Tickbox Draft your answers free
Guide

How to complete a supplier security questionnaire (with examples)

Just been sent a long security or vendor questionnaire by a customer? Here is how to work through it calmly, what each part is really asking, and example answers you can adapt.

Last updated: July 2026

If a bigger customer has sent you a security questionnaire, take a breath: this is routine, it is not a test you can fail, and you almost certainly know more of the answers than you think. It usually means the deal is going well and their procurement team is doing its due diligence before signing.

This guide walks through what these questionnaires are, why you were sent one, how to answer well, and gives worked examples for the questions that come up again and again.

Draft your answers free →

What a security questionnaire actually is

A security questionnaire (sometimes called a vendor security assessment, third-party risk assessment, or supplier due-diligence questionnaire) is a list of questions a customer asks a supplier to understand how they protect information. They range from a dozen questions to a few hundred.

Some are industry-standard templates (you may see names like SIG, CAIQ, or a spreadsheet based on ISO 27001), and many are a customer’s own bespoke form. Whatever the format, they tend to probe the same handful of themes:

Why your customer sent it

When a customer trusts you with their data or access to their systems, they take on the risk that you might not protect it well. Regulators and their own customers hold them accountable for that whole supply chain, so they check their suppliers before signing, and often once a year afterwards.

In other words, this is not personal and it is not a trap. It is a box they need to tick, and a clear, honest set of answers is exactly what unblocks the deal.

Before you start: gather a few facts

Most of the questionnaire is faster to answer once you have these to hand:

How to answer well

A good answer is honest, specific, and consistent with your other answers. You do not need to sound like a large enterprise, and you should never claim a control you do not actually have. A confident "we do X" that turns out to be untrue is far worse than an honest "we do not do this yet, and here is our plan".

Two things trip people up. First, "not applicable" is a perfectly valid answer when a question genuinely does not apply to a small business, as long as you say briefly why. Second, keep it plain: reviewers read hundreds of these, and a clear sentence beats a wall of jargon every time.

What if you can’t answer "yes"?

You will not have everything, and that is fine. The honest, low-risk way to handle a gap is to say what you do today and what you are putting in place. For example: "We do not currently enforce MFA on every system. We are rolling it out across our cloud services this quarter." Buyers see this constantly and generally prefer honesty with a plan over a hollow yes.

A faster way to draft the whole thing

Working through a long questionnaire by hand is slow, and it is easy to answer the same underlying question five different ways. Tickbox reads your questionnaire, drafts a grounded answer to every question in your own words, and shows you which control or policy each answer draws on. You review, edit, and send. Nothing is submitted on your behalf, and it never claims you are certified. Your first few answers are free, so you can see the quality on your own document before paying anything.

Example answers to common questions

Do you enforce multi-factor authentication (MFA)?
Yes. Multi-factor authentication is enforced on our email, file storage, and administrator accounts, and on any cloud service that supports it. Access to those systems requires a second factor in addition to a password.
What is your process for reporting a personal data breach?
We log suspected incidents as soon as they are identified and assess the risk to individuals. Where a breach is likely to result in a risk to people’s rights, we report it to the ICO within 72 hours and notify affected individuals where required.
How is data protected in transit and at rest?
Data is encrypted in transit using TLS. Data at rest is held on reputable cloud services that encrypt stored data by default. We do not store customer data on unencrypted local devices.
How do you control access to systems containing customer data?
Access is granted on a least-privilege basis through individual named accounts, so people only have access to what their role requires. Administrator access is limited to a small number of people and reviewed periodically, and access is removed promptly when someone leaves.
Do you take regular backups, and have you tested restoring them?
Yes. Key systems and data are backed up automatically through our cloud providers, and backups are retained so we can recover from data loss. We periodically confirm that data can be restored.

These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.

Frequently asked questions

How long does a security questionnaire take to complete?

By hand, a typical questionnaire takes a few hours to a couple of days depending on its length and how much you have documented already. Drafting the answers with a tool like Tickbox brings that down to minutes of drafting plus your review time.

Do I need Cyber Essentials to answer one?

No. Cyber Essentials helps and is sometimes requested, but most questionnaires can be answered honestly without it. Where you do not hold it, you simply describe the controls you have in place.

What if a question does not apply to my business?

Answer "not applicable" and add a short reason. For example, if you do not process card payments, a question about cardholder data does not apply, and saying so plainly is the correct answer.

Is what I put in a security questionnaire legally binding?

Your answers form part of your commercial relationship and your customer will rely on them, so they should be accurate. That is exactly why honesty, rather than over-claiming, is the safe approach.

More guides

Answer your questionnaire in minutes

Drop it in and Tickbox drafts every answer for you to review. Your first few are free.

Try it free