What is a customer security questionnaire, and how do you answer one?
A customer security questionnaire is a list of questions a customer sends you before they sign, or at renewal, to check you'll look after their data. It usually arrives as a spreadsheet of 50 to 300 questions about how you protect information, and the deal often waits until it's done. The fastest way to answer one well is to have approved policies and records to answer from, rather than writing every answer from scratch.
Why customers send them
When a business shares data with you or relies on your service, your security becomes part of theirs. Their own auditors, insurers and regulators expect them to check their suppliers. The UK's National Cyber Security Centre recommends exactly this kind of supply chain checking. So their procurement or security team sends you a questionnaire.
It's not personal and it's rarely optional. A slow or vague answer can delay a deal; a clear, consistent one builds trust.
What they ask
Questions vary, but most questionnaires cover the same ground:
| Area | Typical questions |
|---|---|
| Governance | Do you have an information security policy? Who is responsible for security? |
| Certifications | Are you ISO 27001 certified? Do you hold Cyber Essentials? |
| People | Do staff have security training? Are there background checks? |
| Access | Do you use multi-factor authentication? How do you remove leavers' access? |
| Data | Where is our data stored? Is it encrypted? How long do you keep it? |
| Suppliers | Which subprocessors handle our data? How do you check them? |
| Incidents | Do you have an incident response plan? How fast will you tell us about a breach? |
| Continuity | Do you test backups and restores? What's your recovery plan? |
| Technical | Do you patch promptly? Do you run vulnerability scans or penetration tests? |
Many larger customers use a standard format, such as a shared industry questionnaire or their own house template.
How to answer one well
- Read the whole thing first. Note the deadline and any questions that need someone else (HR, finance, a supplier).
- Answer from what you actually do. Never guess or overstate. A "no, but here's what we do instead" is better than a "yes" you can't back up. Answers can become contractual.
- Point to evidence. Where you can, reference a policy, record or certificate. Customers trust answers they can check.
- Keep answers short and specific. "MFA is enforced for all staff on Microsoft 365 and our cloud admin consoles" beats a paragraph of general reassurance.
- Flag gaps honestly, with a plan. "Not yet; planned for Q1" is an acceptable answer to many questions.
- Get one person to review the whole set before it goes back, so answers don't contradict each other.
- Save your final answers. The next questionnaire will ask most of the same questions.
Why it keeps getting harder without a system
The first questionnaire is painful. The tenth is worse if every answer lives in a different person's inbox. Answers drift, policies don't match what you said last time, and someone has to rebuild the evidence each time.
This is where ISO 27001 helps even before you're certified. An ISO 27001 information security management system gives you:
- Approved policies to quote and attach.
- A risk register and Statement of Applicability that show which controls you have and why.
- Records and evidence (training, access reviews, restore tests, incidents) that prove the answers.
Once that exists, most questionnaire answers are a matter of looking things up. And many customers will accept "we are ISO 27001 certified, here is the certificate and our Statement of Applicability" in place of large sections of the questionnaire.
Questionnaire or certificate?
| Answering questionnaires | ISO 27001 certification | |
|---|---|---|
| Effort per customer | High, every time | Low once certified |
| What it proves | What you say you do | That an accredited auditor checked your system |
| Cost | Your time | Audit fees plus building and running the system |
| Best for | A few customers, simple needs | Many customers, larger buyers, tenders |
If questionnaires are slowing your sales, that's often the clearest sign that ISO 27001 will pay for itself.
How ClearIMS helps
ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there. You describe your business in plain English and it drafts your scope, risk register, Statement of Applicability, policies and tasks. A named person in your business approves every record (the AI never approves anything), and the system keeps running with owned, dated tasks and evidence. That gives you approved material to answer questionnaires from.
We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.
Take the 2-minute readiness check, or book a 20-minute call.