A client sent you a security questionnaire
- security
- audit
- cyber-essentials
- suppliers
It arrives as a spreadsheet attached to a polite email, usually from a name in procurement nobody at your end has spoken to. Forty questions. Sometimes ninety. Column B wants Yes, No or N/A, and column C wants evidence.
The first reaction is always the same, and it is not a security reaction. It is a commercial one: this contract is worth real money and somebody has just made it conditional on answers we do not have.
I get pulled into these, and the thing worth saying up front is that most of the panic is misdirected. The questionnaire is rarely the problem. How you answer it is.
Why you are getting one now and did not five years ago
Your customers got asked first.
The government’s Cyber Security Breaches Survey, published on 30 April 2026, puts a number on who is doing this. Across all businesses, 15% reviewed the cyber security risks posed by their immediate suppliers and 6% looked at the wider supply chain. Split it by size and the picture changes completely: 48% of large businesses and 30% of medium ones review their immediate suppliers, against 22% of small businesses and 12% of micro ones.
Read that as a supply chain rather than as a league table. Nearly half of large businesses are asking questions, and the people they ask are smaller than they are. If you sell to anyone with a compliance function, the questionnaire is arriving whether or not you have ever sent one yourself.
The questions sort into three piles, and only one of them is technical
Every one of these documents I have read breaks down the same way.
Pile one: things a machine can answer. Is disk encryption enabled on laptops. Is the firewall on. Are accounts locked out after failed attempts. Is SMBv1 disabled. What is your minimum password length. Is there a local administrator account with a blank password sitting on a machine in the back office. These are settings, they exist in a readable state on every Windows machine you own, and the answer is not a matter of opinion.
Pile two: things only a document can answer. Do you have an information security policy. When was it last reviewed. Do staff receive security training and how often. Do you have a documented incident response process. Who is accountable. What are your data retention periods. No scan tells you any of this, because none of it lives on a computer.
Pile three: things that are a straight fact about your company. Do you hold Cyber Essentials or ISO 27001. Do you carry cyber insurance and to what limit. Have you had a reportable breach in the last twenty-four months. Do you use sub-processors and where are they.
That split matters because it tells you what to buy and what to write. I can do pile one in a day and hand you the evidence. Pile two is a writing job and you or your lawyer are better at it than I am. Pile three is either true or it is not, and no amount of tooling changes the answer.
What I can actually put in the evidence column
The audit reads seventeen checks across your Windows estate, changes nothing, and attaches to every finding the thing it was read from. That last part is the reason it is useful here rather than just useful.
A questionnaire response that says “yes, we enforce a minimum password length” is a claim. A response that says yes and attaches the output of net accounts showing the policy in force, from a machine identified by name, on a dated report, is something the person at the other end can accept and close. I have watched procurement teams stop reading at the point where the evidence appears. They are not trying to catch you out. They are trying to get to the end of a spreadsheet with something they can file.
Findings also get mapped to the relevant Cyber Essentials control, which is worth doing even when nobody has asked for the certificate, because a good half of the questions in pile one are that scheme’s five controls rephrased. If you can see where you stand against those, you can see most of pile one before you write a word. And if the customer wants the certificate itself, I wrote separately about how to pass Cyber Essentials first time, which is mostly about the things that fail people.
I wrote separately about why the audit is read-only and what that constraint costs. In this specific context it happens to be an advantage: you can run it against a live estate on a Tuesday, in the week the questionnaire landed, without a change window you do not have time for.
Write “no” and put a date next to it
This is the part people get wrong, and it is the only part of this piece I would call advice.
The instinct is to answer optimistically. Nobody wants to hand a prospective client a column of noes. So “do you have an information security policy” becomes a yes because there is a document from 2021 that somebody’s cousin adapted, and “is MFA enforced for all users” becomes a yes because it is on for the directors.
Two things go wrong with that. The small one is that the next question is nearly always a request for the evidence, and the evidence contradicts you. The large one is that a signed supplier assurance response becomes a contractual representation. You have not smoothed over a gap, you have written a warranty about it.
The alternative reads worse and performs better. No, with a date: not yet, scheduled for the end of November. In my experience nobody has ever lost a contract over a no with a plan attached. People lose contracts over a yes that turns out to be false, and they lose them later, when it is more expensive.
If you have twelve noes and every one of them has a date, you have given a procurement team a risk register they can work with. That is what they were asking for.
The things I cannot do for you
I cannot certify anybody against Cyber Essentials, and neither can anyone who is not an IASME-licensed certification body. I do not hold it myself. What the mapping does is tell you where you stand before you pay an assessor, which is genuinely useful and is not the same thing as the certificate.
I also will not write your policies. I will tell you which of your answers depends on a document you do not have, which is most of pile two, and then it is your call whether that is a job for you, for a consultant, or for the template you already half-trust.
And I will not fill in the spreadsheet for you. The answers are representations by your company about your company, and they need to be given by somebody who can be held to them. I supply the evidence for the technical half and I will sit on the call while you answer, which is usually what people actually want.
What I would do with a week
If the questionnaire has a deadline on it, the order that works is this.
Read the whole thing first and sort it into the three piles before answering anything, because the technical questions are the ones with a fixed cost and the rest is negotiable effort. Run the audit against the estate and take the wins that are settings rather than projects, since several of pile one are a Group Policy change and an afternoon. Then write the noes, with dates, for everything that is a real gap. Get the whole thing read by somebody who was not in the room when you answered it.
The by-product is the thing that outlasts the contract. You now have a written statement of what your systems actually do, dated, with evidence, and a list of what they do not. Most businesses have never had that, which is roughly what I found when I went looking at my own server and had no reason to expect anything interesting.
