Start-ups and SMEs
Enterprise Security Reviews

The Deal Was Agreed. Then The Questionnaire Arrived.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
16 September 2026 · 11 min read
GCS Insights cover: The Deal Was Agreed. Then The Questionnaire Arrived. Dark brand panel with the headline in white and red, a standfirst on what an enterprise security review asks for and what a fifty-person company can put in place, and four stat chips: 48% of large UK businesses review their immediate suppliers, 22% of small businesses do the same, 54% of vendors surveyed lost a deal to a late questionnaire, and £440 plus VAT for Cyber Essentials at 10 to 49 staff.

The commercial terms have been agreed and the legal review is complete. A spreadsheet then arrives from a function the founder has never dealt with, carrying somewhere between 60 and 300 questions, and a close that was expected this quarter moves into the next. For a company of thirty or fifty people, that document has become the most expensive stage of the enterprise sales cycle. Very little in it is technically demanding. Almost all of it is demanding to answer for the first time, under time pressure, and the organisations sending it understand that well. The security questionnaire has become the mechanism by which large buyers decide, without saying so, which smaller suppliers they are prepared to carry.

48%
of large UK firms
review their suppliers
22%
of small firms do.
That gap is the delay
54%
of vendors lost a deal
to a late questionnaire
£440
plus VAT. Cyber Essentials,
10 to 49 staff

What the questionnaire is for

It is worth being precise about who sends the review and why, because the answer determines how a supplier should respond to it. The questionnaire does not come from the executive who chose the product. It comes from a supplier risk or third party risk function whose mandate is to ensure that, should a supplier be compromised, the organisation can demonstrate that it asked the appropriate questions beforehand. The reviewer has no interest in obstructing the purchase. Their interest is in assembling a file that will withstand scrutiny after the event.

That reframing matters. When the reviewer asks for an incident response plan, they are asking for a document that can be placed on file, and they are not inviting a discussion of whether one is needed. When they ask about personnel screening, they want evidence of a process rather than an assurance of trust. The exercise runs on evidence, and the National Cyber Security Centre has said as much in its guidance to buyers, observing that "a box ticking approach often leads to a false sense of cyber security." Buyers have been instructed to seek proof. A supplier that arrives with proof completes the review in days. A supplier that arrives with good intentions completes it in months.

The questions themselves are considerably more predictable than most founders expect. The NCSC's published supplier assurance questions, which a large number of UK procurement teams use as their starting point, cover ten areas: security governance, incident management and recovery, network protection, data protection, offshoring, personal data, personnel security, physical security, independent testing and assurance, and contractual matters including subcontractors, audit rights and the treatment of data at exit. Larger buyers in financial services and technology tend to use the Shared Assessments SIG questionnaire, or an instrument derived from it, which covers the same ground in greater depth. The form varies. The structure does not. What varies most is whether the supplier has answered it before.

Why the review has become more demanding this year

Founders who closed enterprise business two or three years ago may assume the questionnaire is the same document with a new date. It is not. Four developments have changed what it asks and how it is enforced.

Public sector procurement now operates under the Procurement Act 2023. Procurement Policy Note 014, which took effect on 24 February 2025, restates the Cyber Essentials requirement for central government departments, executive agencies, non-departmental public bodies and NHS bodies, in respect of contracts that involve citizen data, government employee data, OFFICIAL information or the ICT systems that process it. The note is explicit that Cyber Essentials should not be applied to every contract as a matter of course. For contracts with those characteristics, however, it is the condition of entry, and a growing number of framework operators and local authorities have adopted the same test without any obligation to do so.

Financial services obligations now travel through the contract. The EU's Digital Operational Resilience Act has applied since 17 January 2025. Its Article 30 sets out what a financial entity must include in its contracts with ICT third party providers: service levels, data location, incident support, audit and access rights, and exit arrangements. A UK software company selling to a bank, insurer or payments firm with EU operations will encounter those terms in the security schedule rather than in legislation. The same pattern is arriving in the UK through the Cyber Security and Resilience Bill, which reached Report stage in the House of Lords in September 2026 and is expected to bring managed service providers within the regulated perimeter. Once a managed provider is regulated, the scrutiny applied to its own suppliers increases accordingly.

The buyer's own practice has moved ahead of the supplier's. The government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 48% of large businesses had reviewed the cyber risk posed by their immediate suppliers in the preceding twelve months, against 30% of medium businesses, 22% of small businesses and 12% of micro businesses. The figures are better read as a gap than as a league table. The organisation issuing the questionnaire is roughly twice as likely to operate a supplier review process as the company receiving it, and that difference in preparedness is, in practice, the difference in deal velocity.

