Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

15 September 2026  ·  9 minute read

What a customer security questionnaire is actually asking

Forty questions arrive with a ten-day deadline. Most organizations answer them from memory, and the answers are worse than useless, because a questionnaire is a contractual representation rather than a survey.

A customer sends you a security questionnaire. It has forty questions, a deadline of ten working days, and it arrives in the middle of everything else. Somebody in operations is asked to fill it in, probably with help from whoever manages IT, and it goes back with most boxes ticked.

That process fails in a specific way, and the failure is not usually dishonesty. It is that the questions are being read as a survey when they are a contractual representation. An answer you cannot support is a warranty you have given without noticing.

BEFORE YOU ANSWER ANY QUESTION: WORK DOWN, WRITE LASTEach step is two minutes. Each one you skip is a claim the contract inherits.apply in this order1Find the scope wordevery, all, always, within. It is the question.circle it before reading on2Name the artefactwhich export, report or record proves this.cannot name one, cannot answer yes3State the populationwhat it must cover, not what you happen to have.all accounts, all leavers this year4Check you hold it, datedproduced recently enough that a reader accepts it.a 2024 artefact answers 2026 badly5Only now, write the answeryes, qualified with a date, or no.requires one to four, in orderReaching step five without the four above it is how an assumption becomes a warranty.

Five checkboxes and the evidence that closes each. Lift it into your response template; it costs a line and converts a claim into something a reviewer can follow.

Why the questions are worded the way they are

Almost every question in a security questionnaire is asking one of three things, and recognizing which changes how you should answer it.

Does this exist at all

Do you have an information security policy. Do you have an incident response plan. Do you carry cyber insurance. These are binary, easy to answer honestly, and easy to evidence: the document either exists or it does not.

They are also the least informative questions in the set, and the people who write questionnaires know this. A policy proves intent. It proves nothing about operation.

Does it apply to everyone

Is multi-factor authentication enforced. Are all devices encrypted. Do all staff complete training. The operative word in each is the one specifying scope, and it is almost always the word the answer quietly ignores.

Multi-factor authentication covering ninety per cent of accounts is not multi-factor authentication for the purposes of this question. The accounts it does not cover are the ones an attacker will find, and they are disproportionately likely to be the administrative accounts, the service accounts and the accounts belonging to whoever objected to the inconvenience.

Ninety per cent coverage, and the ten per cent is never randomTwenty accounts on a small estate. Eighteen enrolled, two not.svc-backupadmin, exemptedThe two that are left are not a random ten per cent.They are the service account nobody owns, and the administrator exempted because the secondfactor broke a workflow. Both hold more privilege than any of the eighteen, and an attackerenumerating the tenant finds them first.

The exempted administrator is the recurring case. The exemption was granted for a reason, it was never revisited, and it is not recorded anywhere a questionnaire respondent would look.

The honest answer is frequently: yes for staff accounts, not yet for three service accounts and our IT provider's administrative access, both of which are scheduled for closure by a stated date.

That answer is better than a bare yes. It demonstrates that you know your own estate, which is itself the thing being assessed.

Could you demonstrate it today

How quickly is access removed when someone leaves. When did you last test a restore. How long do you retain logs. These look like the first kind of question and they are not. Each has a specific artefact behind it, and the person reading your answer knows what that artefact is.

This is where most questionnaires are answered from memory, and where the answers most often turn out to be wrong. Not deliberately. The person answering genuinely believes access is removed promptly, because that is the process as designed. The leaver list, matched against account disablement timestamps, frequently tells a different story.

The eleven questions that actually differentiate

Across the questionnaires we have seen, a small number of questions do most of the work of separating organizations that manage security from organizations that have bought security products. If you are preparing, start with these.

  • Is multi-factor authentication enforced on all accounts, including administrative and third-party support accounts? The scope qualifier is the question. Answering for staff accounts only, without saying so, is the single most common overstatement.
  • How quickly is access removed when someone leaves, and how do you know? The second clause is doing the work. An organization that can produce the leaver list matched to disablement timestamps is in a different category from one that describes a process.
  • When did you last restore from backup, and how long did it take? A successful backup report establishes that a job ran. It does not establish that the data can be recovered. Organizations routinely discover during an incident that recovery takes days rather than the hours assumed.
  • Could an attacker with administrative credentials delete your backups? If yes, you hold copies rather than backups. This question is appearing in more questionnaires each year because ransomware made it decisive.
  • How long do you retain security logs? The question behind it is whether you could investigate an incident discovered three months after it began, which is the normal case rather than the exception.
  • Who is accountable for security, by name? If the only name is your IT provider, the answer will not be accepted. Accountability cannot be outsourced even where the work is.
  • Has an independent party assessed your controls, and when? Self-assessment is a management tool. It is not assurance, and describing it as assurance is noticed.
  • Do your suppliers have to notify you of a breach, and within what period? Establishes whether your supply chain obligations are contractual or aspirational.
  • What happens if we ask for evidence? Increasingly asked directly. The organizations that answer well have an evidence register; the rest promise to look.
  • Has your incident response plan been exercised? An unexercised plan is a document. The follow-up question is when, and by whom.
  • Have you had a security incident in the last three years? A well-handled incident is not disqualifying. A concealed one is, and concealment is usually discovered during a later incident when it does the most damage.

