The Deal Was Agreed. Then The Questionnaire Arrived.
The commercial terms have been agreed and the legal review is complete. A spreadsheet then arrives from a function the founder has never dealt with, carrying somewhere between 60 and 300 questions, and a close that was expected this quarter moves into the next. For a company of thirty or fifty people, that document has become the most expensive stage of the enterprise sales cycle. Very little in it is technically demanding. Almost all of it is demanding to answer for the first time, under time pressure, and the organisations sending it understand that well. The security questionnaire has become the mechanism by which large buyers decide, without saying so, which smaller suppliers they are prepared to carry.
review their suppliers
That gap is the delay
to a late questionnaire
10 to 49 staff
What the questionnaire is for
It is worth being precise about who sends the review and why, because the answer determines how a supplier should respond to it. The questionnaire does not come from the executive who chose the product. It comes from a supplier risk or third party risk function whose mandate is to ensure that, should a supplier be compromised, the organisation can demonstrate that it asked the appropriate questions beforehand. The reviewer has no interest in obstructing the purchase. Their interest is in assembling a file that will withstand scrutiny after the event.
That reframing matters. When the reviewer asks for an incident response plan, they are asking for a document that can be placed on file, and they are not inviting a discussion of whether one is needed. When they ask about personnel screening, they want evidence of a process rather than an assurance of trust. The exercise runs on evidence, and the National Cyber Security Centre has said as much in its guidance to buyers, observing that "a box ticking approach often leads to a false sense of cyber security." Buyers have been instructed to seek proof. A supplier that arrives with proof completes the review in days. A supplier that arrives with good intentions completes it in months.
The questions themselves are considerably more predictable than most founders expect. The NCSC's published supplier assurance questions, which a large number of UK procurement teams use as their starting point, cover ten areas: security governance, incident management and recovery, network protection, data protection, offshoring, personal data, personnel security, physical security, independent testing and assurance, and contractual matters including subcontractors, audit rights and the treatment of data at exit. Larger buyers in financial services and technology tend to use the Shared Assessments SIG questionnaire, or an instrument derived from it, which covers the same ground in greater depth. The form varies. The structure does not. What varies most is whether the supplier has answered it before.
Why the review has become more demanding this year
Founders who closed enterprise business two or three years ago may assume the questionnaire is the same document with a new date. It is not. Four developments have changed what it asks and how it is enforced.
Public sector procurement now operates under the Procurement Act 2023. Procurement Policy Note 014, which took effect on 24 February 2025, restates the Cyber Essentials requirement for central government departments, executive agencies, non-departmental public bodies and NHS bodies, in respect of contracts that involve citizen data, government employee data, OFFICIAL information or the ICT systems that process it. The note is explicit that Cyber Essentials should not be applied to every contract as a matter of course. For contracts with those characteristics, however, it is the condition of entry, and a growing number of framework operators and local authorities have adopted the same test without any obligation to do so.
Financial services obligations now travel through the contract. The EU's Digital Operational Resilience Act has applied since 17 January 2025. Its Article 30 sets out what a financial entity must include in its contracts with ICT third party providers: service levels, data location, incident support, audit and access rights, and exit arrangements. A UK software company selling to a bank, insurer or payments firm with EU operations will encounter those terms in the security schedule rather than in legislation. The same pattern is arriving in the UK through the Cyber Security and Resilience Bill, which reached Report stage in the House of Lords in September 2026 and is expected to bring managed service providers within the regulated perimeter. Once a managed provider is regulated, the scrutiny applied to its own suppliers increases accordingly.
The buyer's own practice has moved ahead of the supplier's. The government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 48% of large businesses had reviewed the cyber risk posed by their immediate suppliers in the preceding twelve months, against 30% of medium businesses, 22% of small businesses and 12% of micro businesses. The figures are better read as a gap than as a league table. The organisation issuing the questionnaire is roughly twice as likely to operate a supplier review process as the company receiving it, and that difference in preparedness is, in practice, the difference in deal velocity.
