Vendor Risk Management
You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.
A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

If your company sells to anyone bigger than itself, you know the ritual: a customer’s procurement team sends a security questionnaire, and someone on your side loses a week answering it. Here is the part most SMBs miss: you are someone’s big customer too. The payroll provider, the CRM, the IT outsourcer, the logistics platform — to them, you are the enterprise buyer. And nobody on your side is asking them anything.
The numbers say that silence is expensive. Verizon’s 2026 Data Breach Investigations Report found a third party involved in 48% of all breaches — up 60% in a single year. For smaller organisations it is worse: 55% of SMB breaches involve a third party. ENISA’s 2025 Threat Landscape ranks supply-chain compromise among the top three attack vectors in the EU. Your vendors are now your attack surface. This article gives you the questionnaire to send them — 12 questions, the red flags, and a scoring rule.
The questionnaire now travels in both directions
Two things changed. The first is the attacks. When ransomware hit Collins Aerospace’s MUSE check-in platform in September 2025, the victims were not Collins — they were Brussels, Berlin and Heathrow airports, reduced to pen-and-paper boarding for days. One vendor, hundreds of disrupted operations. Attackers have worked out that compromising one supplier beats compromising fifty customers one at a time.
The second is the law. NIS2 Article 21(2)(d) makes supply-chain security a mandatory risk-management measure, and Article 21(3) is specific: entities must consider “the vulnerabilities specific to each direct supplier”, the overall quality of suppliers’ cybersecurity practices, and their secure development procedures. Belgium has been auditing against this since April 2026. France has not transposed: the loi résilience is still unadopted, the European Commission referred France to the Court of Justice on 8 July 2026 asking for a lump sum and daily penalties, and the bill still has no scheduled date for its first reading in the National Assembly, where the ordinary session opens on 1 October. Read that as delay, not reprieve. ANSSI’s Référentiel Cyber France (March 2026) and the MonEspaceNIS2 registration portal already spell out what supplier oversight will look like for the roughly 15,000 entities coming into scope, and the duty arrives whole on the day the law lands — there is no phase-in for Article 21. If NIS2 applies to you — check our NIS2 compliance services if you are not sure — vendor vetting stops being good practice and becomes evidence a regulator can ask for.
The questionnaire now travels in both directions — and the numbers explain why.
Three rules before you send it
Tier first. You do not need to interrogate the coffee supplier. List your vendors (your finance team’s invoice list is the fastest source), then mark the ones that touch your data, your systems, or your ability to operate. In a typical 50–200 person company that is 10 to 20 names. They get the questionnaire; the rest get a lighter touch.
Evidence beats promises. Every yes should come with an attachment — a certificate, a report extract, a screenshot of the setting. A vendor who answers “yes” twelve times in ten minutes without a single document has told you something important.
The questionnaire finds it; the contract fixes it. Answers are a snapshot. Whatever matters — notification deadlines, patch commitments, data return — must end up as a contract clause, or it evaporates at the first incident.
In the financial sector, this is already contract law. DORA Articles 28–30 prescribe the exact contractual provisions financial entities must impose on their ICT providers. If your customers are banks, insurers or payment firms, expect these 12 questions from them — with legal force behind them.
The 12 questions — and the answers that should worry you
Access and identity
1. Is multi-factor authentication enforced on every account that can reach our data or services — including admin and remote access? “Enforced” is the word that matters. Verizon found that fewer than one in four third parties fully fixed missing MFA on their cloud accounts. Red flag: “MFA is available to users.” Available is not enforced.
2. When your staff leave, how quickly are their accounts — and any credentials to our systems — revoked? You are looking for a defined offboarding step with a deadline, ideally same-day. Red flag: no defined process, or shared team accounts that nobody ever rotates.
Incidents and resilience
3. If you have a security incident affecting our data or service, when and how will you tell us? You carry a 24-hour early-warning duty under NIS2 Article 23 and a 72-hour clock under GDPR Article 33 — and yours starts when they call. Ask for hours, a named contact, and a commitment in writing. We mapped how those clocks interact — and why your real deadline is shorter than you think — in One Incident, Three Regulators. Red flag: “we notify as required by law.” That sentence has no phone number in it.
