The contract is as good as awarded, then the attachment arrives. A customer security questionnaire, 180 rows in Excel, response due within ten working days. From that moment a deal your sales team spent six months building hangs on a file nobody in the building feels responsible for. IT has already planned the week, sales does not know the answers, and the management team hears about it when half the deadline has gone.
This is the normal case in Swiss SMEs, and it is expensive. The security itself is usually fine. It is just that nobody owns the answer.
A customer security questionnaire is a sales process, not an IT process. It rarely fails on missing controls, it fails because nobody owns the answers and the evidence is kept nowhere. An honest no with a date next to it carries further than a polished yes. What you tick becomes binding later, in the contract and in the audit.
A customer questionnaire is a sales process
It arrives through procurement. It helps decide whether the contract happens, and its deadline follows the customer's purchasing process, not your capacity. Treat it as a pure IT task and you hand it to the part of the business with the least time and the least authority to decide.
Because you are deciding something. What you tick in that document, you are promising on behalf of the company. In many procurements the completed questionnaire becomes part of the contract documents, or at least the reference point the customer falls back on later. The Swiss Federal Office for Cyber Security BACS describes exactly this sequence from the customer's side in its guidance on cyber security in the supply chain: suppliers are categorised by risk, assessed through self-declaration or an on-site inspection, and the supplier contract is the instrument that makes the requirements legally binding.
Most SMEs already know this side of the table, only the other way round. Which suppliers can stop your business is the same question, asked by you. The customer sending 180 questions is not being unreasonable. He is doing his homework.
What does a customer check with a security questionnaire?
He is not checking whether you are perfect. He is estimating how risky it is to engage you, and whether he can justify that estimate internally. So what interests him most is who at your end can reach his data, and what happens when something goes wrong at your end. On top of that runs a quiet test: whether your answers agree with each other.
The person at the other end is rarely a security specialist. Usually she sits in procurement or risk management and has to write a recommendation that her manager signs. For that she needs answers that are evidenced and do not contradict one another. A clear "no, we have this compensating measure, and the change is planned by the end of Q2" is something she can file. A soft yes that dissolves at the first follow-up question costs her another round. She remembers that at the next questionnaire.
The reflex goes: we finally need a certificate, then this will stop. Honestly, it does not stop, it gets shorter. What makes the difference today is less spectacular and considerably cheaper than a certificate or another GRC tool. A maintained set of answers and evidence, and a name that stands behind it. More protection, fewer tools, lower cost.
Where questionnaires fail
Almost never on missing controls. In our experience it comes down to three other things.
- Nobody owns the answer. Three people each fill in a block, from memory, without knowing about each other. The result reads like three different companies.
- The evidence is kept nowhere. The policy sits in one employee's personal folder, the screenshot is two years old, and the restore test did happen but was never recorded.
- The answers contradict each other. Question 14 says multi-factor authentication applies everywhere. Question 96 names three exceptions. That gets noticed, because consistency is the thing a customer can check without knowing your systems.
Here is how that looks in practice. A supplier with around 150 employees, decent IT, multi-factor authentication across the board, backups tested twice a year. The questionnaire from a German group customer still went into a second round. Four answers contradicted each other, and for the restore test there was no record, only the administrator's recollection that it had gone well. The security was in order. Demonstrable it was not. The close slipped by six weeks, during which nothing changed technically.
What does it cost to answer a customer questionnaire?
The first time, in our experience, two to four person-days spread over two weeks, because the searching takes longer than the answering. By the fourth questionnaire it is often only hours, provided somebody maintained the set in between. The larger item appears on no timesheet: the weeks the close sits still.
That makes it a sales calculation. An order that slips by six weeks costs most SMEs more than the ability to answer such questions on the spot. In our engagements that ability is part of the base scope. Customer questionnaires and supplier audits are answered within the retainer, with maintained evidence rather than night shifts before the deadline. What the three packages cover in detail is on the homepage. The CISO Retainer starts at CHF 4'900 per month, with a six-month minimum term.
