---
id: KB-NO-014
url: https://app.codecontract.io/help/regulation/client-security-questionnaires
idioma: en
categoria: normativa
subcategoria: cadena
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-NO-004, KB-IC-010, KB-NO-021, KB-NO-027]
citadoPor: [KB-AD-016]
---

# Client security questionnaires

_A large client sends a hundred questions about how you handle their information. How to answer without dying trying._

**Responde a:** client security questionnaire · they are asking for iso 27001 · answering a supplier security assessment · vendor risk assessment questions

A questionnaire arrives from a large client with dozens or hundreds of questions about how you store their information, who accesses it and what would happen if something failed. Frameworks such as ISO 27001, NIS2 or the GDPR appear by name, and the typical reaction — answering fast so as not to stall the contract — is what gets paid for later.

## The four blocks that repeat

| Block | What they ask | What answers it |
| --- | --- | --- |
| Who has access | How access is granted and removed | Your policy and the activity log |
| Where the data is | Location, providers, subprocessors | The list of who you use and for what |
| What happens if something fails | Backups, recovery, incident notification | Your plan, however short |
| And what certifications you hold | Current certificates and their scope | The certificate, with its scope and date |

> [!IMPORTANT]
> The second half of that last row sinks many companies: holding a certificate is not enough, you must state **what it covers**. A certificate covering one site or one service, presented as if it covered the whole company, is spotted on first review and costs credibility for everything else.

## How to answer without redoing the work each time

1. **Keep the answers you gave, not only the questionnaire** — 80% of questions repeat between clients; answering from scratch each time is the expensive mistake.
2. **With the date of each answer** — What was true two years ago may not be; an undated answer gets copied and ages by itself.
3. **With who validated it** — Technical answers are validated by whoever knows, not by whoever fills in the form.
4. **And without promising what you do not do** — Ticking "yes" for something you have not built becomes a contractual breach the day it is checked.

> [!WARNING]
> The fourth point causes the most trouble and is done most often without noticing. One extra "yes" in a questionnaire is not sales optimism: it becomes part of what you have declared to that client, and if there is ever an incident, your answer is compared with reality.

## What is up to you even without certifications

**En corto**

- Being able to say who accesses what, and prove it with a log.
- Knowing which providers you give data to, and for what.
- Having written what you would do in an incident, even on one page.
- And being able to show that you genuinely check third-party documentation.

Those four are answered with what you already do, provided it is recorded, and they weigh most in the assessment of a small company — more than holding a badge.

> [!NOTE]
> Which frameworks apply, their deadlines and who they bind vary by country, sector and size, and they move. What is described here is how to organise the answer; **what applies to you and from when is a question for your adviser**, not something to infer from a questionnaire.

**Do we need certification to sell to a large company?**

Not always; many accept answers and evidence without a certificate. Ask before investing.

**Can I reuse answers from another client?**

Yes, and it is sensible; what does not work is reusing them without checking the date.

**What if an answer is "we do not have that"?**

It is a valid answer, especially if you say what you do instead. Lying is not.

## Ejemplos

**A small firm receives a security questionnaire from a large client and fills it in one afternoon.**

- Keeps the answers with dates and who validated them
- Corrects two "yes" answers that matched nothing in place

→ The next questionnaire takes two hours and declares nothing they cannot stand behind.

**A hundred questions and two weeks.**

- Starts from the previous questionnaire's answers

→ You begin from something rather than zero.

**Yes is answered to something that cannot be backed up.**

- Links each answer to its document

→ You answer what can be evidenced.

**The always-attached documents are scattered.**

- Gathers the company file in one place

→ Attaching stops being half the job.

**Gaps are spotted and forgotten on submission.**

- Notes what was missing as the year's agenda

→ The next questionnaire finds fewer gaps.

**Each client asks the same on a different form.**

- Reuses the same documentary base

→ The third questionnaire costs an afternoon.
