A customer sent a security questionnaire. What should you do?
Before answering, identify the service and systems being reviewed, assign one response owner, and gather evidence for each material claim. Bring your IT provider into the process, document unknowns and exceptions, and have the right business leader approve commitments before submission.
A cybersecurity consultant can help when your team cannot connect the questions to your actual controls. A vCISO may be a better fit when customer reviews have become recurring work and no one owns the security program.
The goal is an accurate, supportable response and a plan for the gaps that matter to the customer relationship. Filling every box with "yes" does not accomplish that.
Why customers ask for security evidence
When your company receives customer information, connects to customer systems, or supports a critical service, the customer inherits some risk from your practices.
NIST's SP 1305 supply chain quick-start guide, finalized in October 2024, explains how organizations can define and communicate supplier cybersecurity requirements. The FTC's small-business cybersecurity guidance recommends putting vendor security expectations in contracts and reviewing whether those expectations are being met.
NIST also finalized SP 1326 on July 8, 2026, addressing supplier due diligence, including resilience and foundational cybersecurity practices. That guide specifically concerns information and communications technology suppliers; it is not a universal questionnaire mandate for every small business.
HostBreach's interpretation: treat the questionnaire as a request for evidence about a defined business relationship. Ask what the customer needs to understand before spending money on a certification or assessment the customer never requested.
Start with scope, not the spreadsheet
Ask the customer which product, service, legal entity, locations, and data flows the review covers. Confirm the deadline, required evidence, acceptable explanations, and who can resolve ambiguous questions.
Then map the service internally:
- What customer information do you receive, create, store, or transmit?
- Which applications, devices, accounts, and providers support that work?
- Can employees or vendors access customer systems?
- Which controls are operated by your company, your MSP, or a cloud provider?
- What contract language accompanies the questionnaire?
For example, an agency answering for a client file-sharing service should understand that service's accounts, permissions, retention, and recovery. It should not automatically answer for every unrelated system in the business.
Conversely, a narrow scope cannot justify ignoring a shared identity system that gives access to the reviewed service.
If a question changes contractual obligations, involves a warranty, or requires a legal interpretation, involve the person responsible for contracts or counsel. Technical assistance does not replace that judgment.
Use an answer-and-evidence worksheet
Create an internal working record before entering answers into the customer's portal. HostBreach recommends tracking the question, scope, answer, evidence, owner, review date, and any exception or proposed action.
| Customer question | Evidence to request | Assumption to challenge |
|---|---|---|
| Is MFA enforced? | Settings and coverage for relevant accounts, including privileged access and exceptions | Owning an MFA-capable license means MFA is enforced everywhere |
| Are devices patched? | Current device inventory, patch records, exception handling, and provider responsibilities | The MSP's general service description proves current coverage |
| Do you test recovery? | Dated restore-test results for the reviewed service and documented dependencies | Successful backup jobs prove the business can restore operations |
| Can you detect and respond to incidents? | Monitoring scope, escalation contacts, response procedures, and exercise records | An endpoint security subscription establishes a complete response capability |
| Do staff receive security training? | Training content, completion records, cadence, and handling of missed training | Having a policy means staff have completed training |
These are illustrative checks, not a required format or a statement that every customer expects identical evidence.
Where the question is broader than your evidence, qualify the answer. A policy describes what should happen; operational records help establish whether it happens.
How to handle "no," "unknown," and partial coverage
Use the customer's permitted response format. If only yes/no answers are available, ask how to record a limitation rather than hiding it.
An internal draft might say: "MFA is enforced for the named cloud service. Coverage for the legacy application has not yet been verified; the IT owner is checking it."
Do not turn that draft into a final claim until the coverage is confirmed and the responsible owner approves it.
For a validated gap, record:
- the affected service or system;
- the existing protection, if any;
- the action and responsible owner;
- dependencies and a realistic target date; and
- the evidence needed to confirm completion.
