A spreadsheet arrives from your largest customer. Sixty questions about your security, due in a fortnight, and somewhere in the covering email a line about the contract being contingent on the outcome.
This is now routine. Large organisations have worked out that their weakest point is often a supplier, and they have started checking. If you sell into enterprise, the public sector, financial services or healthcare, expect this to become a normal part of winning work.
Why you are being asked
Some of the most damaging breaches of recent years reached their target through a smaller supplier with legitimate access. Regulators noticed, and supply chain due diligence became something large organisations have to demonstrate.
That is worth understanding, because it reframes the exercise. You are not being singled out or distrusted. Your customer is being asked to prove they checked, and you are the evidence.
What they actually want to know
The questionnaires vary in length but circle the same ground:
- How people sign in, and whether MFA is enforced
- Who has administrative access and how that is controlled
- How you patch, and whether anything unsupported is running
- Whether you back up, and whether you have tested restoring
- What happens to their data — where it lives, who can see it, how long you keep it
- Whether staff receive security training
- What you would do in an incident, and how quickly you would tell them
- Whether you hold any certification
- How you vet your own suppliers
That last one catches people out. The chain continues past you.
How to answer well
Be accurate, including where the answer is no. Reviewers are experienced and inconsistencies are obvious. A truthful “not currently, planned for Q3” reads considerably better than a yes that unravels under follow-up questions — and unlike a false yes, it does not become a contractual problem later.
Answer what was asked. Padding invites scrutiny. Short, specific, factual.
Have the evidence ready. Many questionnaires ask for supporting documents: a policy, a certificate, a recent test result. Assembling those in advance turns a fortnight of panic into an afternoon.
Write it once and keep it. The overlap between questionnaires is enormous. Maintain a single answer bank with your standard responses and supporting documents, keep it current, and each new request becomes an editing job rather than a research project.
Certification does a lot of the work
Cyber Essentials answers a meaningful proportion of a typical questionnaire in one line, because it covers the same fundamentals: firewalls, secure configuration, update management, access control and malware protection.
For larger contracts you may meet requests for ISO 27001, which is a significantly bigger undertaking. It is worth understanding which of your target customers genuinely require it before committing to that path — for many SMEs, Cyber Essentials plus clear, honest answers is enough.
Treat it as commercial, not administrative
The businesses that handle this well treat it as part of winning the work rather than paperwork to be endured. A prompt, confident, well-evidenced response is a differentiator — particularly when your competitor takes three weeks and answers vaguely.
It also tends to surface genuine gaps. If a questionnaire is the first time anyone has asked whether you have tested a restore, the honest answer is useful information.
The bottom line
Supplier security questionnaires are becoming a standard part of selling to larger organisations. Answer honestly, keep a reusable answer bank with the evidence attached, and consider certification to cover the fundamentals in one go. Handled properly it is a competitive advantage rather than an obstacle.
FAQ
What if we cannot answer yes to something important? Say so, and say what you are doing about it with a date. Most reviewers will accept a credible plan. Almost none will forgive a false answer discovered later.
Do we have to complete every questionnaire we receive? Weigh the value of the contract against the effort. But once you have built an answer bank, the marginal cost of each additional one drops considerably.
Is Cyber Essentials enough? For many SME supplier relationships, yes, particularly alongside clear answers on data handling and incident response. Some sectors and larger contracts will ask for more.


