Supplier security questionnaire: template and key questions

What to ask a provider, with what evidence and according to what criticality? A complete method and a downloadable 30-question template.

· 13 min read
Illustration: four glass tiles in a row, the last one orange

A supplier security questionnaire is used to assess a provider's cybersecurity level before entrusting it with your data or access to your information system, and then throughout the contract. To be useful, it must be proportionate to the supplier's criticality, require evidence for every important answer and lead to a decision. This guide, which builds on our article on third-party risk management (TPRM), gives you the method and a downloadable 30-question template.

01

What is a supplier security questionnaire for?

The questionnaire is the basic tool of supplier cybersecurity assessment. It comes in at three points: during selection (to compare offers and rule out a candidate that is too weak), before signing (to know which requirements to put in the contract) and during the relationship (to check the level is maintained). It replaces neither risk analysis nor audit, but it shows where to focus them.

It also meets an obligation. NIS 2 requires taking into account each direct supplier's vulnerabilities and cybersecurity practices, DORA requires due diligence before any ICT services contract, and the GDPR requires working only with processors that provide sufficient guarantees: we detail these texts in our article on third-party risk, NIS 2 and DORA. The stakes are real: according to Verizon's 2025 DBIR, a third party is involved in 30% of the breaches studied.

Questionnaire, audit, external rating: three complementary tools

The questionnaire collects the supplier's own account of its practices; it covers many topics at low cost. An audit, on documents or on site, checks those practices in depth, but is expensive and best kept for critical third parties. External rating services observe what the supplier exposes on the internet (certificates, open ports, known leaks): useful for spotting a weak signal, they say nothing about its internal organisation. A mature approach combines all three according to criticality, and the questionnaire remains the entry point.

02

Matching questionnaire depth to the third party's criticality

Sending 200 questions to an office supplies vendor and 20 to your managed service provider is the most common mistake. Start by ranking your third parties on four criteria, then derive a level:

Four criteria to rank a supplier
CriterionQuestion to ask
DataWhat data do you entrust to it (personal, health, strategic, financial)?
AccessDoes it access your information system, with what privileges, remotely or on site?
Service criticalityWhat happens if the service stops for a day, a week? Does it support a critical or important function within the meaning of DORA?
SubstitutabilityHow much time and effort would it take to replace?

Three levels are enough for most organisations: standard (around ten questions, reviewed at renewal), important (about twenty-five questions with evidence) and critical (full questionnaire, systematic evidence, audit rights). The template below applies this logic: choose a level to see the questionnaire shrink or grow.

03

Question families in a subcontractor security questionnaire

Governance

Does the supplier have a security policy approved by its management, a named owner, a risk assessment covering the service? These questions tell you whether security is managed or endured.

Access management

This is the family that best predicts incidents: multi-factor authentication, named privileged accounts, access reviews, leavers handled promptly, administrative access through a controlled point. ANSSI's outsourcing guide stresses this for remote interventions.

Encryption and data protection

Encryption in transit and at rest, including backups, separation between customers, and above all: who holds the keys? For sensitive data, customer control of the keys significantly changes the risk level.

Operations and vulnerabilities

Patch deadlines, regular penetration tests, centralised and monitored logs: these are the signs of well-run operations.

Backups and continuity

An untested backup is only an assumption. Ask for an isolated copy, a recent restoration test and, for a critical service, recovery objectives (RTO, RPO) consistent with your own business continuity plan.

Incident management

An existing procedure, a notification time stated in hours, a history of recent incidents and the measures taken. The notification time must be compatible with your own reporting obligations.

Fourth parties

Your supplier has suppliers of its own: hosting provider, offshore support, software vendors. Ask for the list, the countries, the requirements it imposes on them and a commitment to inform you of any change. Supply chain attacks often go through this tier that nobody looks at.

Location and hosting

Countries of hosting, backup and access (support counts too), exposure to non-European laws, conditions for returning and deleting data at the end of the contract.

