Blog

Vendor Security Questionnaires: How to Answer Them

A deal is going well. Then procurement sends through a spreadsheet with 180 questions about your security controls, due Friday. Nobody in your business has seen most of these questions before, and the person best placed to answer them is the same person shipping the product.

Vendor security questionnaires are now a standard part of selling to Australian enterprise, government and financial services buyers. Handled badly they cost you weeks and occasionally the deal. Handled well they take a couple of hours and make you look like the safest option on the shortlist. The difference is almost entirely preparation.

Why you are being asked

Your customer is managing their own third party risk. When they hand you their data or plug you into their systems, your weaknesses become their problem, and they have obligations of their own to meet.

For an APRA regulated buyer such as a bank, insurer or superannuation trustee, that pressure comes from CPS 234 for information security and CPS 230 for operational risk, which took effect on 1 July 2025 and includes specific requirements around managing material service providers. Government buyers work to their own frameworks. Most buyers handling personal information have obligations under the Privacy Act, and while the small business exemption still applies to organisations turning over three million dollars or less, there are significant exceptions including health service providers and Commonwealth contractors. The questionnaire is how those obligations reach you.

Understanding that changes how you answer. You are not being interrogated. You are being asked to help someone else document a decision they have to justify internally.

The questionnaires you will see

Standard frameworks

Some buyers use published questionnaires. The SIG from Shared Assessments and the Cloud Security Alliance CAIQ are the two you are most likely to meet. Both are long, both are reusable, and answering one properly gives you most of the answers to the next.

Home grown spreadsheets

More common with Australian mid market buyers. These vary wildly in quality and often contain questions copied from a framework that does not apply to your business, such as questions about data centre physical security when you run entirely on AWS.

Portal based reviews

Larger buyers may use a third party risk platform and invite you into it. The questions are similar. The difference is that your answers persist and get compared against what you said last year, so consistency matters.

A process that scales

The goal is to answer each question well once, then reuse it. Here is the shape of it.

Four step process for answering a customer security questionnaire: qualify it, answer from a library, flag the gaps, feed it back
A repeatable loop. The fourth step is the one that makes the next questionnaire faster.

Step 1: qualify before you answer

Ask your sales contact what the deal is worth and where it sits in the process. A 200 question review for a small pilot may not be worth two engineering days, and it is reasonable to ask whether a summary of your controls and a recent test report would satisfy the reviewer instead.

Also ask who is reviewing it. If it is a security team you will get technical follow up questions. If it is procurement ticking boxes, clarity matters more than depth.

Step 2: answer from a library, not from memory

Build one document containing your approved answers to the questions you keep seeing: access control, encryption, backups, logging, incident response, staff screening, security awareness training, subcontractors, data location and business continuity. Each answer gets an owner and a review date.

This single artefact is the biggest time saver available to a small business. It typically takes a weekend to build and pays for itself quickly.

Step 3: flag the gaps honestly

You will not answer yes to everything, and you are not expected to. A 30 person business is not going to have a 24 hour security operations centre. Say what you do, say what you do not do yet, and where it matters, say when you plan to close it.

Reviewers are used to seeing gaps. What they are not used to is a vendor who states them plainly, and it builds more confidence than a page of yeses. A claim that turns out to be untrue, discovered during an incident or a later audit, is the version that ends relationships.

Step 4: feed every new question back

Every questionnaire teaches you something about what your market expects. New questions go into the library with an approved answer. Repeated questions you keep having to answer no to become an input to your security roadmap.

How ready are you, really

Most Australian small businesses sit on one of four rungs, and knowing which one you are on tells you what to do next.

Four level readiness ladder for security questionnaires, from answering from scratch each time up to holding ISO 27001 certification or a SOC 2 report
Moving from level one to level two is a weekend of work and the biggest single win on this ladder.

The top rung is worth reaching when security reviews are repeatedly slowing down real revenue. Both ISO 27001 certification and a SOC 2 report replace large sections of most questionnaires, because the reviewer can read the certificate or the report instead of asking you to describe every control. Note the wording: ISO 27001 certifies, while SOC 2 is an attestation that produces a report.

What neither one does is remove questionnaires entirely. Expect a shorter one, plus requests for your certificate, your scope statement and evidence of recent testing.

The evidence pack that shortens every review

Assemble these once and keep them current. Between them they answer or shortcut most of what gets asked.

  • Your information security policy set, in a form you are comfortable sharing.
  • An attestation or summary letter from your most recent penetration test, rather than the full report.
  • A simple architecture diagram showing where customer data lives and which region it sits in.
  • Your list of subprocessors and the material services you rely on.
  • Your incident response plan and when you last exercised it.
  • Evidence of security awareness training, including completion rates.
  • Your certificate or audit report, if you hold one, with its scope.

Data location deserves special mention. Australian buyers ask about it constantly, and a clear answer about which regions hold their data, plus who else can access it and from where, resolves several questions at once. Keep it accurate as your infrastructure changes, because this is the answer customers check.

Questions that trip people up

“Do you have a CISO?”

A 40 person company does not need a full time chief information security officer, and answering no with no context reads badly. Name the person accountable for security, describe how they are supported, and if you use an external adviser or a virtual CISO, say so. Reviewers care about accountability, not headcount.

“Describe your penetration testing program”

Frequency, scope and what you do with the findings. “Annual external test of the production platform by a CREST accredited provider, with critical and high findings remediated and retested” answers it. If you have never had one done, that gap is worth closing before your next enterprise deal, not after.

“How do you manage your own suppliers?”

Buyers increasingly want to know that the risk does not simply pass through you. A short register of your material suppliers, what data each one touches and what assurance you hold over them is enough for most reviews.

Common questions

How long should a security questionnaire take to complete?

The first serious one usually takes a few days spread across a couple of people. With an answer library and an evidence pack, most later ones take two to four hours. If every questionnaire still costs you a week, the problem is the process rather than the questions.

Can we refuse to answer some questions?

Yes, and it is better than guessing. Mark items as not applicable with a one line reason, and decline anything that would expose sensitive detail about your own security. No competent reviewer expects a copy of your firewall rules.

Should we get certified just to avoid questionnaires?

Not for that reason alone. Certify when the market is asking for it repeatedly, when deals are stalling on it, or when you have decided you want the discipline of a management system. If one buyer asked once, an answer library and a gap analysis will serve you better and cost far less.

Who should own questionnaires in a small business?

One named person, usually whoever owns security or operations, with input from engineering. Leaving it to whoever happens to be free is how inconsistent answers reach the same customer twice.

What if we answer a question wrong?

Correct it in writing as soon as you notice, and say what the accurate position is. Reviewers deal with corrections regularly and they are not fatal. What damages trust is an inaccurate answer that stands until someone else finds it.

Making security reviews a strength

Security questionnaires are not going away, and for smaller Australian businesses they are quietly an advantage. Larger competitors take weeks to route a review through three teams. You can answer in two days, honestly, with evidence attached, and that is a genuine reason for a buyer to choose you.

Siege Cyber helps Australian businesses build the answer library, the evidence pack and the security program behind them. Have a look at our cyber security advisory services, or get in touch and we will work out what your buyers are actually asking for.