← Guide

My customer sent a security questionnaire. Now what?

A security questionnaire is how your customer passes on their own duty of care. Filling one in usually costs one to two days, and the next customer sends a different list. So do not answer the list, answer the ten topics underneath it. Then you only have to do it once.

Sixty to two hundred questions, in their own format, with a deadline attached. The questions are about patch policy, log retention and recovery points, and nobody on your side knows the right answer off the top of their head. This piece is about what to do with it.

Why am I getting this list?

Under the Dutch Cybersecurity Act your customer has to demonstrably assess the security of their suppliers, and the questionnaire is their evidence. That also explains why the lists are so long and so unlike each other: every organisation has its own procurement or compliance department making its own version.

There is more about that in Do I have to meet NIS2 as a supplier?.

Do I have to fill in everything?

Almost always there is more in the list than applies to you. Questions about industrial control systems are pointless if you do not have any, and inventing an answer is worse than putting "not applicable" with a line of explanation.

Two things matter more than completeness:

  • Answer honestly. An over-rosy answer comes back the moment something goes wrong, and it is your signature underneath it.
  • Back up what you claim. "Yes, we make backups" is an assertion. "Yes, daily, with a monthly restore test, see the attached policy" is an answer your customer can do something with.

How long will this take me?

For the first list, count on one to two days, most of which goes into working out what is actually being asked. If you have no IT person on staff, add your IT provider's hourly rate to that.

The annoying part is that the investment does not carry over to the next customer. They send a different list, in a different format, with the same questions in different words.

How do I stop doing this over and over?

By not taking the list as your starting point, but the ten topics from article 21(2) of the NIS2 directive. Every serious questionnaire is a translation of them. If you know where you stand on those ten topics, and you have backed that up, every next list becomes filling in rather than figuring out.

That is what Ketenpas was built for. You describe the state of your security once, then share a passport: one page setting out what you have arranged, which you send to a customer instead of answering their form.

If your customer insists on getting their own spreadsheet back, that works too: you upload their file and your saved answers are written into it, so all that is left for you is the review.

Which questions always come up?

Whatever the length and the format, the same six topics recur, and together they account for most of any list:

  • is MFA enforced on email and on everything reachable from the internet
  • are backups made automatically, is one copy out of reach, and has restoring been tested in the past year
  • is there an incident procedure with a reporting deadline, and an incident log
  • is there an adopted security policy with someone responsible named
  • are updates applied in time, and within what deadline for critical vulnerabilities
  • is access withdrawn when someone leaves, and how often do you check that

Get these six in order and on paper and you can answer the bulk of any list without having to call anyone.

Can I send my own document instead of their form?

Asking always works, and it succeeds more often than people think. Buyers want evidence, not a particular file format; a complete, substantiated overview of your measures is often more usable for their file than a half-filled spreadsheet.

Two situations where it does not work: the customer uses a portal that scores answers per question, or the questionnaire is part of a tender where deviating costs points. Then send your own overview along as an attachment to their form. It saves them follow-up questions, and it is exactly the document you will use again at the next customer.

What if something is not arranged yet?

Then you say so, and when you will pick it up. No customer expects a company of thirty people to have everything in order. What they cannot use is a supplier who does not know where they stand.

An open point with a date on it is also a stronger answer than a tick you cannot substantiate. At the next audit, a promise you kept is worth more than a claim that did not hold; see also proving your measures work.

Getting started yourself

Take the free scan: 39 questions in plain language, about ten minutes, no account needed. You will know where you stand and what deserves attention first, and you can share the result with your customer as a passport.

Already have a questionnaire on your desk? With Pro (€39 per month, excl. VAT) you upload it and have the answers filled in from your own scan and evidence. You review it and send it back.

Updated on 5 August 2026