Guide
How to answer a security questionnaire from a customer
By Ahmed Hussein, Founder of Securevoo · Updated
A security questionnaire (also called a supplier assurance questionnaire, vendor security questionnaire or SAQ) is how a buyer checks your security before they sign. It is not an exam you pass by sounding confident. Every "yes" is a statement the buyer may rely on in the contract, so the goal is answers that are accurate, specific and backed by evidence. This guide walks through doing that, step by step, for UK suppliers.
1. Work out what you have been sent, and why
Before answering anything, establish three things. Who is asking — a procurement team, the buyer's security team, or a third-party risk platform acting for them. What format it is — a custom spreadsheet, a standard set such as SIG Lite or CAIQ, a Word document, or a web portal. And what it is gating — is it a condition of signing, or a periodic review of an existing supplier? The answer tells you how much detail they expect and how fast they need it.
Ask for the deadline in writing, and ask whether they accept existing certificates in place of sections. Many buyers will accept a valid Cyber Essentials or ISO 27001 certificate for a whole block of questions if you ask.
2. Triage before you write a single answer
Read the whole questionnaire first and sort every question into one of four piles:
- Answered before. You have given this answer to another buyer and it is still true. Reuse it, after checking nothing has changed.
- Answerable from evidence. The truth is sitting in a system: your identity provider knows whether MFA is enforced, your patch records know how fast critical updates went in.
- Needs a human decision. Policy and judgement questions — your incident response process, your stance on subcontractors.
- Not applicable. Questions about things you genuinely do not do (for example, card payment handling). Say so and give the reason in one line.
Triage turns a 200-question spreadsheet from an afternoon of dread into a list of perhaps twenty things that actually need thought.
3. Answer from evidence, not memory
The most common failure is answering from what people believe is configured rather than what is. Before you write "MFA is enforced for all users", export the policy from Microsoft Entra, Okta or Google Workspace and check there are no exempt accounts or applications. Before you write "critical patches are applied within 14 days", check the update logs against the dates the fixes were released.
Those two examples are not arbitrary. Cyber Essentials v3.3 requires high and critical security updates to be applied within 14 days of release, and multi-factor authentication on cloud services for all users. If your answers say you meet Cyber Essentials, your evidence has to show both.
4. Be honest about gaps
You will find questions where the true answer is "no" or "not yet". Do not write an aspirational "yes". A buyer who discovers a false answer after signing has grounds to treat it as a misrepresentation, and it destroys trust far more than the gap itself would have.
A good gap answer has three parts:
- the honest current state ("MFA is enforced for staff; two service accounts are exempt");
- any compensating control ("those accounts are restricted to a fixed IP range and monitored");
- a remediation plan with a date ("replacing both with managed identities by 31 March").
Buyers see gaps every day. What they are judging is whether you know about them and have a plan.
5. Keep answers short, specific and consistent
Answer the question asked, in two or three sentences, and name the actual control: "Laptops are encrypted with BitLocker, enforced by Intune policy; compliance is reported daily" beats a paragraph about your commitment to security. Keep a library of approved answers so the same question gets the same answer for every buyer — buyers compare notes, and inconsistent answers invite follow-up questions.
6. Map answers to the frameworks the buyer cares about
Many UK buyers structure questions around ISO/IEC 27001:2022. Its Annex A groups controls into four themes: organisational (A.5), people (A.6), physical (A.7) and technological (A.8). Citing the control reference next to your answer (for example "A.8.8, management of technical vulnerabilities") shows the buyer you understand what they are really asking. If you hold a certificate, cite it and give the buyer a way to check it; Cyber Essentials certificates can be verified on the IASME registry.
7. Return it in their format, and make it checkable
Send the questionnaire back in exactly the format you received it — their spreadsheet, their column layout, their dropdown values. A reformatted PDF creates work for the reviewer and looks evasive. Attach supporting evidence where it helps (a policy excerpt, a redacted configuration export, a certificate), and keep it redacted: never send raw logs containing internal hostnames, IP addresses or personal data.
8. Keep a record of who approved what
Record who signed off each answer, when, and what evidence it rested on, with the date that evidence was collected. When the next buyer asks the same question — or this buyer comes back a year later — you can reuse what is still true and re-check what might have changed.
Where Securevoo fits
Securevoo automates steps 2 to 8 for UK compliance consultancies and the companies they support: deterministic triage, verdicts computed by code from live evidence rather than by an AI, drafts that cite their evidence, a human sign-off queue with an audit trail, and the buyer's own workbook handed back filled in. Questions the evidence cannot support are flagged, never guessed. See how it works for consultancies or write to ahmed@securevoo.com.
Stuck on one right now?
Our Emergency Unblock service answers one urgent questionnaire from your own evidence, human-signed, the same day, for £150–£300.