Complision
Supplier security questionnaires

Your customer sent you a security questionnaire. We answer it.

180 questions, a 30-day deadline, and the contract on the table. Upload the questionnaire and know exactly where you stand in a minute.

NIS2 · ISO 27001 · DORA · ENS · TISAX · or your customer’s own format

Your file never leaves your browser. To classify the questions, only the text of each question is processed — never the document, never company names, and never any answer you’ve already filled in.

Supplier_Security_Assessment_2026.xlsxDue in 12 days

Do you have a documented information security policy approved by management?

art. 21.2.a

COVERED

Is multi-factor authentication enforced for all remote access?

art. 21.2.j

COVERED

State the RTO and RPO of your critical systems.

art. 21.2.c

GAP

How often do you perform vulnerability scans?

art. 21.2.e

GAP
178 questions analyzed141 gaps across 16 controls
What we solve

What we solve

Your customer is required to prove their suppliers are secure. They can’t audit all of you, so they send a questionnaire. If you don’t answer it — or answer it badly — you stop being a supplier.

What we do

  1. 1.We analyze the questionnaire you received and tell you what it’s really asking, question by question.
  2. 2.We build your evidence base: we draft the policies you’re missing and organize the documents you already have.
  3. 3.We hand back the questionnaire answered, in its original format, with the evidence package ready to send to your customer.

Why us

Works for any framework

NIS2, ISO 27001, DORA, ENS, TISAX, or your customer’s own format. We work on controls, not formats: underneath, they all ask the same things.

You don’t throw it away

The evidence base we build stays. The next questionnaire you get answered in minutes, not weeks.

We don’t answer what can’t be proven

No evidence, it’s marked as a gap. A "yes" with no backing inside a contract is a false statement, and it costs far more than the original problem.

Fixed, published price

You know what it costs before talking to anyone. No custom quotes, no billable hours.

This is for you if...

  • You received a security questionnaire from a customer
  • You have a deadline and don’t know where to start
  • You don’t have a security department or compliance officer
  • You’ll be asked again next year

This isn’t for you if...

  • You want to get ISO 27001 certified (you need a consultancy)
  • You want us to implement technical measures (we won’t set up MFA — we’ll tell you it’s missing)
  • You need an official audit (that requires an accredited body)
The problem

It’s not paperwork. It’s your customer deciding whether you stay their supplier.

Regulations like NIS2, DORA, ISO 27001 and Spain’s ENS require large companies to control the security of their supply chain. Since they can’t audit hundreds of suppliers, they send questionnaires. The consequence of not answering usually isn’t a penalty: it’s that the contract doesn’t get renewed. There’s no case file, no notice — you just stop being on the list, and often you don’t even know why.

It arrives without warning, from procurement

An email with a spreadsheet attached and a deadline. Nobody negotiated it with you. If you don’t return it on time, your customer has to look for another supplier — their own regulation requires it.

It asks things nobody on your team knows how to answer

RTO, RPO, network segmentation, patch management, MFA, log retention. You make parts. Your IT guy handles the printers and email.

And you have to attach proof

Ticking "yes" isn’t enough. They want the document, the report, the screenshot. And signing a "yes" you can’t prove is a false statement inside a commercial contract.

And you don’t lose it by refusing — you lose it by taking too long

54% of companies report having lost business for not completing security questionnaires on time, and 88% take more than two weeks doing it by hand, according to industry data. You don’t lose out by failing the questionnaire — you lose out by being slow.

What we actually do

The work behind a questionnaire

What it costs you to do it yourself

Breakdown starting from scratch

Reading and understanding the 180 questions4-6 h
Figuring out what each one actually means8-12 h
Finding out who in the company knows the answer6-10 h
Drafting the policies that don’t exist yet10-20 h
Gathering and organizing the evidence8-15 h
Filling in and reviewing the questionnaire4-6 h
If you already have the documentation12-18 hours
If you’re starting from scratch40-70 hours

(most of it is drafting what doesn’t exist yet)

With Complision2-3 hours

Those 2-3 hours are yours, answering our questions about how you work. We handle everything else.

The cost you don’t see

  • Delivery slips and your customer’s deadline keeps running.
  • Your production or IT people stop what they’re doing to answer questions that aren’t theirs.
  • Without technical judgment, you end up answering "yes" to things you can’t prove — a false statement inside a contract.
  • Next year you start from zero again, because nothing was kept.

We leave you a reusable base: the next questionnaire gets answered in minutes, not weeks.

What we DON’T do

  • We don’t issue certifications or accreditations for any framework.
  • We don’t audit — that requires an accredited certification body.
  • We don’t answer "yes" to what can’t be backed by real evidence.
  • We don’t implement technical measures — we won’t set up MFA for you; we’ll tell you it’s missing and what that means.
  • We don’t implement a management system (ISMS). That’s a consultancy’s job.
  • We don’t prepare you for a certification audit.

Cost comparison

Doing it in-house

12-70 h of your team’s time

Between €480 and €2,800 of internal cost at €40/h, depending on whether you already have the documentation (12-18 h) or you’re starting from scratch (40-70 h) — and on someone at your company knowing the right answer.

Traditional consulting

€3,000-8,000

4 to 8 weeks.

Complision

€1,200-2,400

48-72h from your evidence, and you’re left with a base built for the next questionnaires.

We don’t do the same thing as a full NIS2 implementation consultancy — they implement compliance with an entire regulation. We solve this specific problem: answering the questionnaire you’ve just received, backed by real evidence.

The number one objection

Wouldn’t a consultancy do the same thing?