Artificial intelligence now has a section of its own. The 2025 edition of the SIG questionnaire introduced a dedicated AI domain, and buyer questionnaires now routinely ask which models a supplier uses, what customer data reaches them and who governs that use. The breaches survey found that only 24% of businesses using AI had security processes in place for it. Most smaller suppliers have no written answer to these questions, and an informal account of which assistant the team uses for drafting does not constitute one.
What it costs
The questionnaire does not cost a founder money directly. It costs time, and in a company of this size the two are indistinguishable. A Whistic survey, cited by Responsive in February 2026, found that 54% of responding vendors had lost deals because they were unable to complete a security questionnaire on time, and that salespeople spent an average of 6.8 hours a month answering them. These are vendor figures from firms with a commercial interest in the problem, and they should be weighed as such. The direction of the finding is not in doubt, and it will be familiar to anyone who has sold into a regulated institution.
The mechanism is unremarkable. A first review at an unprepared company is answered by the founder or the chief technology officer, because nobody else can answer it. Each question that cannot be answered from an existing document becomes a task. Each task takes a week, because the person responsible is also running the business. Each follow-up from the reviewer, and there are always follow-ups, restarts the clock. In the meantime the buyer's budget holder faces a quarter end, a reorganisation or a competing priority, and an opportunity that was live in March is lukewarm by June and closed without decision by September.
There is also a loss that never appears on any report. The breaches survey found that 5% of UK businesses hold Cyber Essentials, rising to 12% of small businesses, from 5% the year before. A growing proportion of buyers, public and private, filter on that certificate before a proposal is read by anyone. A company without it does not lose the bid. It is never invited to submit one, and its pipeline simply looks thinner than the market would justify.
What a fifty-person company can put in place
None of what follows requires a security team, a significant tooling budget or a consultant on retainer. It requires that the work has an owner, that the answers exist before the questions arrive, and that the company can evidence the fundamentals rather than describe them. In order of priority:
- Give the questionnaire an owner other than the founder. Identify the person who will answer every review from this point, typically the operations lead or the most methodical engineer, and give them the authority to obtain answers from the rest of the business. The first questionnaire takes weeks. The fifth takes a day, provided the same person has answered the previous four.
- Build the answer file before the next review rather than during it. Take the NCSC's ten areas and write a plain, accurate answer for each, with the supporting document attached: the access control policy, the backup schedule and the date of the last restore test, the incident plan, the list of subprocessors, the position on offshoring. Where the accurate answer is that a control does not yet exist, say so and give the date by which it will. Reviewers place considerably more weight on a dated gap than on an unsupported yes.
- Obtain Cyber Essentials, and decide now whether Plus is required. The self-assessed certificate costs £320 plus VAT for a micro business and £440 plus VAT for a company of 10 to 49 staff, through IASME. It is the least expensive credible signal in the UK market that the five technical fundamentals are in place, it is a hard requirement for a defined class of public contracts under PPN 014, and it resolves a surprising number of questionnaire lines outright. Plus adds an independent technical audit and becomes worthwhile as soon as a buyer in a regulated sector enters the pipeline.
- Write and test the incident response plan, and record the test. One in four UK businesses has a formal plan. The reviewer is not asking whether the company would cope with a breach. They are asking for the document, the named roles, the customer notification commitment and evidence of a rehearsal. A two hour tabletop exercise with a written note of the lessons satisfies most reviews and improves the business regardless.
- Settle the company's position on AI and write it down. Which tools staff may use, what customer data may reach them, and who approved the arrangement. One page is sufficient. This section of the questionnaire is recent enough that a clear answer places a small supplier ahead of many larger ones.
- Put the security schedule into the sales process rather than after it. Send the answer file and the certificates with the proposal, before they are requested. This moves the review to the point in the cycle at which the opportunity has momentum, and it signals to the reviewer that they are dealing with a supplier who has done this before.
Three questions for the founder
- If our largest prospect issued a 200 line security review tomorrow, who would answer it, how long would it take, and how many of the answers already exist as documents?
