has a practical consequence that catches companies out.
- It has no regulatory authority. No FAR part authorizes a DDQ, no clause prescribes one, and no agency publishes a form for it. It exists because a private party asked for it. That means the sender sets the rules, including the deadline.
- It is evidence-seeking, not offer-seeking. A solicitation asks what you would do. A DDQ asks what you already are. The correct output of a DDQ is not a persuasive narrative; it is a set of attachments with a short covering answer.
- It is usually a gate, not a scoring exercise. Most DDQs are pass or fail on a handful of items and informational on the rest. One unanswerable question can stop the whole thing regardless of how strong the other forty answers are.
- It is asymmetric. You disclose; the sender does not. A DDQ is a reasonable moment to ask for a mutual nondisclosure agreement before returning anything sensitive, and it is a normal request that competent senders expect.
Because the instrument is undefined, the useful mental model is to ignore the format and look at what the sender is standing behind. A prime that puts you on a team is, in effect, telling a contracting officer that you are a responsible source. That is the pressure the DDQ is transmitting, and it is written down in the FAR even though the DDQ is not.
DDQ vs RFI: Different Senders, Different Purpose
These two get confused because both arrive as a list of questions and neither leads directly to an award. Almost everything else about them differs.
A request for information is a government market research instrument. The agency is trying to learn what the market can do so it can shape a future solicitation. A DDQ is a private risk instrument. The sender already knows what you say you can do and is checking whether it is true.
| DDQ | RFI | Security questionnaire | |
|---|---|---|---|
| Who sends it | A prime, a teaming partner, an agency program office or an investor | A government contracting activity | A buyer, a prime, or a customer security team |
| What it is for | Verifying that you are what you claim before taking on risk with you | Market research to shape a future requirement | Assessing the security of a specific product, service or connection |
| Authority | None. It exists because the sender asked | FAR 15.201, market research and exchanges before receipt of proposals | None, though the format is often a published standard such as SIG or CAIQ |
| What a good answer is | Short factual answers with documentary attachments | A capability narrative that shapes the requirement in your favor | Control-by-control responses mapped to a named framework |
| What happens next | You are added to a team, or quietly dropped | A solicitation may or may not follow | The vendor is approved, approved with conditions, or rejected |
| Response length | Set by the sender. Often a workbook plus attachments | Usually a page limit set in the notice | Fixed by the questionnaire |
DDQ vs RFP
A request for proposal asks you to compete. A DDQ asks you to substantiate. An RFP response is written to persuade an evaluator against stated criteria; a DDQ response is written to survive a check. The comparison between the three government-side instruments, RFP, RFQ and RFI, is worked through in the RFP vs RFQ vs RFI guide.
The practical difference is who is exposed. In an RFP the government is choosing. In a DDQ a private party is deciding whether to put its own name behind you, which is a harder audience because the consequences land on them.
DDQ vs a Vendor Security Questionnaire
A vendor security questionnaire is a subset of what a DDQ covers, and it is the subset most likely to arrive in a published standard format rather than in somebody’s spreadsheet. Two names come up repeatedly.
- SIG. The Standardized Information Gathering questionnaire, published by Shared Assessments. It is the long-established third-party risk questionnaire in financial services and has spread well beyond it.
- CAIQ. The Consensus Assessments Initiative Questionnaire, published by the Cloud Security Alliance and built into its Cloud Controls Matrix. CCM version 4.1 carries 197 control objectives across 17 security domains, and the CAIQ is the yes-or-no question set that maps to them.
If a DDQ arrives in SIG or CAIQ format, that tells you something useful: the sender has a third-party risk program and will compare your answers against other vendors’ answers to the same questions. Answer to the framework, not around it.
A federal DDQ is broader. It asks the security questions, and then it asks about your accounting system, your indirect rates, your past performance, your ownership and your contract vehicles. The security questionnaire is one section of it, not the whole thing.
Who Sends a DDQ, and When in the Deal
The sender tells you what the DDQ is really about, because each type of sender is protecting against a different failure.
- A prime building a team. The most common case. The prime is deciding whether to name you in a proposal. Its exposure is that you are found non-responsible, or that your systems fail a flow-down clause it already accepted.
- A teaming partner or a joint venture counterparty. Symmetrical risk, and often the one case where you should be sending a DDQ back.
