Home / Cybersecurity / Supplier security questionnaire
A customer sent you a security questionnaire. Here is how to answer it.
NIS2 makes energy, health, transport, manufacturing and many other companies responsible for the security of their suppliers. So they send questionnaires — often with a deadline and a contract at stake. Below: the 30 questions you will almost always see, and the evidence that closes each one.
→ Get help with my questionnaire
Five rules before you start
- 01 Answer only what is true today; put the rest in a dated plan.
- 02 Attach evidence (policy, screenshot, certificate) — a 'yes' without proof is often scored as 'no'.
- 03 Use one owner and one shared evidence folder, so the next questionnaire takes hours, not days.
- 04 Fix the quick wins first: MFA, backups tested, DMARC, patching routine.
- 05 Keep a signed copy: your answers become commitments in the contract.
The 30 questions and the evidence expected
| # | Question | Evidence that closes it |
|---|---|---|
| 01 | Governance Do you have a written information-security policy approved by management? | Signed policy, date of last review |
| 02 | Governance Who is responsible for information security? | Named person and role, organisation chart |
| 03 | Governance Do you hold ISO/IEC 27001, CyberFundamentals (CyFun®) or a similar certification? | Certificate and scope, or a dated roadmap |
| 04 | Governance Do you carry out a yearly risk assessment? | Latest risk register (summary) |
| 05 | Governance Do you have cyber insurance? | Insurance certificate |
| 06 | Access Is multi-factor authentication enforced for email, remote access and admin accounts? | Screenshot of policy settings, % of accounts covered |
| 07 | Access How are accounts created and removed when staff join or leave? | Joiner/leaver procedure, last review |
| 08 | Access Are administrator rights separated from daily user accounts? | List of admin accounts, review date |
| 09 | Access How do your staff access our systems or data, if at all? | Named users, access method, logging |
| 10 | Access Do you use a password manager and a password policy? | Tool name, policy extract |
| 11 | Data Where is our data stored and in which countries? | Hosting providers and regions |
| 12 | Data Is data encrypted in transit and at rest? | TLS configuration, disk/database encryption |
| 13 | Data How long do you keep our data and how is it deleted? | Retention schedule, deletion procedure |
| 14 | Data Do you have a GDPR data processing agreement? | Signed DPA |
| 15 | Data Which subcontractors process our data? | List of sub-processors |
| 16 | Continuity Do you have backups, and are restores tested? | Backup policy, date and result of last restore test |
| 17 | Continuity Are backups kept offline or immutable? | Technical description |
| 18 | Continuity Do you have a business-continuity plan? | Plan summary, last exercise |
| 19 | Continuity What is your recovery time for the service you provide to us? | RTO/RPO figures |
| 20 | Incidents Do you have an incident-response procedure? | Procedure, contact list |
| 21 | Incidents How fast will you notify us of an incident affecting us? | Contractual commitment (e.g. within 24 hours) |
| 22 | Incidents Have you had a significant security incident in the last 24 months? | Short description and lessons learned |
| 23 | Incidents Do you monitor logs and alerts? | Tooling, who reviews, retention |
| 24 | Technical How do you manage security updates (patching)? | Patch policy, time-to-patch for critical updates |
| 25 | Technical Do you run antivirus/EDR on all endpoints? | Tool name, coverage |
| 26 | Technical Is your email domain protected (SPF, DKIM, DMARC)? | DNS records — run our free email security check |
| 27 | Technical Do you perform vulnerability scans or penetration tests? | Date and summary of last test |
| 28 | Technical Is your network segmented and protected by a firewall? | Network diagram (high level) |
| 29 | People Do staff receive security awareness training? | Training records, phishing-test results |
| 30 | People Do staff sign confidentiality commitments? | Template clause |
Question 26 — check your SPF, DKIM and DMARC for free →
Where NIS2 applies to your customers
Frequently asked questions
We are too small for NIS2. Why do we get these questionnaires?
NIS2 requires in-scope companies to manage the security of their supply chain. They pass requirements down to their suppliers through questionnaires, contract clauses and audits — whatever the supplier's size.
Can we answer 'in progress'?
Yes, if it is true and dated. A short roadmap with owners and dates is better than a vague 'yes'. Never claim a control you do not have: it becomes a contractual commitment.
Which certification do customers accept?
ISO/IEC 27001 is recognised everywhere. In Belgium, CyberFundamentals (CyFun®) is the national framework; its Basic level is designed for suppliers of NIS2 entities.
How long does it take?
A typical questionnaire of 50–150 questions takes 2 to 5 working days with evidence, less when the evidence pack already exists.
Questionnaire due soon?
Tell us the customer's deadline. An English-speaking advisor replies within one business day with how many days it takes and what is missing.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg