Contact Us
Next webinarQuickBooks on AutopilotThursday October 15, 3:00 PM CDTRegister Now
Oct 6, 2026

Your Biggest Customer Just Sent a Vendor Security Questionnaire. Now What?

It usually arrives as a spreadsheet attached to a routine email from purchasing. Eighty to three hundred rows. "Do you enforce multi-factor authentication for all remote access?" "Describe your incident response plan." "Provide evidence of annual penetration testing." Due in two weeks.

For a lot of owners, this is the first time IT stops being a cost line and starts deciding revenue. The customer isn't asking out of curiosity. Somebody above them (an auditor, an insurer, a regulator) is asking them about their suppliers, and you're one of the suppliers.

Why these questionnaires are showing up everywhere

Five years ago, security questionnaires were mostly a big-company problem. Now they land on 30-person manufacturers, CPA firms and medical billing companies every month. The requests we see from clients and prospects look like this:

  • A security requirements annex from a large customer, built on the ISO 27001 standard.
  • A written security baseline from an insurance carrier, tied to the business that carrier sends your way.
  • An attestation against a health plan's security requirements.
  • Vendor reviews under the Gramm-Leach-Bliley Act, including the ones financial firms send to their IT providers.
  • Security terms a software platform requires its partners to meet before renewal.
  • Due diligence questions from investors ahead of a funding round, which are the same questions in different words.

The pressure comes from rules that make companies responsible for their vendors. The FTC's Safeguards Rule requires financial institutions to oversee their service providers and require safeguards by contract. The SEC's amended Regulation S-P now requires investment advisers and broker-dealers to oversee vendors with access to customer information, and smaller firms had to comply by June 3, 2026. HIPAA requires business associate agreements. And for defense suppliers, phase two of the Department of Defense's CMMC program starts on November 10, 2026, when many contracts begin requiring third-party certification at award.

The result is the same for you: the questionnaire flows downhill until it reaches a company without a security team.

What a vendor security questionnaire usually asks

The formats vary (custom spreadsheets, portals, the industry-standard SIG and CAIQ templates, ISO 27001 annexes), but the substance repeats. Expect questions in these areas:

  • Access control. Is MFA enforced for email, remote access and admin accounts? How are accounts removed when people leave?
  • Endpoint protection. What protects laptops and servers? Is it monitored, and by whom?
  • Data protection. Is data encrypted on devices and in transit? Where is customer data stored?
  • Backup and recovery. How often do you back up, and when did you last test a restore?
  • Incident response. Do you have a written plan? Who do you call, and how fast will you notify the customer?
  • Training. Do employees get security awareness training, and can you prove completion?
  • Vendor management. Who are your own critical vendors, and how do you vet them?
  • Testing and evidence. Vulnerability scans, penetration tests, policies, and sometimes screenshots or reports.

The eight areas a vendor security questionnaire usually asks about

The trap: answering "yes" because it sounds right

The quickest way to fill in a questionnaire is to answer yes to everything. It's also the riskiest.

A questionnaire answer is a representation to a customer, often attached to a contract. If there's a breach later and the answers don't match reality, the conversation stops being about the breach and starts being about what you told them. The same applies to cyber insurance applications, which ask many of the same questions and which carriers check after a claim.

We regularly see the gap between what a company believes and what's configured. MFA that's enrolled but not enforced. Training that was assigned but that most employees never completed. An "incident response plan" that's a vendor's phone number on a sticky note. None of these are unusual. They become a problem when they're written down as "yes."

An honest "partially, with a remediation date" is a far better answer than a "yes" you can't support. Most customers would rather see a plan than a perfect score.

How to answer it well

Find out what's driving it. Ask your contact who requires the questionnaire and what a passing result looks like. Sometimes only a handful of questions are mandatory, and the rest are informational.

Answer from evidence, not memory. For each technical answer, have whoever runs your IT confirm it against the actual settings and reports. If nobody can show it, treat the answer as "no" for now.

Mark gaps with a date. "MFA is enforced for email; enforcement for the VPN is scheduled for completion by December 15" is a credible answer.

Keep a master copy. Most questionnaires ask the same 80 percent. Once you've answered one carefully, reuse it and keep it current. The second one takes an afternoon instead of two weeks.

Fix the cheap gaps first. Enforcing MFA, turning on disk encryption, removing old accounts and writing a one-page incident response plan close a large share of the "no" answers quickly.

Business owner and IT engineer reviewing security questionnaire answers together

Security as a sales advantage

The flip side is good news. When you can return a clean, honest questionnaire in a few days, you look like the safer supplier, and the customer's procurement team remembers it at renewal. For several companies we've worked with this year, a customer's questionnaire was what finally got their security in order.

Where SafePoint IT comes in

When a client receives a security questionnaire, our engineers work through the technical sections with them and answer from what's configured in their environment, not from guesses. Where an answer is "not yet," we put a remediation plan and a date behind it. For prospects, a business risk review shows where you stand before the next spreadsheet arrives.

Got a questionnaire on your desk?

If a customer, insurer or regulator just sent you one and you're not sure how to answer it accurately, book a 15-minute call with our team. We'll tell you which questions matter most and what it would take to answer them with confidence.

Book a free 15-minute call

Frequently Asked Questions

What is a vendor security questionnaire?
It's a set of questions a customer sends a supplier to assess how well the supplier protects data and systems. It usually covers access control, MFA, endpoint protection, backups, incident response, training and policies. Customers use the answers to decide whether working with you creates risk for them.
Who has to fill out a security questionnaire?
Any business that handles a customer's data or connects to their systems can be asked to complete one. They're most common for suppliers to financial firms, healthcare organizations, manufacturers in regulated supply chains and defense contractors, because those customers are required to oversee their vendors.
How long does it take to answer a security questionnaire?
The first one often takes one to three weeks, because you have to gather evidence and confirm settings. Later questionnaires go much faster if you keep a maintained master copy of your answers. Having your IT provider answer the technical sections speeds it up considerably.
What happens if I answer a security questionnaire incorrectly?
An inaccurate answer can become a contract or legal issue if there's a breach and the customer relied on what you said. It can also affect cyber insurance claims if your application contained the same inaccuracies. Answer from evidence, and mark each gap with a remediation date.
What is the difference between SIG, CAIQ and ISO 27001 questionnaires?
SIG (from Shared Assessments) and CAIQ (from the Cloud Security Alliance) are standardized questionnaire templates many companies reuse. An ISO 27001 annex asks you to show controls aligned to the ISO 27001 security standard. The underlying questions overlap heavily, so one well-documented set of answers covers most of them.

Technology Insights

SafePoint IT team standing together in a modern Chicago office

SafePoint IT Named to the 2026 Inc. 5000 List

SafePoint IT has been named to the 2026 Inc. 5000 list, the annual ranking of...
Read More
Business owner reviewing rising AI costs on a laptop dashboard

Why Your Team's AI Bills Are Higher Than They Should Be (And the Habits That Actually Fix It)

If your business runs on Claude, ChatGPT, or any other AI assistant at scale, you've...
Read More
Office manager looking at her phone after an unexpected sign-in alert

MFA Was On. They Got In Anyway: How Attackers Bypass MFA in Microsoft 365

A business owner turns on multi-factor authentication (MFA), checks the box on the cyber insurance...
Read More
chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram