Five years ago, supplier data security questionnaires were largely the preserve of large financial institutions, government departments and healthcare organisations. If you were not in their supply chain, you were unlikely to receive one.
That has changed significantly. The questionnaires have followed a clear pattern of trickling down through supply chains, from regulated enterprise to mid-market, from mid-market to SME supplier. The businesses receiving them today are not fundamentally different from the businesses that were not receiving them three years ago. The businesses sending them have simply extended their requirements further down the chain.
What these questionnaires are actually asking
The content of supplier security questionnaires varies but the majority cover a consistent set of areas. Understanding what is being asked, and why, helps both in preparing answers and in understanding what genuinely needs to be in place.
**Cyber security controls**
Questions about what technical security controls are in place. Firewall configuration, endpoint protection, patch management practices, email security, multi-factor authentication. These questions are assessing whether your business has implemented the basics, roughly equivalent to what Cyber Essentials certification tests.
**Data protection practices**
Questions about how personal data is handled. What data you process, on what legal basis, how it is protected, who has access, how long it is retained and what your breach response process looks like. These questions are assessing UK GDPR compliance.
**Access management**
Questions about how user access is managed. How accounts are provisioned and deprovisioned, how administrator access is controlled, whether multi-factor authentication is in place for remote access and privileged accounts.
**Business continuity**
Questions about resilience. Whether you have a tested backup and recovery process, whether you have a business continuity plan, what your recovery time objectives are.
**Third-party risk**
Questions about your own supply chain. What suppliers have access to your systems or data, what due diligence you have conducted on them, whether Data Processing Agreements are in place.
**Certifications and evidence**
Many questionnaires now ask specifically for Cyber Essentials certification, ISO 27001 certification, or other third-party evidence of security practices. The move from self-attestation to third-party evidence is one of the most significant shifts in supplier security requirements over the past two years.
Why this is happening
The organisations sending these questionnaires have learned, often from painful experience, that their supply chain represents a significant attack surface. A large enterprise with sophisticated security controls can still be compromised through a smaller, less well-protected supplier that has privileged access to their systems or data.
The regulatory environment reinforces this. UK GDPR places explicit obligations on data controllers regarding the security practices of their processors. Enterprise legal and compliance teams are increasingly requiring evidence of supplier security as a contractual and regulatory necessity rather than a nice-to-have.
What happens if you cannot answer
In the short term, the questionnaire gets escalated within the client’s procurement or security team. You may be given an opportunity to remediate specific gaps. In some cases there is flexibility on timeline.
In the longer term, businesses that consistently cannot answer these questionnaires satisfactorily are quietly removed from preferred supplier lists or excluded from tender processes before they reach the questionnaire stage. This happens without fanfare, you simply stop being considered.
How to prepare
The good news is that the controls being asked about are not exotic or expensive. They are broadly equivalent to what Cyber Essentials certification tests, five core technical controls that most businesses are closer to implementing than they realise.
The preparation has three elements. First, understand what your current position actually is, not what you assume it is, but what an honest assessment reveals. Second, close the gaps that matter most, prioritised by what is most commonly asked for rather than what is most technically complex. Third, document what you have in place so you can evidence it clearly when asked.
Northstar’s IT and Cyber Risk Review is designed specifically to give you an honest picture of where you stand against these requirements, and what proportionate action looks like for a business of your size.