Skip to content

Answering customer security questionnaires: get it right once, then reuse

5 min read Last checked on

A security questionnaire is how a customer checks whether it can trust you with its data and processes. Customers often must, under the GDPR and the supply chain duties of NIS2. If you answer honestly and concretely, back every answer with evidence and keep answers in a library with an owner, the next questionnaire takes hours instead of weeks.

A security questionnaire is how a customer checks whether it can trust you with its data and processes. For a software or IT supplier selling to larger organizations, one lands on the table sooner or later, often just as a deal is about to close. If you record and support your answers properly once, the next questionnaire takes hours instead of weeks.

Why customers ask

A customer that uses your software or service remains responsible for what happens to its data. Besides ordinary diligence, there are two legal reasons:

  • The GDPR. If you process personal data on behalf of a customer, you are a processor. The customer may only use processors that provide appropriate security measures, and records the arrangements in a processing agreement. The Dutch data protection authority recommends making those arrangements as concrete as possible and keeping control over the whole chain of suppliers.
  • NIS2. Organizations in scope must manage the risks of their suppliers; supply chain security is part of the duty of care. Even if you are not in scope yourself, your customer will ask you about it.

On top of that come procurement terms, insurers and the customer's own risk function. The result is a questionnaire.

The questionnaires you will meet

  • The customer's own questionnaire. Often a spreadsheet with dozens to hundreds of questions, written by procurement or security.
  • Standard questionnaires. The SIG from Shared Assessments and the CAIQ from the Cloud Security Alliance are widely used. CAIQ v4 has 261 yes/no questions mapped to the Cloud Controls Matrix.
  • Sector-specific questions. Dutch healthcare organizations ask about NEN 7510, Dutch public bodies about the BIO.
  • The security annex to a processing agreement. Not a questionnaire by name, but the same questions: which measures do you take, and how do you show it.

The format differs, but the topics are always the same: policy and responsibilities, access, encryption, backups and continuity, incidents, suppliers, personnel, physical security and certification.

What a good answer looks like

A good answer is true, concrete and supported.

  1. True. Answer what is true today. If something is in progress, say so with a date. An answer often becomes part of the contract.
  2. Concrete. Not "we take appropriate measures", but "all employees sign in with MFA; administrators use a hardware key".
  3. Scoped. Say what the answer covers: the service the customer buys, not the whole company, or precisely the whole company.
  4. Supported. Point to evidence you can show: a policy, a certificate, a penetration test summary, a recent restore test report.

An honest "no, and this is why it does not matter for your risk" builds more trust than a "yes" that falls apart at the first follow-up question.

Get it right once: an answer library

Most of the work is in the first questionnaire. Record the answers in a library you reuse every time:

  • a standard answer per topic in plain language, in English and Dutch;
  • an owner per answer who keeps it current, and the date it was last checked;
  • a link from each answer to its evidence;
  • a fixed review, at least yearly and after every change that affects an answer.

An answer library that is not maintained goes out of date as quickly as the policy it refers to. It works best when the answers come straight from your measures and evidence, so a change in one place carries through everywhere.

A trust center

A trust center is a public page showing how you handle security and privacy: your certificates, summaries of your main policies, your subprocessors and where your data is stored. More sensitive material, such as a penetration test report or your Statement of Applicability, you make available on request under a non-disclosure agreement. A good trust center answers many questions before they are asked, and shows a prospect that you take security seriously.

Security due diligence in larger deals

Larger contracts sometimes come with a deeper review: a call with your security lead, access to audit reports or an audit by the customer. What helps then is not having to search. You can show which risks you know, which measures you take, who is responsible for what, when checks were carried out and which evidence belongs to them.

Who signs off

Have every questionnaire checked by someone who can oversee the answers before it goes out, and keep a record of what you sent. Answers can become contractual commitments, and at a later audit or after an incident you want to be able to see what you promised and when.

From questionnaire to advantage

A security questionnaire feels like paperwork, but it is a sales conversation. Answering quickly, honestly and with evidence shows that your cybersecurity is organized, which is exactly what the customer wants to know. Trustbird keeps your risks, measures, owners and evidence together, so your questionnaire answers come from the same source your auditor sees.

Frequently asked questions

Why do customers send a security questionnaire?

Because they remain responsible for what you do with their data and processes. The GDPR requires a controller to use only processors that provide appropriate measures, and NIS2 requires organizations in scope to manage the risks of their suppliers. A questionnaire is the most common way to establish that.

Does an ISO 27001 certificate replace a security questionnaire?

Often in part. Many customers skip questions once you show a valid certificate with a fitting scope, sometimes together with your Statement of Applicability. Questions about your specific service, such as where data is stored, who can access it and how you report incidents, usually remain.

Can I answer "yes" when a measure is still being implemented?

No. Answer what is true today, and mention what is in progress with a date. An answer in a questionnaire often becomes part of the contract, and an incorrect "yes" can later turn into a liability question.

What is a trust center?

A public page on which a supplier shows how it handles security and privacy, with certificates, policy summaries and subprocessors, and the option to request more sensitive documents under a non-disclosure agreement. It answers part of the questions before they are asked.

Read next

Sources

  1. Autoriteit Persoonsgegevens, Processing agreement
  2. Autoriteit Persoonsgegevens, Three recommendations for a strong processing agreement in the event of a cyber attack
  3. NCSC Netherlands, Duty of care under the Cyberbeveiligingswet (Dutch)
  4. Cloud Security Alliance, STAR Level 1 Security Questionnaire (CAIQ v4)
  5. Shared Assessments, What is the SIG?
  6. ISO, ISO/IEC 27001 Information security management systems

Trustbird helps organizations become cyber proof and stay that way, with compliance as the result you can show. It is being built with two certified design partners, and we are looking for more companies to join them.

Become a design partner