What is a customer security questionnaire, and how do you answer one?

7 min read · Updated

A customer security questionnaire is a list of questions a customer sends you before they sign, or at renewal, to check you'll look after their data. It usually arrives as a spreadsheet of 50 to 300 questions about how you protect information, and the deal often waits until it's done. The fastest way to answer one well is to have approved policies and records to answer from, rather than writing every answer from scratch.

Why customers send them

When a business shares data with you or relies on your service, your security becomes part of theirs. Their own auditors, insurers and regulators expect them to check their suppliers. The UK's National Cyber Security Centre recommends exactly this kind of supply chain checking. So their procurement or security team sends you a questionnaire.

It's not personal and it's rarely optional. A slow or vague answer can delay a deal; a clear, consistent one builds trust.

What they ask

Questions vary, but most questionnaires cover the same ground:

Area Typical questions
Governance Do you have an information security policy? Who is responsible for security?
Certifications Are you ISO 27001 certified? Do you hold Cyber Essentials?
People Do staff have security training? Are there background checks?
Access Do you use multi-factor authentication? How do you remove leavers' access?
Data Where is our data stored? Is it encrypted? How long do you keep it?
Suppliers Which subprocessors handle our data? How do you check them?
Incidents Do you have an incident response plan? How fast will you tell us about a breach?
Continuity Do you test backups and restores? What's your recovery plan?
Technical Do you patch promptly? Do you run vulnerability scans or penetration tests?

Many larger customers use a standard format, such as a shared industry questionnaire or their own house template.

How to answer one well

  1. Read the whole thing first. Note the deadline and any questions that need someone else (HR, finance, a supplier).
  2. Answer from what you actually do. Never guess or overstate. A "no, but here's what we do instead" is better than a "yes" you can't back up. Answers can become contractual.
  3. Point to evidence. Where you can, reference a policy, record or certificate. Customers trust answers they can check.
  4. Keep answers short and specific. "MFA is enforced for all staff on Microsoft 365 and our cloud admin consoles" beats a paragraph of general reassurance.
  5. Flag gaps honestly, with a plan. "Not yet; planned for Q1" is an acceptable answer to many questions.
  6. Get one person to review the whole set before it goes back, so answers don't contradict each other.
  7. Save your final answers. The next questionnaire will ask most of the same questions.

Why it keeps getting harder without a system

The first questionnaire is painful. The tenth is worse if every answer lives in a different person's inbox. Answers drift, policies don't match what you said last time, and someone has to rebuild the evidence each time.

This is where ISO 27001 helps even before you're certified. An ISO 27001 information security management system gives you:

  • Approved policies to quote and attach.
  • A risk register and Statement of Applicability that show which controls you have and why.
  • Records and evidence (training, access reviews, restore tests, incidents) that prove the answers.

Once that exists, most questionnaire answers are a matter of looking things up. And many customers will accept "we are ISO 27001 certified, here is the certificate and our Statement of Applicability" in place of large sections of the questionnaire.

Questionnaire or certificate?

Answering questionnaires ISO 27001 certification
Effort per customer High, every time Low once certified
What it proves What you say you do That an accredited auditor checked your system
Cost Your time Audit fees plus building and running the system
Best for A few customers, simple needs Many customers, larger buyers, tenders

If questionnaires are slowing your sales, that's often the clearest sign that ISO 27001 will pay for itself.

How ClearIMS helps

ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there. You describe your business in plain English and it drafts your scope, risk register, Statement of Applicability, policies and tasks. A named person in your business approves every record (the AI never approves anything), and the system keeps running with owned, dated tasks and evidence. That gives you approved material to answer questionnaires from.

We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.

Take the 2-minute readiness check, or book a 20-minute call.

SOURCES

  1. Supply chain security guidance (NCSC)
  2. ISO/IEC 27001:2022 (ISO)
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.