Whether the customer accepts a gap or alternative control is the customer's decision. A consultant cannot promise acceptance, a signed contract, or a passing result.
What your MSP should contribute—and what leadership owns
Ask your MSP or internal IT team for evidence of the controls it actually operates. Confirm the service agreement, technical scope, exceptions, and whether the evidence applies to your environment.
Your business still needs someone to coordinate answers about contracts, staff practices, data handling, subcontractors, and incident decisions. Those areas may sit outside the MSP's scope.
A useful division is:
- IT/MSP: supply configuration and operational evidence.
- Cybersecurity consultant: evaluate the evidence, resolve technical ambiguity, and prioritize gaps within the agreed scope.
- Business leadership: approve commitments, resources, and risk decisions.
- vCISO: maintain the process when reviews and security decisions recur.
Read Cybersecurity Consultant vs. MSP for a Small Business for a fuller comparison.
Where the Cyber Intel Exposure Review helps
A questionnaire often starts with the company's internal description of its controls. HostBreach adds an outside-in intelligence layer to help challenge that description.
Within an agreed review, the proprietary Cyber Intel Engine can surface passive observations concerning externally visible infrastructure, credential-exposure indicators, vulnerability context, or email trust conditions. Relevant observations become questions for asset-owner validation.
For example, an externally visible service may warrant checking who owns it, whether it supports the reviewed customer relationship, and which provider maintains it. A historical credential observation may warrant checking account status and identity protections. Neither observation alone proves a current vulnerability, usable password, intrusion, or customer data exposure.
This layer cannot establish MFA coverage, backup restoration, staff training, or compliance from the outside. It complements internal assessment.
The business benefit is a more useful review: what might permit initial access, how access could spread, whether activity would be detected, who would respond, and how operations would recover. These are HostBreach review priorities, not additional questionnaire requirements imposed by NIST.
Should you buy questionnaire help, an assessment, or vCISO support?
Choose the purchase around the underlying problem.
- One questionnaire and credible existing evidence: focused response assistance may be sufficient.
- Unclear controls, conflicting provider answers, or a stalled roadmap: an assessment and action plan may be more useful than editing the spreadsheet.
- Repeated customer reviews and ongoing ownership gaps: consider threat-informed vCISO support.
Before hiring, ask who will perform the work, what evidence they need, whether they will coordinate with your IT provider, what deliverables are included, and who approves the final response. Clarify whether remediation, penetration testing, certification, and future questionnaires require separate work.
For cost and scope comparisons, see Small Business Cybersecurity Assessment Cost.
A clear starting point with HostBreach
HostBreach provides threat-informed cybersecurity advisory for small and midsized businesses.
The $3,500 Small Business Cybersecurity Assessment & Action Plan, including a Cyber Intel Exposure Review, is an initial engagement for businesses that need to understand their security priorities and next steps. Scope, evidence inputs, and schedule are agreed before work begins.
Questionnaire-specific assistance and deliverables must be agreed in the proposal; the price is not a promise to complete unlimited questionnaires or satisfy every customer's requirements. Implementation, specialist testing, and ongoing vCISO work are separate.
Book a free 15-minute call with Franco Velasquez. Bring the reason for the review, deadline, company name, work email, primary website domain, and email domain if different. Sensitive questionnaires and evidence can be shared through an agreed secure process after scope is discussed.
Explore Small Business Cybersecurity Advisory to understand the assessment and buying path.
Primary sources and interpretation
- NIST SP 1305: Cybersecurity Supply Chain Risk Management Quick-Start Guide, final October 21, 2024.
- NIST SP 1326: Due Diligence Assessment Quick-Start Guide, final July 8, 2026; scoped to ICT suppliers.
- FTC: Cybersecurity for Small Business, reviewed October 6, 2026.
The response workflow, illustrative evidence checks, service-selection advice, and threat-informed review priorities are HostBreach recommendations. Applicable obligations depend on the actual customer relationship, contracts, services, and jurisdiction.