Artificial intelligence now has a section of its own. The 2025 edition of the SIG questionnaire introduced a dedicated AI domain, and buyer questionnaires now routinely ask which models a supplier uses, what customer data reaches them and who governs that use. The breaches survey found that only 24% of businesses using AI had security processes in place for it. Most smaller suppliers have no written answer to these questions, and an informal account of which assistant the team uses for drafting does not constitute one.

Infographic titled The Review Gap. Four bars showing the share of UK businesses that reviewed the cyber risk of their immediate suppliers in the last year: large 48%, medium 30%, small 22%, micro 12%. Below, three lines: the buyer sending the questionnaire is twice as likely to have a supplier review process as the company answering it; only 5% of UK businesses hold Cyber Essentials; only 25% have a formal incident response plan. Source: DSIT Cyber Security Breaches Survey 2025/2026.
The organisation issuing the review is roughly twice as likely to operate a process for it as the organisation answering. Source: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, published 30 April 2026.

What it costs

The questionnaire does not cost a founder money directly. It costs time, and in a company of this size the two are indistinguishable. A Whistic survey, cited by Responsive in February 2026, found that 54% of responding vendors had lost deals because they were unable to complete a security questionnaire on time, and that salespeople spent an average of 6.8 hours a month answering them. These are vendor figures from firms with a commercial interest in the problem, and they should be weighed as such. The direction of the finding is not in doubt, and it will be familiar to anyone who has sold into a regulated institution.

The mechanism is unremarkable. A first review at an unprepared company is answered by the founder or the chief technology officer, because nobody else can answer it. Each question that cannot be answered from an existing document becomes a task. Each task takes a week, because the person responsible is also running the business. Each follow-up from the reviewer, and there are always follow-ups, restarts the clock. In the meantime the buyer's budget holder faces a quarter end, a reorganisation or a competing priority, and an opportunity that was live in March is lukewarm by June and closed without decision by September.

There is also a loss that never appears on any report. The breaches survey found that 5% of UK businesses hold Cyber Essentials, rising to 12% of small businesses, from 5% the year before. A growing proportion of buyers, public and private, filter on that certificate before a proposal is read by anyone. A company without it does not lose the bid. It is never invited to submit one, and its pipeline simply looks thinner than the market would justify.

What a fifty-person company can put in place

None of what follows requires a security team, a significant tooling budget or a consultant on retainer. It requires that the work has an owner, that the answers exist before the questions arrive, and that the company can evidence the fundamentals rather than describe them. In order of priority:

  • Give the questionnaire an owner other than the founder. Identify the person who will answer every review from this point, typically the operations lead or the most methodical engineer, and give them the authority to obtain answers from the rest of the business. The first questionnaire takes weeks. The fifth takes a day, provided the same person has answered the previous four.
  • Build the answer file before the next review rather than during it. Take the NCSC's ten areas and write a plain, accurate answer for each, with the supporting document attached: the access control policy, the backup schedule and the date of the last restore test, the incident plan, the list of subprocessors, the position on offshoring. Where the accurate answer is that a control does not yet exist, say so and give the date by which it will. Reviewers place considerably more weight on a dated gap than on an unsupported yes.
  • Obtain Cyber Essentials, and decide now whether Plus is required. The self-assessed certificate costs £320 plus VAT for a micro business and £440 plus VAT for a company of 10 to 49 staff, through IASME. It is the least expensive credible signal in the UK market that the five technical fundamentals are in place, it is a hard requirement for a defined class of public contracts under PPN 014, and it resolves a surprising number of questionnaire lines outright. Plus adds an independent technical audit and becomes worthwhile as soon as a buyer in a regulated sector enters the pipeline.
  • Write and test the incident response plan, and record the test. One in four UK businesses has a formal plan. The reviewer is not asking whether the company would cope with a breach. They are asking for the document, the named roles, the customer notification commitment and evidence of a rehearsal. A two hour tabletop exercise with a written note of the lessons satisfies most reviews and improves the business regardless.
  • Settle the company's position on AI and write it down. Which tools staff may use, what customer data may reach them, and who approved the arrangement. One page is sufficient. This section of the questionnaire is recent enough that a clear answer places a small supplier ahead of many larger ones.
  • Put the security schedule into the sales process rather than after it. Send the answer file and the certificates with the proposal, before they are requested. This moves the review to the point in the cycle at which the opportunity has momentum, and it signals to the reviewer that they are dealing with a supplier who has done this before.
Infographic titled Six Decisions Before The Next Review. 01 Give the questionnaire an owner who is not the founder. 02 Build the answer file before the next review, using the NCSC's ten areas. 03 Get Cyber Essentials, £440 plus VAT for a company of 10 to 49 people, and decide on Plus. 04 Write and test the incident response plan and record the test. 05 Decide your AI position on one page. 06 Send the security schedule with the proposal, before the buyer asks. Closing line: the fifth questionnaire takes a day, but only if the same person answered the first four.
Six decisions a founder can take this month, none of which requires a security team or a tooling budget.