- Which of the frameworks, panels or customers we intend to pursue next year will filter on Cyber Essentials or ISO 27001 before reading our proposal, and do we know that with certainty or are we assuming it?
- If a buyer asked what customer data reaches the AI tools our people use, is there a written answer, and would the chief technology officer and the head of sales give the same one?
The strategic takeaway
The enterprise security questionnaire is not a compliance event. It is a stage in the sale, and it is the stage that most smaller companies have never designed for. The buyer's review process is fixed and becoming stricter. The supplier's readiness is the only variable, and it decides whether an opportunity agreed in principle closes in the quarter it was won or drifts into the one after.
A company that treats the questionnaire as an interruption will meet it on every enterprise opportunity it pursues, and will answer it from a standing start each time. A company that treats it as a repeatable element of selling answers it once, keeps the answers current, and converts the slowest stage of the enterprise cycle into the fastest. At this scale, that is the whole distinction between a security posture that consumes revenue and one that generates it.
Confidence note
Confirmed. That the Cyber Security Breaches Survey 2025/2026, published by DSIT and the Home Office on 30 April 2026, reports 48% of large, 30% of medium, 22% of small and 12% of micro businesses reviewing the cyber risk of their immediate suppliers, 15% of all businesses doing so, 6% reviewing the wider supply chain, 5% of businesses holding Cyber Essentials with 12% of small businesses doing so, 25% holding a formal incident response plan, 31% having board level responsibility for cyber security, and 24% of AI using businesses having security processes for it. That the NCSC's supplier assurance questions cover the ten areas listed above and that its supplier assurance guidance contains the quoted line on box ticking; both were published on 17 December 2020. That Procurement Policy Note 014 took effect on 24 February 2025, applies to central government departments, executive agencies, non-departmental public bodies and NHS bodies, and states that Cyber Essentials should not be applied to all contracts as a matter of course. That IASME's published Cyber Essentials assessment fees are £320 for micro, £440 for small, £500 for medium and £600 for large organisations, each plus VAT. That the Digital Operational Resilience Act has applied since 17 January 2025 and that its Article 30 sets contractual requirements for ICT third party providers. That the Cyber Security and Resilience Bill reached Report stage in the House of Lords in September 2026, according to the parliamentary bill record.
Assessed. That the Cyber Security and Resilience Bill will bring managed service providers into scope is drawn from the government's stated intent and from secondary reporting; the final text is not settled. That the 2025 edition of the SIG questionnaire introduced a dedicated AI domain is taken from secondary descriptions of the instrument rather than from Shared Assessments' own documentation. The 54% and 6.8 hour figures come from a Whistic survey as cited by Responsive in an article updated 3 February 2026; the survey's date and sample are not stated there, and both firms sell questionnaire software. The range of 60 to 300 questions is our assessment from questionnaires in general circulation and is not a published statistic. That buyers increasingly filter on Cyber Essentials before reading proposals is our assessment from the direction of procurement policy and observed market practice.
Not known. How many UK enterprise opportunities slip by a quarter or more specifically because of the security review; no independent UK figure exists. How many private sector framework operators now apply Cyber Essentials as a hard gate. Whether the Cyber Security and Resilience Bill will pass in its current form, or when it will commence.
If your largest prospect issued a 200 line security review tomorrow, would you be answering it or building it?
Garzon Cyber Solutions is built for companies at precisely this stage: put the fundamentals in place, map them to what buyers actually ask for, obtain the certificate that opens the door, and give the answer file an owner so that it stays current. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Sources: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 April 2026 · NCSC, Supplier Assurance Questions, December 2020 · NCSC, Supplier Assurance: Having Confidence in Your Suppliers, December 2020 · Cabinet Office, Procurement Policy Note 014, Cyber Essentials Scheme, February 2025 · IASME, Cyber Essentials Pricing, September 2026 · UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, September 2026 · Regulation (EU) 2022/2554 (DORA), Article 30 · Responsive, What Is a Security Questionnaire, February 2026, citing Whistic · Shared Assessments, Standardized Information Gathering Questionnaire, 2025 edition