Supplier Security Questionnaires: How to Stop Losing Days to Them
Published 4 August 2026
Why questionnaires cost so much time
A 150-row spreadsheet from a single enterprise buyer routinely takes a small supplier two to three days, and the answers usually live in someone's head rather than a document. Do that four times a year and you have lost a fortnight, produced four slightly different versions of the truth, and still cannot prove any of it.
The fix is not answering faster. It is having the underlying evidence exist, be current, and be independently verified.
What questionnaires nearly always ask
| Question area | What answers it |
|---|---|
| Firewalls, patching, malware protection, secure configuration | Cyber Essentials certificate |
| MFA and privileged access control | Cyber Essentials, plus the access control theme |
| Do you have an information security policy? | Cyber Assurance governance theme |
| How do you assess and treat risk? | Risk register and treatment plan |
| Do you train staff, and how often? | Training records under the people theme |
| What happens when you have an incident? | Incident response plan with named roles |
| Are backups tested, and what is your RTO? | Business continuity plan and test evidence |
| How do you assure your own suppliers? | Supplier management register and due diligence process |
| Independent verification of any of the above | Cyber Essentials Plus or Cyber Assurance Level 2 audit |
Build a reusable evidence pack
Keep one folder, reviewed quarterly, containing:
- Current certificates (Cyber Essentials, CE Plus or Cyber Assurance) with expiry dates visible.
- Information security policy, dated and version-controlled.
- Risk register with recent review dates.
- Incident response plan with named contacts and reporting timescales.
- Business continuity plan and the date of the last restore test.
- Training completion records.
- Subcontractor and supplier register.
- A one-page scope statement describing what your certification covers.
That pack answers the majority of any questionnaire, and the certificate does the job of convincing the buyer without them auditing you.
Why a certificate beats a self-declaration
Third-party risk teams discount self-declarations, because everyone ticks yes. A certificate issued by a licensed Certification Body means someone independent reviewed the evidence. That is why buyers who previously sent a 150-row spreadsheet often accept a certificate plus a short scope statement instead. For the audited version, see Level 1 vs Level 2.
Where the gaps usually are
Suppliers who already hold Cyber Essentials typically fail on the governance half: no written risk methodology, an incident plan that has never been rehearsed, backups that are taken but never restored, and no supplier register at all. Those four gaps are exactly what Cyber Assurance forces you to close. See the 14 themes for what evidence each one needs.
What to do next
- Collect your last three questionnaires and highlight every question you could not evidence.
- Confirm your Cyber Essentials scope matches the contracts you are bidding for.
- Close the governance gaps through Cyber Assurance Level 1.
- Keep the evidence pack current and answer future questionnaires by exception.
