The SME guide to passing client security questionnaires
If a larger client has ever sent you a spreadsheet of security questions before they would sign, you already know how much can ride on it. Increasingly, the answers decide whether the contract goes ahead. This guide explains what these questionnaires are really checking, the handful of controls they almost always come back to, and how to answer in a way that is both honest and convincing.
A security questionnaire is a due diligence document. Before a client trusts you with their data, systems, or access, they want evidence that you will not become the weak link that leads to their breach. Some questionnaires are a short one-page form. Others run to hundreds of rows mapped to a standard such as ISO 27001, SOC 2, or the NIST framework. Whatever the length, the underlying question is the same: if we let you in, are we taking on unacceptable risk?
Why they are becoming unavoidable
Supply chain attacks have taught larger organisations that their security is only as strong as their smallest supplier. Regulators, cyber insurers, and their own clients now expect them to vet the businesses they work with. That expectation flows downhill, which is why a 15-person agency or a boutique consultancy is now being asked the sorts of questions that used to be reserved for enterprise vendors. It is not personal, and it is not going away. Treating it as a normal part of winning larger work is the healthier mindset.
The controls they almost always ask about
The wording varies, but the vast majority of questionnaires circle the same core controls. If you have these in place and can describe them clearly, you will answer most of any questionnaire without breaking a sweat.
- Multi-factor authentication (MFA): is it enforced on email and key systems for every user, not just offered as an option?
- Access control: how do you grant access, review it, and remove it when someone leaves?
- Device security: are laptops encrypted, patched, and protected with endpoint security software?
- Data backup: do you back up important data, and have you actually tested that you can restore it?
- Patching and updates: how quickly are operating systems and software updated when fixes are released?
- Security awareness: do staff receive any training on phishing and safe handling of data?
- Incident response: if something did go wrong, do you have a basic plan for how you would respond and notify affected parties?
The pattern to notice
These are the same controls that underpin the Cyber Essentials scheme and most cyber insurance policies. Get them in place once and you satisfy questionnaires, insurers, and certification at the same time.
How to answer honestly without overclaiming
The single biggest mistake is to exaggerate. It is tempting to tick every box green to get the contract, but a good client will ask for evidence, and a great one will audit you later. If you claim a control you do not have and an incident then exposes the gap, you have turned a security problem into a breach of contract and a broken relationship. Honesty is not just ethical here, it is commercially safer.
Where you do not yet meet a requirement, say so plainly and describe your plan and timeline to close the gap. Buyers see far more half-truths than honest roadmaps, and a credible plan often reassures them more than a suspiciously perfect scorecard. Answer in specifics rather than adjectives: "MFA is enforced for all users on Microsoft 365 via conditional access" tells a reviewer far more than "we take security seriously".
Common mistakes that cost the contract
- Leaving it to the last minute, then rushing answers that do not stand up to a follow-up call.
- Having one person guess at answers about systems they do not manage.
- Describing intentions as if they were already in place.
- Ignoring the free-text boxes, where a clear sentence often matters more than the yes or no.
- Never revisiting the answers, so last year's questionnaire no longer matches reality.
Get ahead of the next one
The businesses that find questionnaires easy are the ones that treat security as an ongoing programme rather than a scramble per deal. Put the core controls in place, keep a short internal document that records how each one works, and update it when things change. Then every new questionnaire becomes a copy, paste, and tailor exercise rather than a fire drill. That is exactly the position we get our clients into, and it is often the difference between winning larger contracts and quietly losing them.