A vendor proposes a new SaaS platform that processes regulated customer data. Procurement wants to sign by quarter-end, and the vendor's SOC 2 Type II report is six months old. As the security architect, what is the MOST appropriate next step?
A. Accept the SOC 2 report and proceed with contract execution
B. Require the vendor to complete your standard security questionnaire
C. Perform a risk assessment mapped to your control requirements
D. Demand a fresh penetration test before signing