Certifications and qualifications

  • ISO/IEC 27001:2022: certification of the information security management system; everything depends on its scope.
  • HDS: mandatory to host health data in France; the framework published in the Official Journal on 16 May 2024 requires hosting within the European Economic Area and gave already-certified hosts until 16 May 2026 to migrate (see our article on HDS certification).
  • SecNumCloud: ANSSI's qualification for cloud services, which includes requirements for protection against non-European laws (see our SecNumCloud article).
  • SOC 2: a US attestation report; Type II covers the operating effectiveness of controls over a period, Type I only their design at a point in time.
04

Supplier security questionnaire template: 30 questions

Here is our template: 30 questions in nine families, each with the expected evidence and the criticality from which to ask it. It contains 11 questions for a standard supplier, 25 for an important supplier and 30 for a critical supplier.

Template · 30 questions Supplier criticality
30 questions Critical function, sensitive data or privileged access, hard to replace. Suggested review: every year, and after any change

Governance

  1. 01 Do you have an information security policy approved by management and reviewed within the last year? From Standard
    Expected evidence : Dated, approved policy, or its table of contents and approval date
  2. 02 Is a named person responsible for security (CISO or equivalent) and reachable by customers? From Standard
    Expected evidence : Name, role and contact details
  3. 03 Do your staff and contractors receive security awareness training at least once a year? From Important
    Expected evidence : Training programme and participation rate
  4. 04 Have you carried out a risk assessment covering the service you provide to us? From Critical
    Expected evidence : Summary of the assessment: method, date, main risks and measures

Access management

  1. 05 Is multi-factor authentication enforced for all remote access and administrator accounts? From Standard
    Expected evidence : Policy extract or configuration screenshot
  2. 06 Are access rights to our data and systems granted on a need-to-know basis and reviewed at least once a year? From Important
    Expected evidence : Access procedure and record of the last review
  3. 07 Are accounts of people who leave or change roles disabled within a defined time? From Important
    Expected evidence : Leaver procedure and target time
  4. 08 Are privileged accounts named, separate from everyday accounts and inventoried? From Important
    Expected evidence : Privileged account management policy
  5. 09 Do administrative operations on our systems go through a controlled, logged access point (bastion, gateway)? From Critical
    Expected evidence : Architecture diagram and sample access log

Data and encryption

  1. 10 Is our data encrypted in transit with up-to-date protocols (TLS 1.2 or higher)? From Standard
    Expected evidence : Configuration or TLS test report
  2. 11 Is our data encrypted at rest, including in backups? From Important
    Expected evidence : Description of encryption mechanisms
  3. 12 Is our data logically separated from your other customers' data? From Important
    Expected evidence : Description of customer isolation
  4. 13 Who manages the encryption keys, and can we keep control of them? From Critical
    Expected evidence : Description of key management

Operations and vulnerabilities

  1. 14 Do you apply critical security patches within a defined time? From Standard
    Expected evidence : Patch management policy and target times
  2. 15 Is the service penetration-tested or technically audited at least once a year? From Important
    Expected evidence : Summary of the latest report and remediation plan
  3. 16 Are security logs centralised, retained and monitored? From Important
    Expected evidence : Logging scope, retention period, detection setup

Backups and continuity

  1. 17 Is our data backed up at a defined frequency, with at least one isolated or offline copy? From Standard
    Expected evidence : Backup policy
  2. 18 Do you test backup restoration at least once a year? From Important
    Expected evidence : Report of the last restoration test
  3. 19 Do you have a tested business continuity and recovery plan, with recovery time (RTO) and recovery point (RPO) objectives? From Critical
    Expected evidence : Extract from the BCP or DRP and date of the last exercise

Incidents

  1. 20 Do you have a security incident management procedure? From Standard
    Expected evidence : Incident management procedure
  2. 21 Within what time do you commit to notify us of an incident or data breach affecting us? From Standard
    Expected evidence : Contractual commitment stated in hours
  3. 22 Have you had a significant security incident in the last 24 months, and what measures did you take as a result? From Important
    Expected evidence : Statement and summary of corrective actions

Fourth parties (subcontractors)

