The 7 Questions Every Enterprise Asks in a Security Questionnaire
Enterprise procurement teams are not trying to catch you out. They're trying to reduce their own risk — and they ask the same questions every time. If you know what's coming, you can prepare answers that close deals instead of stalling them.
Here are the seven questions that appear in almost every enterprise security questionnaire, what the buyer is actually trying to understand, and what a good answer looks like.
1. Do you have ISO 27001 certification or equivalent?
What they're really asking: Can I trust that your security programme is real and independently verified, or is it just a policy document someone wrote?
If you have ISO 27001, this is a one-line answer. If you don't, the honest answer is to describe what you do have — a documented ISMS, regular risk assessments, named controls — and when you plan to certify. A credible roadmap is better than a vague yes.
2. How do you control access to our data?
What they're really asking: If one of your employees goes rogue or gets phished, how much of our data can they reach?
This is an IAM question. Good answers reference least-privilege access, role-based permissions, MFA on all accounts, access reviews, and offboarding procedures. If you're on AWS, you can point to specific controls: IAM policies, no shared credentials, CloudTrail logging every access event.
3. How do you handle a security incident?
What they're really asking: If something goes wrong, will we find out from you or from the news?
They want to see a documented incident response plan with defined roles, escalation paths, and notification timelines. Under GDPR and NIS2, you're required to notify affected parties within 72 hours of a breach. Your answer should reference this and confirm you have the logging in place to detect incidents in the first place.
4. Where is our data stored and processed?
What they're really asking: Are you storing our data in a jurisdiction that creates legal or regulatory problems for us?
For EU buyers, this is a GDPR question. They need to know data stays in the EU or that appropriate transfer mechanisms are in place. If you're on AWS, specify the region (e.g. eu-west-1). If you use any US-based sub-processors, name them and confirm the legal basis for the transfer.
5. How do you manage third-party and supply chain risk?
What they're really asking: Are your suppliers going to be the weak link that exposes us?
List your key sub-processors and infrastructure providers. Describe how you assess them — do you review their security certifications, their terms, their incident history? ISO 27001 requires a supplier security policy; if you have one, reference it here.
6. How do you manage vulnerabilities and patching?
What they're really asking: Are you running software with known critical vulnerabilities?
Describe your patching cadence — how quickly critical patches are applied, how you track CVEs, whether you run automated scanning. If you use AWS, tools like Inspector and Security Hub give you a continuous vulnerability posture you can reference directly.
7. Do you have penetration testing done regularly?
What they're really asking: Have you actually tested whether your defences work, or are you just assuming?
Annual penetration testing by a qualified third party is the standard expectation. If you've had one done, say when and by whom (you don't need to share the report). If you haven't, be honest and give a timeline. Some buyers will accept a recent vulnerability assessment as an interim answer.
The pattern behind all seven
Every question is asking the same thing in a different way: do you take security seriously, do you have evidence of it, and will you tell us when something goes wrong?
The businesses that answer these well aren't necessarily the most secure. They're the ones who have documented what they do, implemented it in their infrastructure, and can point to evidence. That's exactly what a compliance sprint delivers.
Want to talk through what this means for your business?
Get in touch