Skip to content
DreamSolve

How to answer a supplier security questionnaire

Tanmoy Hossain

Last updated

The short answer

A supplier security questionnaire is how a bigger customer checks that you will look after their data before they sign. Answer every question honestly and back each yes with evidence you can show. Where the honest answer is not yet, say so and show your plan.

What the questions are really checking

When a company buys from you, your weaknesses become their risk. The NCSC's supply chain security guidance (opens in a new tab) puts it plainly: a vulnerable supply chain can cause damage and disruption, and attackers have both the intent and the ability to exploit it (correct as of 5 October 2026). The person who sends you the questionnaire is accountable for that risk inside their organisation. The questionnaire is their record that they checked.

That shapes everything about it. They are not trying to catch you out. They are building evidence they can show to their own auditors, their board or a regulator. Some buyers write their own forms. Others use standard ones, such as the Shared Assessments SIG (opens in a new tab), a third-party risk questionnaire, or the Cloud Security Alliance's CAIQ (opens in a new tab), a set of yes or no questions for cloud services.

Whatever the format, most questions come back to five things:

  • Access: who can reach our data, how they log in, and what happens when someone leaves.
  • Data: where it is stored, how it is protected, how long you keep it and how you delete it.
  • Incidents: how you would spot a problem, what you would do, and how quickly you would tell us.
  • Your suppliers: which hosting providers and tools touch our data, and how you checked them.
  • Continuity: backups, recovery and how long the service can be down.

You will often meet the same question several times in one form. Different teams write different sections (security, privacy, legal and procurement), and some questions exist to check that the answers agree. Consistency matters more than polish.

How to answer honestly without bluffing

Answer the question that was asked, not a better one. Then assume every yes will be followed by "show me". If you could not produce a policy, a screenshot, a report or a setting within a day, it is not a yes yet.

Partial answers are fine when they are precise. Compare these two:

  • Weak: "Yes, we use multi-factor authentication."
  • Strong: "Partially. Multi-factor authentication is enforced on our email, code repository, cloud hosting and every admin account. Two internal tools still use passwords only. Both move to single sign-on with multi-factor authentication by 31 March."

The second answer tells the buyer more, and it is the one they will trust. Be just as careful with "not applicable". Use it only with a reason, such as "we do not store card data: payments go through our payment provider".

Never copy policy language you do not follow. A buyer who later finds the gap will remember the answer, not the gap.

Then build an answer library. Keep every answer you give in one place, alongside the evidence behind it and the date you last checked it. Give it a named owner. The first questionnaire is slow. With a library, the tenth takes an afternoon, and every answer stays consistent across customers. Review it whenever something changes, such as a new tool, a new supplier or a new hire with admin access, and at least every few months regardless.

The policies you need in place

A small company does not need a shelf of policies. It needs a handful that are short, true and followed. This is the minimum credible set I would put in place before the first big questionnaire:

  1. Information security policy. One or two pages: who is responsible, what you protect and the rules everyone follows.
  2. Access control. How people get access, how it is reviewed, how it is removed when they leave, and where multi-factor authentication is required.
  3. Devices and acceptable use. Supported, updated, encrypted devices, and what is allowed on them.
  4. Incident response. Who does what when something goes wrong, and who tells the customer, within what time.
  5. Backup and recovery. What is backed up, how often, and when you last tested a restore.
  6. Supplier management. A list of the suppliers that touch customer data, and how you checked each one.
  7. Data protection. How you handle personal data under UK GDPR. If you process personal data on a customer's behalf, the contract between you has to cover specific terms, which the ICO sets out under Article 28 (opens in a new tab) (correct as of 5 October 2026).

Keep each one short enough that people read it, and written to match what you do today. A policy that describes an imaginary company is worse than no policy, because it will be tested against reality.

Certificates save you time here. Cyber Essentials covers the technical basics: firewalls, configuration, updates, access and malware protection. ISO 27001 covers how you manage security as a whole: risk, policies, suppliers, incidents and continuity. Neither is required to answer a questionnaire, but each one answers whole sections of it, and buyers recognise both.

When to say "not yet, here is our plan"

Most buyers do not expect a small supplier to be perfect. They expect you to know where your gaps are and to be closing them. An honest "not yet" with a plan often does more for trust than a stretched yes.

Some gaps are usually acceptable with a plan: a policy still being written, an annual review not yet done, a lower-risk internal tool still waiting for single sign-on. Others are deal breakers, because they leave the buyer's own data exposed or because the contract makes them mandatory. No multi-factor authentication on systems that hold their data, no backups, unsupported software, or a certificate the contract names, such as Cyber Essentials on the central government contracts that require it.

A credible plan has five parts:

  • The gap, stated plainly. No euphemisms.
  • The interim measure. What reduces the risk until the fix lands.
  • An owner. A named person, not "the team".
  • A date. One you will hit.
  • How you will show it is done. The evidence you will send when it is.

Then follow up before they ask. Tell the buyer when the plan is delivered, and update your answer library so the next questionnaire gets a yes. Delivering on a plan you volunteered is one of the strongest signals a small supplier can send.

If bigger customers are starting to send these, here is how I help small companies get enterprise-ready.

Questions

  • What is a supplier security questionnaire?

    A list of questions a customer sends before or during a contract to check how you protect their data and keep your service running. Some buyers write their own. Others use standard ones, such as the Shared Assessments SIG or the Cloud Security Alliance's CAIQ for cloud services.

  • Can I answer no and still win the contract?

    Often, yes. An honest no with a dated plan, an owner and an interim measure usually lands better than a yes you cannot back up. The exceptions are requirements the contract makes mandatory, such as a named certificate, and gaps that leave the buyer's own data exposed.

  • Do I need Cyber Essentials or ISO 27001 to answer one?

    No, but each one answers many questions at once. Cyber Essentials covers the technical basics, such as updates, access and malware protection. ISO 27001 covers how you manage security as a whole: risk, policies, suppliers and incidents.

How DreamSolve helps

Enterprise Readiness helps you answer questionnaires honestly and put the missing pieces in place: the policies, the controls and the evidence behind each answer. I was CTO of a small SaaS company that grew to more than 200 enterprise and public sector clients.

Book an intro call (opens in a new tab)A free 30 minute fit check.
Tanmoy Hossain

Written by

Tanmoy Hossain

Fractional CTO. About seven years building and leading technology at a cybersecurity SaaS company, from systems developer to CTO.

More about Tanmoy

Not sure which door you're at?

That's what the first call is for. It's 30 minutes and free: we work out whether I can help, and which door you're at.