Home / Cybersecurity / Supplier security questionnaire

Guide · for suppliers of NIS2 companies

A customer sent you a security questionnaire. Here is how to answer it.

NIS2 makes energy, health, transport, manufacturing and many other companies responsible for the security of their suppliers. So they send questionnaires — often with a deadline and a contract at stake. Below: the 30 questions you will almost always see, and the evidence that closes each one.

→ Get help with my questionnaire

Five rules before you start

  1. 01 Answer only what is true today; put the rest in a dated plan.
  2. 02 Attach evidence (policy, screenshot, certificate) — a 'yes' without proof is often scored as 'no'.
  3. 03 Use one owner and one shared evidence folder, so the next questionnaire takes hours, not days.
  4. 04 Fix the quick wins first: MFA, backups tested, DMARC, patching routine.
  5. 05 Keep a signed copy: your answers become commitments in the contract.

The 30 questions and the evidence expected

#QuestionEvidence that closes it
01Governance
Do you have a written information-security policy approved by management?
Signed policy, date of last review
02Governance
Who is responsible for information security?
Named person and role, organisation chart
03Governance
Do you hold ISO/IEC 27001, CyberFundamentals (CyFun®) or a similar certification?
Certificate and scope, or a dated roadmap
04Governance
Do you carry out a yearly risk assessment?
Latest risk register (summary)
05Governance
Do you have cyber insurance?
Insurance certificate
06Access
Is multi-factor authentication enforced for email, remote access and admin accounts?
Screenshot of policy settings, % of accounts covered
07Access
How are accounts created and removed when staff join or leave?
Joiner/leaver procedure, last review
08Access
Are administrator rights separated from daily user accounts?
List of admin accounts, review date
09Access
How do your staff access our systems or data, if at all?
Named users, access method, logging
10Access
Do you use a password manager and a password policy?
Tool name, policy extract
11Data
Where is our data stored and in which countries?
Hosting providers and regions
12Data
Is data encrypted in transit and at rest?
TLS configuration, disk/database encryption
13Data
How long do you keep our data and how is it deleted?
Retention schedule, deletion procedure
14Data
Do you have a GDPR data processing agreement?
Signed DPA
15Data
Which subcontractors process our data?
List of sub-processors
16Continuity
Do you have backups, and are restores tested?
Backup policy, date and result of last restore test
17Continuity
Are backups kept offline or immutable?
Technical description
18Continuity
Do you have a business-continuity plan?
Plan summary, last exercise
19Continuity
What is your recovery time for the service you provide to us?
RTO/RPO figures
20Incidents
Do you have an incident-response procedure?
Procedure, contact list
21Incidents
How fast will you notify us of an incident affecting us?
Contractual commitment (e.g. within 24 hours)
22Incidents
Have you had a significant security incident in the last 24 months?
Short description and lessons learned
23Incidents
Do you monitor logs and alerts?
Tooling, who reviews, retention
24Technical
How do you manage security updates (patching)?
Patch policy, time-to-patch for critical updates
25Technical
Do you run antivirus/EDR on all endpoints?
Tool name, coverage
26Technical
Is your email domain protected (SPF, DKIM, DMARC)?
DNS records — run our free email security check
27Technical
Do you perform vulnerability scans or penetration tests?
Date and summary of last test
28Technical
Is your network segmented and protected by a firewall?
Network diagram (high level)
29People
Do staff receive security awareness training?
Training records, phishing-test results
30People
Do staff sign confidentiality commitments?
Template clause

Question 26 — check your SPF, DKIM and DMARC for free →

Where NIS2 applies to your customers

Frequently asked questions

We are too small for NIS2. Why do we get these questionnaires?

NIS2 requires in-scope companies to manage the security of their supply chain. They pass requirements down to their suppliers through questionnaires, contract clauses and audits — whatever the supplier's size.

Can we answer 'in progress'?

Yes, if it is true and dated. A short roadmap with owners and dates is better than a vague 'yes'. Never claim a control you do not have: it becomes a contractual commitment.

Which certification do customers accept?

ISO/IEC 27001 is recognised everywhere. In Belgium, CyberFundamentals (CyFun®) is the national framework; its Basic level is designed for suppliers of NIS2 entities.

How long does it take?

A typical questionnaire of 50–150 questions takes 2 to 5 working days with evidence, less when the evidence pack already exists.

Free first call · English

Questionnaire due soon?

Tell us the customer's deadline. An English-speaking advisor replies within one business day with how many days it takes and what is missing.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call