For companies with an IT lead who can already handle this operationally and only wants a second opinion, that is often oversized. CISO Sparring exists for that, from CHF 2'400 per month with two days a month. It is enough to review answers and prepare a walkthrough, without anyone handing responsibility out of the house.
Incidentally, this is the one occasion in the year when the management team does not see security as a cost centre. A questionnaire blocking a close makes the link between security work and revenue visible without anyone having to explain it. Anyone who needs budget for evidence upkeep or an ISMS will get it more easily after a case like that than after any risk presentation.
When "no" is the better answer
A questionnaire is rarely passed or failed. It is a risk rating, and a rating tolerates gaps as long as they are named and placed in context. What it does not tolerate is surprises that surface later. So what matters is less what you tick than whether it holds.
| Answer | What the customer does with it |
|---|---|
| Yes, with evidence | Ticks it off and reads on. |
| Yes, without evidence | Asks again. Costs a round and some trust. |
| A polished yes | Becomes a commitment and surfaces in the walkthrough, usually at the wrong moment. |
| No, with a compensating measure and a date | Recorded as a known residual risk he can work with. |
| Not applicable, with one sentence of reasoning | Accepted as a rule. |
The reason for that sits in the contract. Your ticks become binding the moment the contract refers to them, and BACS explicitly names the supplier contract as the instrument that makes security requirements legally valid. Anyone who was optimistic while filling it in explains that next spring at the audit walkthrough. With an audience.
When is a certificate worth more than an endless run of questionnaires?
When the same questions arrive several times a year from the same customer segment and the effort of answering exceeds the effort of building. A certificate rarely replaces the questionnaire entirely. It shortens it, because part of the questions are settled with a reference, and it moves the conversation from "prove it to us" to "show us your scope".
Which proof carries weight depends on the customer, not on the standard. Whether ISO 27001 or SOC 2 is the right proof is decided in sales. If you want to measure your own position soberly first, without starting a certification project, BACS provides an assessment tool with the IKT-Minimalstandard, the Swiss minimum standard for ICT resilience, which lets you establish your own maturity level. The standard is binding only for the electricity and gas sectors; all other operators of critical infrastructure are recommended to implement it. As an honest self-assessment it also serves an SME that simply wants to know where it stands before a customer asks.
What changes when somebody owns the questionnaire
The customer questionnaire becomes a process with a name on it. One voice answers outwards, the same voice sits in the audit walkthrough later, and the evidence is maintained because it is needed anyway and not because a deadline is pressing. This is unglamorous. It is also the difference between ten working days of stress and half a day of work.
The second part gets thrown away almost every time. A customer questionnaire is the most accurate market research you get for free. It shows early what your customers will soon require contractually. When three customers in a row ask about logging of administrator access, that is not harassment, it is your next budget line. Anyone who only works through questionnaires and files them pays the same price again later, then under time pressure.
Frequently asked questions
Who should sign the questionnaire in the company?
Not the person who knows the most, but the one who can stand behind the commitment. The content is prepared by IT or by security leadership, and it is signed as a rule at management level. The separation sounds bureaucratic, but it prevents the most common mistake: that somebody promises something out of helpfulness which the company then has to keep.
Are we allowed to leave questions open?
Yes, with a reason. A "not applicable" plus one sentence of context is better than an invented answer, and confidentiality is a valid reason too. You do not have to disclose details of your protective measures or of other customers. Experienced assessors do not count a reasoned silence as a gap; evasion they do.
What if the customer also wants an on-site audit?
Then what you wrote gets checked. BACS names self-declaration and on-site inspection as the two routes by which a customer assesses its suppliers. The questionnaire is therefore often only the first stage. For companies that answered honestly, an appointment like that is uneventful. For everyone else it is the day the optimistic answers fall due.
Who answered your last customer questionnaire, and whether those answers can still be found today, says more about your security organisation than any tool inventory. In most companies nobody knows offhand. That is not an accusation, it is the normal state. It is also the reason the next questionnaire will cost another ten working days.
