Why your first compliance event is a customer, not a regulator
For a small supplier, a customer questionnaire may be the first structured review of its security. A short deadline does not change the need to verify the answers.
That spreadsheet is not enthusiasm. It is your customer's own obligation, pushed one level down the chain. NIS2 Art. 21(2)(d) makes supply chain security part of the risk-management measures an entity in scope must take, and Art. 21(3) requires it to take into account the vulnerabilities specific to each direct supplier. For financial entities, DORA Art. 28–30 does the same thing harder, with prescribed contractual content. And since 2018, GDPR Art. 28 has required a controller to use only processors providing sufficient guarantees — a requirement for which questionnaires can support due diligence but do not by themselves establish sufficient guarantees.
So the person on the other side is not testing your character. They are collecting the evidence that they checked you. If you are supplying a bank, an energy operator or a hospital, the supplier-side view of that obligation is worth reading before you answer, and whether your own organisation is directly in scope is a separate question with a different answer.
What the buyer is actually checking
Behind every block of questions sit three concerns, that recur often.
Can we lose data through you. Access, encryption, staff, subprocessors, where the data sits.
If you go down, can we get back up. Backups, restore testing, continuity, dependency on one person, exit and data return.
Can we prove to our own auditor that we checked. Dates, documents, evidence, a right to audit.
Evidence helps the buyer assess the claim. For example, a dated Conditional Access export can show the policy settings. It does not by itself prove effective MFA coverage: include exceptions, relevant sign-in results and testing where the claim requires it. The buyer’s acceptance criteria determine the score; no artefact guarantees full marks.
Why a "yes" you cannot evidence is a contractual risk
The failure mode here is almost never deliberate lying. It is the sales lead filling in the security section on Thursday evening and ticking "yes" wherever a control basically, more or less, exists.
Follow that tick forward. Questionnaire responses are routinely attached to the contract as an annex or restated as representations and warranties. At that point "yes, backups are encrypted at rest" is no longer an optimistic answer — it is a term. If an incident follows, that spreadsheet is the first document the other side's lawyer reads, and the gap between what you wrote and what was configured is the whole case. GDPR Art. 28(3)(h) also gives the controller audit rights, so the claim is testable by design.
Give one person ownership of the response and access to the technical owners. If evidence cannot yet be found, mark the answer as pending verification internally. Use “partial” when coverage is actually partial; the speed of finding a file does not determine whether a control exists.
Question block by question block
Every questionnaire reshuffles the same material. The answers below are illustrative — write your own with your real dates — but the shape is what matters.
| Block of questions | What the buyer is really asking | A good honest answer when you do not have the control |
|---|---|---|
| Policies, roles, governance | Is anyone here accountable, and can I put a dated document in my file | "We have no approved information security policy yet. Security decisions sit with the managing director; access changes are recorded in our ticket system. A written policy goes to management for approval in [month]." |
| Access control, MFA, offboarding | If one of your people loses a password, do we lose data | "MFA is enforced on email and the admin console, not yet on [system]. Three named engineers can reach your data. Offboarding is manual and verified by [role] within one working day." |
| Data location, subprocessors, transfers | Where does our data physically sit and who else touches it | "Data is held in [region]. Two subprocessors: [A] and [B]. We have no automated change notification; we will commit contractually to 30 days' written notice before adding one." |
| Backup, restore, continuity | If you disappear on Monday, when do we work again | "Backups run daily, retained 30 days. We have not tested a full restore. The first restore test is scheduled for [date] and we will send you the result." |
| Incident response and notification | Will you tell us fast enough for us to meet our own 24-hour and 72-hour clocks | "We have no written incident response plan. We commit in the contract to notifying your named contact in writing without undue delay after becoming aware of an incident affecting your data, through the agreed channel and within any applicable contractual maximum. The plan is due [month]." |
| Vulnerabilities, patching, testing | Do you know what you run, and do you fix it | "Workstations patch automatically; servers are patched manually each month. We have never had an external penetration test. One is planned for [quarter] and we will share the summary." |
| Certification and audit rights | Can I close this file without doing the work myself | "We are not ISO/IEC 27001 certified and have no SOC 2 report. Instead we offer a contractual right of audit and an annual evidence pack on a fixed date." |
How to answer when you do not have the control yet
Four parts, in this order, and nothing else.
State the position plainly. "No. We do not have that." No softening verbs, no "we are in the process of exploring".
Say what you do instead, specifically. The compensating control is the substance of the answer. Two named people with MFA beats a policy nobody reads, and the buyer knows it.
Size the actual exposure to this customer's data. Often it is far smaller than the question implies, because the customer's data touches three systems, not thirty. Say so.
Give one date and one accountable role — and only a date you will meet. A missed commitment in a supplier file is worse than the original gap.