  1. 23 Do you use subcontractors to deliver the service? Which ones, for what and in which countries? From Standard
    Expected evidence : List of sub-processors
  2. 24 Do you impose on your subcontractors security requirements at least equivalent to ours? From Important
    Expected evidence : Standard clauses and subcontractor assessment process
  3. 25 Do you inform us in advance of any change of subcontractor, with the option to object? From Important
    Expected evidence : Corresponding contract clause

Location and hosting

  1. 26 In which countries is our data hosted, backed up and accessible, including for support? From Standard
    Expected evidence : List of sites and countries
  2. 27 At the end of the contract, how is our data returned and then deleted, and within what time? From Important
    Expected evidence : Exit procedure and template deletion certificate
  3. 28 Is your company or your hosting provider subject to non-European legislation allowing a foreign authority to access our data? From Critical
    Expected evidence : Statement and legal analysis

Certifications

  1. 29 Do you hold certifications or qualifications covering the service (ISO/IEC 27001, HDS, SecNumCloud, SOC 2 Type II report)? From Standard
    Expected evidence : Valid certificate or report
  2. 30 Does the certification scope cover exactly the service, sites and teams relevant to us? From Important
    Expected evidence : Certificate scope and statement of applicability
Levels and review frequencies suggested by Phinasoft as a guide: adapt them to your own third-party classification.

Download the questionnaire template (CSV, 30 questions) UTF-8 CSV file, semicolon-separated: family, question, expected evidence, minimum criticality. It opens in Excel, LibreOffice or Google Sheets.

05

Building on existing frameworks

No need to start from scratch, nor to take everything: draw on recognised frameworks, then cut down.

These standard questionnaires are exhaustive by design: they are catalogues, not questionnaires to send as is. The right reflex is to accept a CAIQ or SIG already completed by the supplier, then only ask the questions specific to your context.

06

What evidence to ask for, and how to check it

A “yes” is only worth something if it can be checked. A few simple checks avoid most bad surprises:

Common evidence and what to check
EvidenceWhat to check
ISO/IEC 27001 certificateValidity, accredited certification body, scope (sites, services, teams), statement of applicability.
SOC 2 reportType II rather than Type I, period covered, exceptions noted by the auditor, controls left to the customer.
HDS, SecNumCloudService listed in the public registers of the French digital health agency or ANSSI, exact scope.
Penetration testDate, scope, tester, whether critical vulnerabilities were fixed.
Policies and proceduresApproval date, consistency with the answers, actual application (one sample record beats a document).
List of subcontractorsCompleteness (hosting, backup, support), countries, role of each.

For a critical supplier, add an interview with its security lead, or even a document or on-site audit if the contract allows: setting these commitments and oversight rights is precisely the role of the security assurance plan.

07

Scoring answers and deciding

A simple scale is enough: two points for a requirement met and evidenced, one point for a partial or unevidenced answer, zero for non-compliance, with non-applicable questions excluded. The score shows a trend; the decision depends on the gaps themselves. A single non-compliance on a managed service provider's multi-factor authentication can justify rejection, whatever the overall score.

The example below shows why verification changes everything: the same supplier goes from “acceptable” to “action plan required” once the evidence is examined.

Scoring · Fictitious example Supplier X, “Important” criticality
  • Multi-factor authentication on remote access Self-declared : Compliant After verification : Compliant Configuration screenshot provided.
  • Backup with an isolated copy Self-declared : Compliant After verification : Partial Policy provided, but all copies remain online.
  • Annual restoration test Self-declared : Compliant After verification : No evidence No test report sent.
  • Incident notification within 24 hours Self-declared : Compliant After verification : Compliant Commitment included in the draft contract.
  • List of subcontractors Self-declared : Compliant After verification : Partial A backup hosting provider is missing from the list.
  • ISO/IEC 27001 scope covering the service Self-declared : Partial After verification : Non-compliant The certificate only covers head office, not managed services.
Self-declared92%
Acceptable
After verification58%
Action plan required
Scale: compliant and evidenced = 2 points, partial or no evidence = 1, non-compliant = 0. Thresholds: 80% or more acceptable, 50 to 79% action plan, under 50% reject or escalate. Indicative scale suggested by Phinasoft.