Three questions for the founder

  • If our largest prospect issued a 200 line security review tomorrow, who would answer it, how long would it take, and how many of the answers already exist as documents?
  • Which of the frameworks, panels or customers we intend to pursue next year will filter on Cyber Essentials or ISO 27001 before reading our proposal, and do we know that with certainty or are we assuming it?
  • If a buyer asked what customer data reaches the AI tools our people use, is there a written answer, and would the chief technology officer and the head of sales give the same one?

The strategic takeaway

The enterprise security questionnaire is not a compliance event. It is a stage in the sale, and it is the stage that most smaller companies have never designed for. The buyer's review process is fixed and becoming stricter. The supplier's readiness is the only variable, and it decides whether an opportunity agreed in principle closes in the quarter it was won or drifts into the one after.

A company that treats the questionnaire as an interruption will meet it on every enterprise opportunity it pursues, and will answer it from a standing start each time. A company that treats it as a repeatable element of selling answers it once, keeps the answers current, and converts the slowest stage of the enterprise cycle into the fastest. At this scale, that is the whole distinction between a security posture that consumes revenue and one that generates it.

Confidence note

Confirmed. That the Cyber Security Breaches Survey 2025/2026, published by DSIT and the Home Office on 30 April 2026, reports 48% of large, 30% of medium, 22% of small and 12% of micro businesses reviewing the cyber risk of their immediate suppliers, 15% of all businesses doing so, 6% reviewing the wider supply chain, 5% of businesses holding Cyber Essentials with 12% of small businesses doing so, 25% holding a formal incident response plan, 31% having board level responsibility for cyber security, and 24% of AI using businesses having security processes for it. That the NCSC's supplier assurance questions cover the ten areas listed above and that its supplier assurance guidance contains the quoted line on box ticking; both were published on 17 December 2020. That Procurement Policy Note 014 took effect on 24 February 2025, applies to central government departments, executive agencies, non-departmental public bodies and NHS bodies, and states that Cyber Essentials should not be applied to all contracts as a matter of course. That IASME's published Cyber Essentials assessment fees are £320 for micro, £440 for small, £500 for medium and £600 for large organisations, each plus VAT. That the Digital Operational Resilience Act has applied since 17 January 2025 and that its Article 30 sets contractual requirements for ICT third party providers. That the Cyber Security and Resilience Bill reached Report stage in the House of Lords in September 2026, according to the parliamentary bill record.

Assessed. That the Cyber Security and Resilience Bill will bring managed service providers into scope is drawn from the government's stated intent and from secondary reporting; the final text is not settled. That the 2025 edition of the SIG questionnaire introduced a dedicated AI domain is taken from secondary descriptions of the instrument rather than from Shared Assessments' own documentation. The 54% and 6.8 hour figures come from a Whistic survey as cited by Responsive in an article updated 3 February 2026; the survey's date and sample are not stated there, and both firms sell questionnaire software. The range of 60 to 300 questions is our assessment from questionnaires in general circulation and is not a published statistic. That buyers increasingly filter on Cyber Essentials before reading proposals is our assessment from the direction of procurement policy and observed market practice.

Not known. How many UK enterprise opportunities slip by a quarter or more specifically because of the security review; no independent UK figure exists. How many private sector framework operators now apply Cyber Essentials as a hard gate. Whether the Cyber Security and Resilience Bill will pass in its current form, or when it will commence.

If your largest prospect issued a 200 line security review tomorrow, would you be answering it or building it?

Garzon Cyber Solutions is built for companies at precisely this stage: put the fundamentals in place, map them to what buyers actually ask for, obtain the certificate that opens the door, and give the answer file an owner so that it stays current. Cybersecurity, compliance and talent, delivered in that order, as one capability.

Start the Conversation →
Subscribe to GCS Insights

Sources: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 April 2026 · NCSC, Supplier Assurance Questions, December 2020 · NCSC, Supplier Assurance: Having Confidence in Your Suppliers, December 2020 · Cabinet Office, Procurement Policy Note 014, Cyber Essentials Scheme, February 2025 · IASME, Cyber Essentials Pricing, September 2026 · UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, September 2026 · Regulation (EU) 2022/2554 (DORA), Article 30 · Responsive, What Is a Security Questionnaire, February 2026, citing Whistic · Shared Assessments, Standardized Information Gathering Questionnaire, 2025 edition

Start-ups and SMEs Security Questionnaires Cyber Essentials Procurement Deal Velocity