If a bigger customer has sent you a security questionnaire, take a breath: this is routine, it is not a test you can fail, and you almost certainly know more of the answers than you think. It usually means the deal is going well and their procurement team is doing its due diligence before signing.
This guide walks through what these questionnaires are, why you were sent one, how to answer well, and gives worked examples for the questions that come up again and again.
Draft your answers free →What a security questionnaire actually is
A security questionnaire (sometimes called a vendor security assessment, third-party risk assessment, or supplier due-diligence questionnaire) is a list of questions a customer asks a supplier to understand how they protect information. They range from a dozen questions to a few hundred.
Some are industry-standard templates (you may see names like SIG, CAIQ, or a spreadsheet based on ISO 27001), and many are a customer’s own bespoke form. Whatever the format, they tend to probe the same handful of themes:
- Information security: access control, multi-factor authentication, encryption, patching, malware protection.
- Data protection: how you handle personal data under UK GDPR, breach processes, retention, and deletion.
- Operational resilience: backups, business continuity, and incident response.
- Governance: who owns security, what policies you hold, staff training, and your use of subcontractors.
Why your customer sent it
When a customer trusts you with their data or access to their systems, they take on the risk that you might not protect it well. Regulators and their own customers hold them accountable for that whole supply chain, so they check their suppliers before signing, and often once a year afterwards.
In other words, this is not personal and it is not a trap. It is a box they need to tick, and a clear, honest set of answers is exactly what unblocks the deal.
Before you start: gather a few facts
Most of the questionnaire is faster to answer once you have these to hand:
- Who is responsible for security and data protection in your business (often the founder or an IT provider).
- What tools and cloud services you use (email, file storage, your main systems) and whether MFA is on.
- Any policies you already have written down, even short ones.
- Whether you hold Cyber Essentials, or are working towards it.
- Your ICO registration number, if you process personal data.
How to answer well
A good answer is honest, specific, and consistent with your other answers. You do not need to sound like a large enterprise, and you should never claim a control you do not actually have. A confident "we do X" that turns out to be untrue is far worse than an honest "we do not do this yet, and here is our plan".
Two things trip people up. First, "not applicable" is a perfectly valid answer when a question genuinely does not apply to a small business, as long as you say briefly why. Second, keep it plain: reviewers read hundreds of these, and a clear sentence beats a wall of jargon every time.
What if you can’t answer "yes"?
You will not have everything, and that is fine. The honest, low-risk way to handle a gap is to say what you do today and what you are putting in place. For example: "We do not currently enforce MFA on every system. We are rolling it out across our cloud services this quarter." Buyers see this constantly and generally prefer honesty with a plan over a hollow yes.
A faster way to draft the whole thing
Working through a long questionnaire by hand is slow, and it is easy to answer the same underlying question five different ways. Tickbox reads your questionnaire, drafts a grounded answer to every question in your own words, and shows you which control or policy each answer draws on. You review, edit, and send. Nothing is submitted on your behalf, and it never claims you are certified. Your first few answers are free, so you can see the quality on your own document before paying anything.
Example answers to common questions
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
How long does a security questionnaire take to complete?
By hand, a typical questionnaire takes a few hours to a couple of days depending on its length and how much you have documented already. Drafting the answers with a tool like Tickbox brings that down to minutes of drafting plus your review time.
Do I need Cyber Essentials to answer one?
No. Cyber Essentials helps and is sometimes requested, but most questionnaires can be answered honestly without it. Where you do not hold it, you simply describe the controls you have in place.
What if a question does not apply to my business?
Answer "not applicable" and add a short reason. For example, if you do not process card payments, a question about cardholder data does not apply, and saying so plainly is the correct answer.
Is what I put in a security questionnaire legally binding?
Your answers form part of your commercial relationship and your customer will rely on them, so they should be accurate. That is exactly why honesty, rather than over-claiming, is the safe approach.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free