Supplier Security Questionnaire: What It Is and How to Answer It Without Losing the Contract
If you searched for this, you probably have one open in another tab right now.
A supplier security questionnaire is the form — usually a 100-200 question spreadsheet or PDF — that a large customer sends to check how you protect the information and systems you use to serve them. They send it because their own company is obligated to manage supply chain risk, and you are part of that chain.
The most common driver today is the EU NIS2 Directive (2022/2555): it requires large companies in sectors like energy, transport, healthcare, digital infrastructure and critical manufacturing to manage the cybersecurity risk of their suppliers, not just their own. Since they cannot audit hundreds of suppliers individually, they push the obligation down via a questionnaire and, usually, a contract clause.
What the questionnaire asks for, stripped of legal wrapping, is always the same: evidence — a policy, a screenshot, a contract, a report — that you have reasonable controls in areas like access control, backups, incident response, and how you vet your own suppliers.
Who does this apply to?
You receive this questionnaire if you supply a company that is itself obligated by NIS2, by DORA (if your customer is a financial entity), or simply by its own internal supplier risk policy — regardless of whether your own company falls under these regulations directly. The obligation reaches you by contract, not by law.
The most common profile: an industrial or services SME with 30-200 employees, no dedicated security team, suddenly asked to answer precisely about RTO, network segmentation or vulnerability management.
Typical questions
Do you have a documented information security policy?
art. 21.2.a
Is multi-factor authentication (MFA) enforced for remote access?
art. 21.2.j
How often do you perform vulnerability scans?
art. 21.2.e
Do you have a documented incident response plan?
art. 21.2.b
Do you assess your suppliers’ security before engaging them?
art. 21.2.d
Evidence you’d need
- Signed, current security policy document
- MFA configuration screenshot
- Latest vulnerability scan report
- Incident response plan
- Supplier evaluation procedure
Already have the questionnaire in front of you?
Upload it and in a minute you’ll know what you cover, where your gaps are, and what evidence you’re missing. Processed in your browser — the file never leaves your computer.
Analyze my questionnaire for freeFAQ
Does this certify me in NIS2?
No — NIS2 has no official exam or certificate. What exists is the questionnaire your customer sends, and that’s what we help you answer with real evidence.
What happens to the file I upload?
The file itself never leaves your browser. To classify the questions, only the text of each one is processed — never the document, never company names, and never any answer you’ve already filled in. Nothing is stored unless you request the report.
