Supplier security questionnaire template

Sending a 200-question spreadsheet to a five-person supplier gets you nothing back. This template tiers suppliers by risk and asks proportionate questions you can actually assess — and it produces the evidence ISO 27001 A.5.19 to A.5.22 expect.

Every field, explained

FieldWhat to put in it
Question refStable reference so answers can be compared year on year.
QuestionOne clear question. Avoid compound questions — they produce unscoreable answers.
Tier (1/2/3)Tier 1 = critical supplier with access to personal or production data. Tier 3 = low-impact tooling. Only send the tier-appropriate subset.
Supplier answerThe supplier's own words, kept verbatim.
Evidence providedCertificate, report or screenshot reference. An answer with no evidence scores lower.
Assessor commentYour judgement, including anything you accepted on risk.
Score (0-3)0 not met, 1 partial, 2 met, 3 met with independent assurance.
Follow-up actionOwner and due date where the answer is not acceptable.

Worked examples

Question ref
SEC-04
Question
Is multi-factor authentication enforced for all administrative access?
Tier (1/2/3)
1
Supplier answer
Yes, enforced for all staff via SSO with conditional access.
Evidence provided
Screenshot of conditional access policy; SOC 2 Type II §CC6.1
Assessor comment
Independently assured. No action.
Score (0-3)
3
Follow-up action
Question ref
DP-02
Question
Where is our data stored and processed?
Tier (1/2/3)
1
Supplier answer
UK region primary, EU secondary for disaster recovery.
Evidence provided
Contract schedule 2; DPA clause 7
Assessor comment
Acceptable. EU transfer covered by the UK addendum.
Score (0-3)
2
Follow-up action
Re-confirm at annual review
Question ref
BC-01
Question
Do you test restoration from backup at least annually?
Tier (1/2/3)
2
Supplier answer
Backups run daily; restore testing is ad hoc.
Evidence provided
None
Assessor comment
Gap. Untested backups are not a recovery capability.
Score (0-3)
1
Follow-up action
Supplier to provide restore test evidence by 30 Sep 2026 (Ops Manager)

How to use it

  1. Tier the supplier before you send anything — impact if they fail, plus the data they touch.
  2. Send only the tier-appropriate question set; a shorter questionnaire gets a faster, better answer.
  3. Accept existing assurance (ISO 27001 certificate scope, SOC 2 report, Cyber Essentials) in place of re-answering.
  4. Score consistently so you can compare suppliers and track improvement.
  5. Convert every gap into an owned action with a due date — that is what closes the loop for the auditor.
  6. Re-run tier 1 suppliers annually and on contract renewal.

What auditors pick up

  • Questionnaires sent but never assessed — answers filed with no scoring or comment.
  • Certificate collected once at onboarding and long expired.
  • No supplier tiering, so the same effort is spent on the payroll provider and the stock photo site.
  • Identified gaps with no corrective action or owner.

FAQ

How many questions should a supplier security questionnaire have?

For a tier 1 supplier, 25–40 well-chosen questions is plenty for an SME. Tier 2 typically needs 10–15 and tier 3 can often be satisfied by a certificate check alone.

Can we accept a SOC 2 report instead of a completed questionnaire?

Usually yes for the areas the report covers, provided you read the scope, the period and the exceptions. Record that you reviewed it and note anything the report does not cover.

Which ISO 27001 controls does this evidence?

A.5.19 supplier relationships, A.5.20 supplier agreements, A.5.21 ICT supply chain and A.5.22 monitoring and review of supplier services — plus A.5.23 where the supplier is a cloud service.

Related

Stop maintaining spreadsheets

Every template here exists as a live module inside ISO-STANDARD.app — owners, review dates, evidence links and audit trail included, with AI-generated remediation plans when something fails.

  • Pre-loaded ISO 27001, 9001, 42001 and SOC 2 content
  • Evidence vault with versioning
  • Named owners and review reminders
  • Export back to CSV any time
Start your workspace