Compliance consultancyComplision
What it solvesImplementing a complete management systemAnswering the questionnaire you received
When you hire itWhen you decide to get certifiedWhen your customer gives you a deadline
ScopeThe whole organizationWhat they’re asking you
Duration4-8 weeks or more48-72h from your evidence
Typical price€3,000-8,000€1,200-2,400
What you’re left withAn implemented management systemYour questionnaire answered and a reusable base
Next questionnaireStart overMinutes

A compliance consultancy and Complision don’t compete: they solve different problems. If your goal is to get ISO 27001 certified or implement a full management system, you need a consultancy, and we don’t replace that. If what you have is a questionnaire on the table with a deadline, that’s us. In fact, many customers start here because the deadline is tight, and hire a consultancy afterward with the gap map already done.

How it works

Three steps. The first is free and takes a minute.

STEP 01

Upload the questionnaire

Excel or PDF, exactly as your customer sent it. Analyzed inside your browser — the file never travels to any server, ours or anyone else’s.

STEP 02

We show you the gaps

Every question classified by control and by the relevant framework, plus the exact list of documents you’re missing to answer with real backing.

STEP 03

We build your evidence base

We draft what doesn’t exist, gather what does, and answer the questionnaire. From then on, the next customer who asks gets answered in minutes.

Whatever framework your customer cites

Your questionnaire might cite very different articles, annexes or acronyms depending on who sends it — or cite no regulation at all and just use your customer’s own format. It doesn’t matter: we classify every question by control, not by the name of the regulation.

Supplier questionnaire, NIS2, ISO 27001, DORA, ENS or TISAX.

Pricing

What it costs, stated plainly.

The hard work is building your evidence base once. After that, keeping it alive is cheap. Fixed, published prices — no custom quotes, no negotiation.

Start for free

Upload your questionnaire and see the full result on screen, no card, no signup. The PDF report is free in exchange for your email.

Analyze my questionnaire
Standard Service
€1,200
You already have documentation
  • Evidence base built
  • We draft the policies you’re missing
  • Your questionnaire answered
  • Delivered in 48-72h from your evidence
Start with the triage
Complete Service
€2,400
You start from scratch
  • Everything in Standard Service
  • Full drafting of policies
  • More documentation to gather
  • Delivered in 48-72h from your evidence
Start with the triage
Optional
Maintenance€490per year
  • Alerts before a piece of evidence expires
  • Updates when regulation changes
  • One questionnaire per year included
  • No lock-in. If you don’t renew, your base stays put.
With maintenanceWithout maintenance
Annual fee€490€0
First questionnaire of the yearIncluded€600
Next questionnaires€300€600
Expiry alertsYesNo
Regulatory updatesYesNo

Your case

1 questionnaire per year

€490 vs €600

Worth it

2 questionnaires per year

€790 vs €1,200

Clearly worth it

None that year

€490 vs €0

Not worth it

Prefer to do it yourself?

Detailed report

€299

The exact list of what you’re missing, which document you need for each thing, in what order, and how many hours it’ll take. You execute it.

See what’s included
FAQ

What people ask before hiring us.

Does this certify me in any framework?

No — and be wary of anyone who says otherwise. Neither NIS2, nor ISO 27001, nor DORA, nor Spain’s ENS get "approved" through us: none of them has an exam or a certificate issued via a third party like Complision. What does exist, and is very real, is the questionnaire your customer sends. That’s what we answer.

The questionnaire is confidential. Where does the file end up?

The file itself, nowhere: the analysis happens inside your browser and the document is never uploaded to a server. To classify each question, only its text is processed — never the file, your company’s name, or any answer already filled in. Close the tab and nothing of yours remains. We only store the aggregated result if you request the report.

My questionnaire doesn’t mention any specific regulation. Does it still work?

Yes. ISO 27001, DORA, ENS, TISAX, your customer’s own format, or a mix of everything: underneath, they ask the same things, only the wording changes. Our system works on controls, not on the format.

How do I know which framework applies to me?

Your customer’s email usually says why. If it’s not clear, upload the questionnaire: we detect it from the content itself.

My questionnaire mixes several frameworks. Does it still work?

Yes, that’s the most common case. We detect several at once and classify by controls, not by format.

Does this replace a compliance consultancy?

No. A consultancy implements a full management system; we answer the questionnaire you received and build your evidence base. They’re different things, and often complementary.

Do I have to pay a monthly fee?

No. The service is a one-time payment. Maintenance is annual and optional: if you don’t hire it, your evidence base stays saved and you only pay when another questionnaire arrives.

Is maintenance worth it for me?

If you get at least one questionnaire a year, yes: €490 versus the €600 it costs to answer one without maintenance. If you don’t expect to get any, don’t hire it — your base stays saved regardless, and you only pay when you need it.

Why does a questionnaire cost more without maintenance?

Because there’s more work involved. With maintenance, your documentation is up to date and answering is nearly immediate. Without it, after a year much of the evidence has expired and has to be redone.

If I don’t renew, do I lose my evidence base?

No. It stays saved. When another questionnaire arrives, we answer it using that base.

What happens if I get a second questionnaire?

It’s answered using the base we already built, so it costs far less than the service. With maintenance, the first one each year is included and the next ones cost €300. Without maintenance, €600.

We already use Microsoft 365. Does that count?

It counts for more than you’d think. A well-configured Microsoft 365 or Google Workspace already covers MFA, email encryption, and activity logging. The work isn’t implementing anything new — it’s organizing it, documenting it, and being able to show it. A good part of what we do is exactly that.

Start here

Upload the questionnaire. Know what’s missing in a minute.

No signup, no card, and the file never leaves your computer. If you then want us to answer it for you, let’s talk.

Analyze my questionnaire
Complision — Supplier Security Questionnaires