- An agency program office or an OTA consortium. Membership and onboarding checks that sit outside the FAR because the vehicle itself does.
- An investor or an acquirer. Interested in the contract backlog, the option years, novation risk and whether the accounting system survives an audit.
- A commercial customer. Usually the security-questionnaire version described above.
On timing, the DDQ almost always arrives after interest and before commitment. In a teaming pursuit that means after the capability conversation and before the teaming agreement is signed, which is also the point at which the proposal deadline starts to matter. That sequencing is the reason a slow DDQ response costs a seat rather than costing time.
What a Federal DDQ Is Really Asking For
This is the section the commercial DDQ guides do not have, and it is the one worth reading twice. A federal DDQ looks like a generic vendor form, but almost every question on it is a proxy for a specific federal instrument. Once you can see the mapping, the questionnaire stops being a writing task and becomes a document-retrieval task.
The frame underneath most of it is FAR 9.104-1, the general standards a contracting officer must find satisfied before awarding to anyone. A prime that teams with you is inheriting your exposure against those standards. The seven standards are: adequate financial resources or the ability to obtain them; the ability to meet the delivery or performance schedule given all existing commitments; a satisfactory performance record; a satisfactory record of integrity and business ethics; the necessary organization, experience, accounting and operational controls and technical skills, or the ability to obtain them; the necessary equipment and facilities, or the ability to obtain them; and being otherwise qualified and eligible under applicable law.
Read that list against any DDQ you have received and the resemblance is immediate. Here is the mapping in the direction that is actually useful, from the question you get to the artifact that answers it.
| DDQ question | What it is really testing | The artifact that answers it |
|---|---|---|
| Do you have a compliant accounting system? | FAR 9.104-1(e) organization and accounting controls | An SF 1408 preaward accounting system survey result, or the audit report if one exists |
| What are your indirect rates? | Whether your pricing survives a rate review | Provisional billing rates established under FAR 42.704, and the rate agreement if you have one |
| Do you handle federal contract information? | FAR 52.204-21 basic safeguarding | Evidence of the 15 basic safeguarding requirements |
| Do you handle covered defense information? | DFARS 252.204-7012 | Your NIST SP 800-171 implementation, incident response process and DIBNet reporting path |
| What is your SPRS score? | DFARS 252.204-7019 and 252.204-7020 | A current NIST SP 800-171 DoD Assessment posted in SPRS, no more than three years old |
| What is your CMMC status? | DFARS 252.204-7021 and 32 CFR part 170 | Your assessment level and status record |
| Any covered telecommunications equipment? | FAR 52.204-25, Section 889 | Your representation and the supply chain review behind it |
Nothing in that table is a matter of opinion. Each row is either satisfied by a document you can produce today or it is not, and that binary is what the sender is measuring. The reason DDQ responses feel hard is that companies try to write their way through rows that need an artifact.
The Security Evidence to Have Ready Before One Arrives
Every item below is defined in a published clause or rule, so there is no ambiguity about what “having it” means. Assemble these once and most security sections of most DDQs answer themselves.
- The basic safeguarding baseline. FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, sets 15 requirements covering access control, identification and authentication, media sanitization, physical access, boundary protection, flaw remediation and malicious code protection. It flows down to subcontracts, so a prime asking about it is asking about a clause it already holds.
- The NIST SP 800-171 implementation, with its plan and its gaps written down. DFARS 252.204-7012 requires the safeguards for covered defense information. Where controlled information is involved the CUI marking and handling rules sit alongside this, and the two are asked about together more often than not.
- A current SPRS score. DFARS 252.204-7019 requires summary level scores of a current NIST SP 800-171 DoD Assessment, meaning not more than three years old, posted in the Supplier Performance Risk System at the time of the offer. DFARS 252.204-7020 carries the same currency rule down to subcontractors: a prime cannot award you a covered subcontract unless you have completed at least a Basic Assessment within the last three years.
- Your CMMC level and status. Under 32 CFR part 170, Level 1 is a self-assessment against the 15 requirements from FAR 52.204-21(b)(1); Level 2 is 110 requirements from NIST SP 800-171 Revision 2, assessed either by self-assessment or by a C3PAO; Level 3 is 24 requirements from NIST SP 800-172, assessed by DCMA DIBCAC. Know which one applies to you and what your current status record says.
