Tickbox Draft your answers free
Guide

Supplier security assurance questionnaires: how to answer one

A customer has asked you to complete a supplier assurance or third-party risk questionnaire before they sign. Here is what they are checking, and how to answer it well as a small supplier.

Last updated: July 2026

Supplier assurance, sometimes called vendor security assessment, third-party risk, or supply chain security, is how a larger organisation checks that the suppliers it depends on protect information properly. If a customer has sent you one, you are being assessed as part of their supply chain, and a clear set of answers is usually the last thing standing between you and a signed contract.

This guide explains what these questionnaires cover, why the questions can feel disproportionate for a small business, and how to answer each area honestly even without a security team.

Draft your answers free →

What supplier assurance actually means

When a customer hands you their data or access to their systems, they inherit the risk that you might not look after it well. Their own regulators, auditors, and customers hold them responsible for that entire chain, so they check each supplier before signing and usually again once a year.

That is all a supplier assurance questionnaire is: their way of getting comfortable that working with you will not become their security problem. It is routine due diligence, not a judgement on your business.

Why a small supplier gets a big-company questionnaire

The form you receive is often a standard template the customer sends to every supplier, from a one-person consultancy to a multinational. That is why a five-person business can be asked about data centre access or a 24/7 security operations centre it does not have.

The answer is not to invent controls to match the question. It is to answer proportionately: describe what you actually do, and where something does not apply to a business your size, say "not applicable" with a short reason. Reviewers expect this from smaller suppliers.

The sections you will usually see

Whatever the template, supplier assurance questionnaires tend to cover the same areas:

How to answer as a small business

The reviewer is looking for honesty, proportionality, and consistency, not enterprise polish. State plainly what you do, keep each answer consistent with the others, and never claim a control you do not actually have. An honest "we do not do this yet, and here is our plan" reads far better than a hollow yes that unravels later.

If you hold Cyber Essentials, say so and give the certificate number, as it answers a whole cluster of technical questions at once. If you do not, simply describe the equivalent controls you have in place.

Proving it: evidence and consistency

Where you can, point to something real: a short policy, your MFA settings, your backup arrangement. You rarely need to attach documents, but answers that reference your actual practices carry more weight than generic statements.

Consistency matters just as much. The same underlying fact, such as who approves access or how you report a breach, should read the same way everywhere it comes up. That is far easier when you answer from a reusable set of approved answers rather than writing each one from scratch.

A faster way to complete it

Supplier assurance questionnaires are long and repetitive, and the same fact is easy to phrase five different ways by the end. Tickbox reads your questionnaire, drafts a grounded answer to every question in your own words, and shows which policy or control each answer draws on. You review, edit, and send. Nothing is submitted on your behalf, and it never claims you are certified. Your first few answers are free, so you can judge the quality on your own document before paying anything.

Example answers to common supplier assurance questions

Do you have a documented information security policy?
Yes. We maintain a written information security policy covering access control, data protection, acceptable use, and incident response. It is owned by our management and reviewed at least annually.
How do you manage third parties and subprocessors who can access customer data?
We keep a list of the subprocessors that support our service, use reputable providers with their own security certifications, and only share the minimum data required. We review this list periodically and put appropriate data processing terms in place.
Do you carry out background checks on staff?
We confirm the identity and right to work of everyone we take on. Given our size, formal screening is applied proportionately to roles that handle customer data, and all staff agree to confidentiality terms.
What is your incident response process?
We log suspected incidents as soon as they are identified, contain and investigate them, and assess the impact on customers and individuals. Where a personal data breach is likely to pose a risk, we notify the ICO within 72 hours and affected customers without undue delay.
Do you hold any recognised security certifications?
We hold Cyber Essentials, which covers the core technical controls a customer usually asks about. Where a question goes beyond that scope, we describe the specific control we have in place.

These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.

Frequently asked questions

Is a supplier assurance questionnaire the same as a security questionnaire?

In practice, yes. "Supplier assurance", "vendor security assessment", "third-party risk questionnaire", and "security questionnaire" all describe the same thing: a customer checking how a supplier protects information before and during the relationship.

We are only a few people. Why are we being asked all of this?

Because the customer usually sends the same template to every supplier. Answer proportionately, describe what you actually do, and mark questions that genuinely do not apply to a business your size as "not applicable" with a brief reason.

Do we need ISO 27001 to pass one?

No. ISO 27001 helps and is sometimes requested for larger contracts, but most supplier assurance questionnaires can be answered honestly without it. Cyber Essentials is a more realistic and widely accepted baseline for a small UK supplier.

How often will we have to complete these?

Often once per customer to win the work, then typically once a year afterwards, plus a fresh one for each new customer. This is exactly why a reusable set of approved answers saves so much time over the year.

More guides

Answer your questionnaire in minutes

Drop it in and Tickbox drafts every answer for you to review. Your first few are free.

Try it free