How to answer when the honest answer is no

The instinct is to answer yes and resolve to fix it afterwards. This is the worst available option and it is worth understanding why.

A questionnaire response is typically incorporated into the contract or relied upon in the supplier assessment that precedes it. An inaccurate answer is a misrepresentation. If the control you claimed is later the one that fails, the questionnaire becomes evidence in a dispute you would otherwise have had a reasonable defense to.

The alternative performs better than people expect. A qualified answer with a remediation date reads as competence:

Not currently. Multi-factor authentication covers all staff accounts and is being extended to service and third-party administrative accounts, with completion scheduled for 31 October 2026. In the interim, those accounts are restricted to named source addresses and their activity is logged and reviewed weekly.

A qualified answer is assembled, not writtenFour parts, in this order. Omit any one and it reads as evasion, or as a bare no.CURRENT STATENot currently.Honest, and first. Never bury it.SCOPE HELDCovers all staffaccounts.What is true today, precisely.GAP AND DATEExtending to service andthird-party admin by 31 Oct.A date, not a quarter.INTERIM CONTROLThose are restricted tonamed addresses, logged.What reduces risk meanwhile.ASSEMBLEDNot currently. Covers all staff accounts; extending to service and third-party administrative accounts by 31 October. In theinterim those accounts are restricted to named source addresses and their activity is logged and reviewed weekly.A bare yes contains none of the four. It is shorter, and it is the answer a reviewer tests first.

Compare that to a bare yes. The qualified answer tells the reader you know your estate, you have a plan with a date, and you have thought about the interim exposure. A reviewer who has read two hundred questionnaires can tell the difference immediately, and the qualified answer is frequently the one that builds confidence.

What to do with the gaps

The most valuable output of a security questionnaire is not the completed questionnaire. It is the list of questions you could not answer with evidence.

That list is a remediation plan somebody else built for you, prioritized by what your customers actually care about. It is also a preview of the next questionnaire, because the questions do not vary much between customers, and of what an insurer will ask at renewal.

What each question is asking you to produceTHE QUESTIONTHE ARTEFACTWHERE FROMPOPULATION IT MUST COVERIs MFA enforced on all accounts?Authentication methods exportIdentity platformEvery account, admin and third partyHow fast is leaver access removed?Leaver list matched to disablement timesHR and identity platformEvery leaver in the periodWhen did you last test a restore?Dated restore record with time takenBackup platformAt least one critical systemHow long are logs retained?Retention config, and a query reaching backLogging platformEvery security-relevant sourceWho is accountable for security?Record naming the individualGovernanceNot applicableThe last column is the one answers omit. An artefact covering part of a population is a sample, not an answer.

Five of the eleven, with what each is asking you to produce. The response kit carries all fifty.

Work through it once and the second questionnaire takes a fraction of the time. Work through it properly, collecting the artefacts rather than just noting the gaps, and you have an evidence register that answers every future request by lookup rather than by scramble.

Preparing before one arrives

The organizations that handle questionnaires well are not the ones with the best security. They are the ones that prepared when nobody was asking.

  • Build the evidence register first. For each control, name the artefact that demonstrates it, the system it comes from, and the population it must cover. Populate it once and maintain it.
  • Answer the eleven questions above honestly, now. Not for a customer. For yourself, with evidence attached where it exists.
  • Keep a standing response document. Most questions repeat across customers. Maintaining one authoritative set of answers, reviewed quarterly, prevents the situation where two people answer the same question differently for two customers.
  • Treat the gap list as a plan. Owners and dates, tracked like any other commitment, and reported to whoever is accountable.

None of this requires a consultant, and none of it requires new software. It requires deciding to find out where you stand before somebody with commercial leverage asks you.

One caution about the answers you copy

There is a growing practice of answering questionnaires from a template, or from another organization's completed response. It saves time and it produces answers that do not describe your organization.

A reviewer detects this quickly. Template answers use vocabulary the rest of your responses do not, they describe controls at a level of sophistication inconsistent with your size, and they fail immediately when the follow-up question asks for the evidence. A questionnaire answered from a template and then tested is worse than one answered honestly and incompletely.

We publish a free response kit covering the fifty questions we see most often, with what each is really testing, the evidence that answers it, and a model answer to adapt. It includes a gap summary, which is the part worth keeping.

If a questionnaire has just arrived

Send us the gap list

Complete our free readiness assessment, send us the result, and we will spend forty-five minutes going through it with you at no charge. If our view is that you can handle this yourself, we will say so and tell you how.