- An incident response path that names DIBNet. DFARS 252.204-7012 defines rapid reporting as within 72 hours of discovery of a cyber incident, submitted at dibnet.dod.mil, with images of affected systems preserved for at least 90 days and any malicious software submitted to the DoD Cyber Crime Center rather than to the contracting officer. A DDQ answer that says “we have an incident response plan” and cannot name that path is a weak answer.
- A Section 889 representation you can stand behind. FAR 52.204-25 names Huawei, ZTE, Hytera, Hikvision and Dahua, prohibits both providing covered equipment and using it in performance, and requires reporting within one business day of discovery with additional detail within 10 days. The representation is easy to sign and hard to substantiate; the substantiation is the supply chain review behind it.
- Your export control position, if the work touches it. Whether ITAR registration and licensing applies to you is a standard DDQ line on any defense pursuit, and the honest answer is a registration status, not a claim of certification.
The pattern across all seven is the same. Each one is satisfied by a record with a date on it. A DDQ answer that describes an intention where a dated record is expected reads, correctly, as a gap.
The Financial Evidence to Have Ready
The financial section of a federal DDQ is usually shorter than the security section and stops more deals, because a prime cannot fix your accounting system for you inside a proposal schedule.
The reference document is Standard Form 1408, the Preaward Survey of Prospective Contractor Accounting System, which is what DCAA uses to judge whether an accounting system is acceptable for award. Its criteria evaluate the design of the system rather than its operation, and they are the clearest published statement of what “compliant accounting system” means:
- Accounting in accordance with generally accepted accounting principles.
- Proper segregation of direct costs from indirect costs.
- Direct costs identified and accumulated by contract.
- A logical and consistent method for allocating indirect costs to cost objectives.
- Accumulation of costs under general ledger control.
- A timekeeping system that identifies employee labor by cost objective, and a labor distribution that charges direct and indirect labor to the right objectives.
- Interim determination of costs at least monthly.
- Exclusion from costs charged to government contracts of amounts that are not allowable.
- Identification of costs by contract line item where required.
- Segregation of preproduction costs from production costs where applicable.
- Ability to provide the cost data needed to comply with limitation of cost or limitation of funds clauses, and to support pricing of follow-on work.
Alongside that, expect questions about your indirect rate structure. Billing rates are established under FAR 42.704 by the contracting officer, the cognizant federal agency official or the auditor responsible for final indirect cost rates, on the basis of recent review, previous rate audits, experience or similar reliable data, and once established they can be revised prospectively or retroactively by mutual agreement to prevent substantial overpayment or underpayment. The vocabulary behind those rates is worked through in the ROM, BOE and G&A guide.
Two more items round out the section: audited or reviewed financial statements for the last two to three years, and your SAM.gov registration with its representations and certifications current rather than lapsed. A lapsed registration is a five-minute discovery for the sender and an unflattering one.
How Long You Get to Return a DDQ
There is no rule, because there is no regulation. In practice the deadline is set by the proposal the prime is chasing, which means it is short and it is not really negotiable. Treat five to ten business days as the planning assumption rather than a published figure, and note that this is an observation about how the instrument is used, not a number anyone publishes.
The more useful planning question is not how long you get but how long your slowest artifact takes to produce. If your SPRS posting is out of date, that is not a deadline problem, it is a three-week problem, and it should be fixed before a DDQ ever arrives.
Why DDQ Responses Stall Teaming Deals
Companies rarely lose a teaming seat because a DDQ answer was badly written. They lose it in four other ways, and all four are operational rather than editorial.
- The evidence exists but nobody can find it. The SSP is on a former employee’s drive, the rate agreement is in an email thread, the insurance certificate expired in June. The answer is knowable and still not deliverable inside the window.
- One unanswerable question freezes the whole response. A single gate item, usually a CMMC status or an SPRS posting, holds the entire workbook while somebody decides how to phrase it. Meanwhile the prime is talking to the next company on its list.
- The answers contradict each other, or contradict SAM.gov. Different people answer different sections, and a NAICS code, an employee count or a business size in one place does not match the other. Nothing looks worse to a diligence reader than an internal contradiction, because the whole exercise is a consistency check.
- The answer is optimistic and the artifact is not. “We are CMMC compliant” against a status record that says otherwise is far more damaging than “Level 2 self-assessment complete, C3PAO assessment scheduled”. Diligence readers are calibrated for hedging; they are not calibrated for being misled, and one discovered overstatement invalidates the rest of the document.