Ask which gaps are mandatory conditions for the deal and which can be addressed through an agreed plan. Some buyers will accept compensating controls; others cannot. A clear scope and realistic commitment support negotiation without guaranteeing acceptance.
Answer once, then make the fifth questionnaire cheap
The first questionnaire is expensive because you are doing archaeology. The rest do not have to be.
Build an answer library: the question, your canonical answer, the evidence artefact, the date it was last verified, the owner. One folder, versioned, every file dated.
A concise security overview can reduce repeated explanations. Ask whether the buyer accepts it alongside or in place of particular questionnaire blocks. Keep sensitive evidence behind an agreed disclosure process.
Re-verify on a cadence — quarterly, and on any change of system, subprocessor or key person. Speed without verification just produces confident wrong answers.
Use unanswered rows as an input to the security roadmap, together with business risk and legal duties. A frequently requested control is a commercial signal, but not automatically the highest risk. An Evidence Sprint can help organise the gaps and evidence.
A questionnaire measures what you claim, not what holds
Every questionnaire is self-assessment. It records declared controls, and declared controls fail quietly. MFA is enabled and an attacker replays a stolen session token. The backup job is green and the restore has never been attempted. The offboarding process exists and three former contractors still have accounts. None of that shows up in a spreadsheet, because a spreadsheet cannot try anything.
That gap — between "the control is configured" and "the control holds under attempt" — is where incidents actually live.
Buyers are starting to notice. Increasingly they ask for a recent penetration test report, proof of a restore test, an external attestation, or read-only access to a live trust page instead of a tick. DORA Art. 30(3) already requires financial entities to secure rights of access, inspection and audit for services supporting critical or important functions. That expectation will not stay inside finance.
The practical consequence is small and cheap: verify the claim before you write it. Restore one backup. Check who actually has administrative access today. Try to send an email that looks like it comes from your own domain and see whether it is delivered. Then answer.
Free Excel workbook: answers and evidence
Download the security questionnaire workbook (Excel). It is a response-management template, not a recognised assessment standard or a completed representation about your organisation. The blank response sheet and separate fictional examples show how to connect each answer to its scope, supporting record, owner and approval.
Keep the customer's question and identifier unchanged. Write the proposed answer, then identify the exact service, systems and exclusions it covers. Add a reference to evidence and its review date. A reference can point to a controlled repository; the workbook does not need to contain the sensitive document itself. Use the gap/action field for missing controls, with a responsible person and target date.
The readiness field checks whether the key fields are populated, including approval and its date. It does not judge truth, legal adequacy or control effectiveness. A complete row can still contain a wrong answer. The reviewer must check the evidence and any commitments before approving the customer's final version.
For example, “MFA is enabled” needs a defined population and exceptions. A statement that all accounts were checked requires records supporting that whole population. The example sheet deliberately uses a partial answer so a planned change is not mistaken for an operating control.
Use one row per customer question or split a compound question with traceable sub-identifiers. The template provides 50 working rows. For a larger questionnaire, extend the table and copy the readiness formula and validation into the added rows, then check them. Retain the approved workbook and exact attachments sent. Recheck reused answers when the service, evidence or question changes.
A certificate can support an answer within its certified scope, but it cannot replace every requested operational record. For an access-removal question, the offboarding verification guide shows what a dated test record can establish.
What to do first
- Name one owner for the questionnaire. Someone who can reach IT and management, and who is not closing the sale.
- Read every row before answering any of them. Mark each one yes, no, partial, or not applicable with a reason. Do not start typing at row one.
- For each "yes", name the file that proves it. If it is not available, verify the facts before finalising the answer.
- Verify the three claims most likely to be tested: MFA on administrative access, one real restore, and the current list of people who can reach the customer's data.
- Write the "not yet" rows with the four-part structure above, then have someone uninvolved read them cold.
- Before you send, save the answers, the artefacts and the dates in one place. That is the asset, not the reply.
The boundary
Once a questionnaire answer is attached to a contract it is a legal commitment. Representations, warranties, liability caps and a specific notification window are for a lawyer, not for the person filling in the sheet.
Answering a questionnaire is also not certification. If the customer genuinely requires ISO/IEC 27001 or SOC 2, that is a separate programme with an accredited certification body or an auditor, on its own timeline. Nothing written well shortens it.
If your sticking points are the email, domain and impersonation rows — SPF, DKIM, DMARC, who can send in your name — our Trust Audit answers them with evidence you can attach to the spreadsheet, and you can see what that evidence looks like before you commit.
Note: general information, not legal advice. What applies to you depends on the specific entity, activity, licence, size, group structure and national implementation.
For a reusable evidence structure, use the questionnaire evidence guide. For help across the whole questionnaire, see Dyasol’s services; a domain audit covers the email questions within its specific scope.