4. Do you have tested backups and a recovery-time commitment for the service we buy from you? Restore tests, not backup jobs, are the proof. Red flag: a recovery time they “aim for” but will not put in the contract.
Governance and proof
5. Who owns information security in your company — name and role? Somebody accountable must exist, even part-time. Red flag: “security is everyone’s responsibility” as the complete answer.
6. Can you show recent independent proof — an ISO 27001 certificate with its scope statement, a SOC 2 report, or a recent penetration-test summary? Read the scope line. A certificate covering “the Dublin datacentre” does not cover the SaaS product you buy. Red flag: “our datacentre is certified” — that is their host’s certificate, not theirs.
Data handling
7. Where is our data stored and processed, and which subprocessors can access it? Under GDPR Article 28 you are entitled to this list, and you cannot assess what you cannot see. Red flag: they cannot produce a subprocessor list, or data leaves the EEA with no named safeguard.
8. Is our data encrypted in transit and at rest — and who holds the keys? A precise answer takes three lines. Red flag: “bank-grade encryption” with no detail. Marketing adjectives are not a cipher.
Patching and development
9. How quickly do you patch critical vulnerabilities in the systems that serve us? Vulnerability exploitation is now the number-one breach entry point — 31% in the 2026 DBIR, having overtaken stolen credentials for the first time. Red flag: no defined timeline for critical patches.
10. If you build the software we use: how is your development pipeline secured — code review, dependency checks, secure development practice? Article 21(3) names suppliers’ “secure development procedures” explicitly, and ENISA documents attackers poisoning open-source and AI development pipelines. From 11 September 2026 there is a second thing to ask: whether they are a manufacturer under the Cyber Resilience Act. If they are, they owe ENISA and their national CSIRT a 24-hour early warning when a vulnerability in their product is actively exploited — and you want to be on the list of people they tell at the same time. Many vendors have not worked out yet that the role applies to them. Red flag: a software vendor with no answer about its own build chain.
Their suppliers, and the exit
11. Who are your critical suppliers, and do you assess them? Your risk does not stop at your vendor — MUSE was the airports’ vendor’s platform. You are asking whether they have ever asked themselves this question. Red flag: visible surprise.
12. When our contract ends, how do we get our data back — in what format, by when — and when is it deleted? The exit is where leverage dies, so agree it at entry. Red flag: no standard data-return process, or deletion “on request” with no deadline.
The 12 questions, six domains — the whole questionnaire on one page.
How to score the answers
Resist the 40-page spreadsheet. Score each answer green (clear answer plus evidence), amber (plausible answer, no evidence or no commitment), or red (evasive, absent, or a red flag above).
| Result | What it means | What you do |
|---|---|---|
| All green | Vendor takes this seriously | Onboard; write the key commitments into the contract |
| 1–3 amber | Normal for a small vendor | Onboard with contractual fixes and a 90-day re-check on the ambers |
| Any red on Q1, Q3 or Q12 | No enforced MFA, no notification commitment, or no exit | Pause. These three are walk-away questions — fix before signature, not after |
| Red elsewhere | Material gap | Escalate to the business owner of the relationship; proceed only with a dated remediation plan |
Send the questionnaire again every year, and immediately after any incident at the vendor. A questionnaire from 2024 tells you about 2024. We made a version of this point in Vendor, Partner, Breach: third-party risk is not a one-time onboarding gate but a relationship you keep auditing.
Your next 30 days
Week one: build the vendor list from finance’s invoice data and tier it — the 10 to 20 that touch data, systems or operations go on top. Week two: send the 12 questions to that top tier with a two-week deadline. Weeks three and four: score what comes back, chase what doesn’t (silence is an answer too), and turn every amber into a contract clause with a date. Then put two reminders in the calendar: annual re-send, and re-send on incident.
If nobody in your company has time to own that cycle, that is not a reason to skip it — it is the definition of a job to delegate. Our Virtual CISO service runs vendor risk as part of the standing security function: tiering, questionnaires, scoring, contract language, and the follow-up nobody else chases.
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.
