Skip to content
Resources

Guide

Answering supplier security questionnaires: an SME playbook

Win an enterprise customer and the reward is a 200-question security questionnaire. Done badly it stalls deals for weeks; done well it becomes a repeatable asset. This is the playbook — including the answer-bank structure to build once and reuse everywhere.

10 min readLast reviewed July 2026

Why questionnaires exist — and what the buyer actually wants

The person sending you a questionnaire usually did not write it and cannot waive it. Enterprise third-party risk teams must evidence that every supplier was assessed; the questionnaire is that evidence. Understanding this changes how you answer: your reader is building a defensible file, not conducting an interrogation. Clear, consistent, evidence-referenced answers make their job easy — and easy files get approved faster.

What gets suppliers rejected is rarely a missing control. It is contradictions (question 41 contradicts question 87), evasion (“see attached policy” with no page reference), and silence on follow-ups. Small firms with honest gaps and clear remediation dates pass review constantly.

Triage before answering

  1. Confirm scope. Which service, which data, which environments? A questionnaire scoped to “suppliers processing personal data” may barely apply if you only receive business contact details. Agreeing scope first can remove half the questions.
  2. Ask what they accept in lieu. Many buyers accept a recent SOC 2 report, ISO 27001 certificate, Cyber Essentials Plus, or a completed industry-standard questionnaire (CAIQ, SIG) instead of their bespoke form — but only if you ask.
  3. Identify the knockouts. Scan for questions marked mandatory or phrased absolutely (“Do you encrypt all data at rest?”). Deal with these first; if one is a genuine blocker, better to negotiate early than after two weeks of form-filling.
  4. Nominate one owner. Questionnaires answered by committee contradict themselves. One person answers; specialists review.

Five answering principles

  • Answer the question asked, then stop. Volunteered detail creates follow-ups and future audit surface.
  • Never claim a control you do not run. Questionnaire answers get incorporated into contracts by reference. A false “yes” is a breach waiting to be discovered at the worst time — during an incident.
  • “No, because…” beats a fake yes. Proportionality is a legitimate answer: “No dedicated SOC; we are a 12-person company. Alerting from our cloud provider routes to the on-call engineer with a 15-minute response target during business hours.”
  • “Not yet, by [date]” is a strong answer. Risk teams can approve suppliers with documented remediation plans. They cannot approve vagueness.
  • Reference evidence precisely. “Yes — MFA enforced tenant-wide via conditional access; enforcement report available on request” reads very differently from a bare “yes”.

Build the answer bank once

The compounding asset is a maintained answer bank: your canonical answers, organised by theme, reused across every questionnaire. Most forms — bespoke or standard — draw from the same underlying domains, so structure yours the same way. For each entry keep four fields: the canonical answer (two to four sentences, honest, current), the evidence pointer (which document or report proves it), the owner, and the last-verified date.

SectionCovers
Company & governanceLegal entity, insurance held, who owns security, policy review cycle
PeopleVetting, security training, joiner/leaver process, confidentiality terms
Access controlMFA, SSO, privileged accounts, access review cadence
Infrastructure & hostingCloud providers and regions, tenancy model, network controls
Data handlingWhat you store, encryption at rest/in transit, retention, deletion on exit
EndpointsDevice management, disk encryption, malware protection
Development & changeCode review, dependency updates, separation of environments
Incident responsePlan, roles, customer notification commitments and timescales
Business continuityBackups, restore testing, recovery targets
Sub-processorsWho they are, what they see, how you assess them
Certifications & assuranceCyber Essentials, ISO 27001, SOC 2, penetration tests — with dates

Review the bank quarterly and after any material change. An answer bank with stale dates is worse than none — it industrialises wrong answers. This page itself is the template: reproduce the eleven sections above in a shared document and you have the structure enterprise reviewers expect.

Handling the hard questions

“Do you have ISO 27001 / SOC 2?”

If no: say no, state what you do hold (for a UK SME, Cyber Essentials is a meaningful and recognised answer), and whether certification is planned. Many buyers have a proportionate track for small suppliers — your honesty routes you into it.

“Describe your SOC / 24×7 monitoring.”

Answer proportionately, as above. Enterprise reviewers know a 10-person firm has no SOC; they are checking whether anyone would notice an incident.

“Have you had a security incident in the last 3 years?”

Answer truthfully and briefly: what happened, impact, what changed afterwards. A disclosed, remediated incident is survivable; a discovered concealment usually is not — contractually and reputationally.

Absolute questions (“all”, “always”, “every”)

Qualify precisely rather than rounding up: “All customer data at rest is encrypted (provider-managed AES-256). Two internal legacy file shares hold no customer data and are scheduled for decommissioning in Q4.”

Escaping the loop entirely

The questionnaire loop exists because SMEs have no standard way to prove posture continuously — so every buyer asks everything, every time, in their own format. The answer bank shrinks the cost per questionnaire; shared, verifiable evidence shrinks the number of questionnaires.

That is the design goal of the TrustQuant Trust Passport: a shareable, independently verifiable credential of your current resilience rating that answers the recurring 80% of questions before the form arrives — leaving only the genuinely bespoke ones. Read a sample report to see the evidence behind it, or join the Q3 2026 pilot to help shape it.

Reading is preparation. Measuring is proof — see where you stand in minutes, without installing anything.

Read a sample report

Turn this guide into a score

Run a free preview of your resilience rating, or apply for the Q3 2026 pilot cohort.