Four outcomes are possible:

  • accept the supplier as it is;
  • accept with conditions, with a dated action plan written into the contract;
  • formally accept the residual risk, by the risk owner, when the service is indispensable;
  • reject or look for an alternative.
08

Reminders and ongoing follow-up

A questionnaire sent without a deadline rarely comes back. Set a return date (two to three weeks for a full questionnaire), send a reminder halfway, then escalate to the account manager or buyer. Tell the supplier from the start which evidence you expect: that is what takes the longest.

Assessment is not a snapshot. Reassess at a pace set by criticality, and whenever an event justifies it: incident at the supplier, change of subcontractor or hosting, acquisition, extension of the service scope. Starting from the previous assessment rather than from scratch saves both parties time and shows progress.

09

Mistakes to avoid with a third-party questionnaire

  • A questionnaire that is too long: beyond fifty or so questions, answers become generic and turnaround times grow.
  • The same questionnaire for everyone: it wears out small suppliers and stays too light for critical ones.
  • Unverified self-declaration: without evidence, a “yes” is only worth the good faith of whoever wrote it.
  • Closed questions: “Do you have a backup policy?” invites a yes; “How often, with what isolated copy, tested when?” invites a useful answer.
  • Results with no follow-up: a gap that goes into neither an action plan nor the contract served no purpose.
  • Forgetting fourth parties: your software vendor's hosting provider carries part of your risk.

Phinasoft's third-party risk management module follows this approach: you build your questionnaires from a list of requirements, with additional questions for each requirement, your providers answer on a dedicated portal, and you give them feedback (accepted or rejected non-conformities, requests for more information). Each provider has its profile and assessment history, so you can start from the previous one, and requirements can be exported to your security assurance plans. You can see it in a demo.

Summary

01

Proportionate

How deep the questionnaire goes depends on the supplier's criticality: around ten questions for a standard third party, the full set for a critical one.

02

Evidenced

Each question calls for specific evidence. A purely self-declared questionnaire reassures without protecting: check certification scopes, dates and reports.

03

Followed up

Score, decide, record gaps in an action plan and in the contract, then reassess at a pace set by criticality and after every change.

Frequently asked questions

What is a supplier security questionnaire?

It is a list of questions sent to a provider to assess its cybersecurity level before entrusting it with data, access or a service, and then throughout the relationship. It covers governance, access, encryption, backups, incidents, subcontracting, hosting and certifications, and each answer should be backed by evidence.

How many questions should a supplier security questionnaire contain?

It depends on the supplier's criticality. Around ten questions are enough for a third party with no access and no sensitive data; a critical provider justifies a full questionnaire of about thirty targeted questions, backed by evidence and sometimes an audit. Beyond that, answer quality drops and turnaround times grow.

What evidence should you ask a supplier for?

Ask for verifiable items: an ISO/IEC 27001 certificate with its scope and statement of applicability, a SOC 2 Type II report, HDS certification or SecNumCloud qualification, a summary of the latest penetration test, a restoration test report, the list of subcontractors and hosting countries, and the incident management procedure.

Are there standard questionnaires?

Yes. The best known are the Cloud Security Alliance's CAIQ, aligned with its Cloud Controls Matrix and designed for cloud services, and Shared Assessments' SIG, updated every year in Lite and Core versions. In France, ANSSI's outsourcing guide offers standard security requirements that can serve as a base.

Is an ISO 27001 certificate enough to assess a supplier?

No. It is a good signal, but you must check that the certified scope covers the service, sites and teams relevant to you, that the certificate is valid and issued by an accredited body. The certificate also says nothing about your own requirements: location, notification times, reversibility.

How often should you reassess a supplier?

At least at every contract renewal. For a critical supplier, an annual review is recommended, along with a reassessment after any significant change: incident, new subcontractor, change of hosting, acquisition or change in the service provided.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.