The common thread is that a DDQ tests the state of your records under time pressure. Every one of these failures is fixed before the questionnaire arrives, not after.
How to Keep a DDQ Answer Library That Does Not Go Stale
The obvious response to repeated questionnaires is a reusable answer library, and most companies build one. The reason it stops working is not that the answers are wrong when written; it is that they are dated facts stored as undated text. An SPRS score, a CMMC status, an insurance certificate, a rate agreement and a registration all expire, and a library that does not know that will confidently supply a stale answer.
A library that survives contact with real questionnaires has four properties:
- Every answer names its artifact. Not the text of the SSP, but which document, which version, where it lives and who owns it.
- Every artifact carries an expiry. The SPRS assessment is current for three years under DFARS 252.204-7019. The registration renews annually. The insurance certificate renews. Store the date, not just the fact.
- Answers are tied to the pursuits that used them. When a fact changes, you need to know which primes were told the old version.
- One owner per answer. Security answers belong to whoever owns the SSP, financial answers to whoever owns the rate submission. Shared ownership is how contradictions get in.
Three questions are worth being able to answer about any teaming pursuit on any working day:
- Which primes have we sent diligence answers to, on which pursuits, and when?
- Which of the artifacts behind those answers expire in the next 90 days?
- If a fact changed this week, who did we already tell, and does it need correcting?
GovOps360 keeps that record: the pursuit, the prime, the teaming position, the dates and the outcome in one place, so an expiring artifact is visible before a questionnaire arrives rather than during one. The artifacts themselves stay wherever your compliance program keeps them; what the capture record holds is which pursuit depended on which one, and when it goes stale. GovFind finds the opportunity. GovOps360 wins it.
See Where GovOps360 Fits Your Pipeline
Bring the states and districts you already sell to, and the cooperative contracts you hold. We will walk through how the coverage gaps and renewal dates would be tracked, and tell you where another tool is the better fit.
Frequently Asked Questions
1. What is a DDQ in business?
2. What does DDQ mean in finance?
3. What is a DDQ in private equity?
4. Is a DDQ binding?
5. Who signs a DDQ?
6. How is a DDQ different from an RFI?
7. Do you have to answer every question in a DDQ?
8. Why does DDQ also mean a chemical reagent?
References and Sources
Every FAR and DFARS citation in this article was read against the official acquisition.gov text, and every CFR citation against the Code of Federal Regulations, on 6 September 2026. The SF 1408 criteria are from the DCAA preaward accounting system audit program.
- FAR 9.104-1, the general standards of contractor responsibility that a federal DDQ is testing by proxy
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, and its 15 requirements
- FAR 52.204-25, the Section 889 prohibition, the named entities and the reporting deadlines
- FAR 42.704, billing rates, who establishes them and on what basis
- FAR 15.201, exchanges with industry before receipt of proposals, the authority behind an RFI
- DFARS 252.204-7012, safeguarding covered defense information, 72 hour reporting and 90 day image preservation
- DFARS 252.204-7019, the requirement for a current NIST SP 800-171 DoD Assessment in SPRS
- DFARS 252.204-7020, the three year currency rule and the flowdown to subcontractors
- 32 CFR 170.4, the CMMC levels and what each one assesses
- DCAA preaward survey audit program, the SF 1408 accounting system criteria
- Cloud Security Alliance Cloud Controls Matrix v4.1 and the CAIQ built into it
- Shared Assessments, publisher of the Standardized Information Gathering questionnaire
- ILPA Due Diligence Questionnaire 2.0, the private equity standard form
Related reading: RFI meaning covers the government-side instrument a DDQ is most often confused with, FAR vs DFARS covers where the safeguarding clauses in a DDQ actually come from, and ROM, BOE and G&A covers the rate vocabulary the financial section uses.

Alaa Negeda
Senior Solution Architect with 23 years of experience in different Technology sectors. Diligent, forward-thinking, and adaptable to dynamic company, customer, and project needs.
Related Articles
Sep 30,2026 RFP vs RFQ vs RFI: Which Solicitation You Are Looking At and What to Do
Sep 25,2026 ITAR Meaning and Compliance for Government Contractors
Sep 23,2026
By Alaa Negeda


