What Your Biggest Customer's Security Questionnaire Really Wants
A 40-question security questionnaire from your top customer isn't busywork. Here's what each section actually checks and how Texas SMBs should answer it.
The Email That Changes Everything
A machine shop outside Katy landed a contract that would double its revenue. Then came the follow-up email from the customer's procurement team: a 42-question spreadsheet titled "Third-Party Security Assessment." Questions about MFA, encryption at rest, incident response runbooks, subcontractor access, backup testing cadence. The owner had never heard of half these terms. He called us the same afternoon, half-convinced the deal was already dead.
It wasn't dead. But that questionnaire wasn't a formality either. Big customers - manufacturers, healthcare systems, banks, energy companies - have learned the hard way that their own security is only as strong as their weakest vendor. They're not asking these questions to slow you down. They're asking because credential abuse shows up in some form in 39% of breaches, according to the Verizon 2026 DBIR (as of 2026-08-20), and a lot of those credentials come in through a trusted third party nobody vetted closely.
What They're Actually Screening For
Are You a Soft Target Inside Their Supply Chain?
Attackers know that hitting a small vendor with weak controls is easier than hitting the enterprise directly, and it can get them the same access if that vendor has a VPN connection, a shared portal login, or an EDI feed into the bigger company's systems. The questionnaire is a proxy for one question: if we let you in, does that widen our attack surface or not?
Will You Tell Them When Something Breaks?
Incident response questions aren't about whether you'll ever have an incident - everyone eventually does. They're about whether you have a defined process to detect it, contain it, and notify affected parties on a timeline that doesn't leave the customer finding out from a news story. A vague answer here worries reviewers more than an honest "we're building this out."
Can You Prove It, Not Just Say It?
Mature questionnaires ask for evidence - policy documents, a SOC 2 letter, screenshots of MFA enforcement, a patch cadence report. Weak vendors write "yes" next to every line item with nothing behind it. Reviewers have seen that pattern enough times to spot it instantly, and it usually triggers a deeper follow-up call, not approval.
Decoding the Standard Categories
Access Control and MFA
This section wants to know if a stolen password alone can get an attacker into your systems. If you haven't enforced multi-factor authentication on email, VPN, and admin accounts, this is the first gap to close, and it's usually the cheapest one to fix. Layering in least-privilege access and formal privileged access management answers several questionnaire lines at once - who has admin rights, how often that's reviewed, and whether access is revoked promptly when someone leaves.
Encryption in Transit and at Rest
They want confirmation that data moving between your systems and theirs, and data sitting on your servers or in your cloud tenant, isn't sitting in plain text. If you're running Microsoft 365, most of this is already available - it just needs to be configured correctly, which is where a lot of smaller shops fall short without dedicated Microsoft 365 management in place.
Incident Response Plan
They're checking for a written plan with named roles, not tribal knowledge in one person's head. Who calls the customer? Within how many hours? Who talks to law enforcement or insurance? If you don't have this documented, it's worth building even outside the questionnaire - ransomware recovery costs a median of $375,000 excluding any ransom payment, per Sophos's State of Ransomware 2026 report (as of 2026-08-20), and having a plan cuts both the cost and the chaos.
Third-Party and Subcontractor Risk
If you outsource IT, payroll, or any data processing, they want to know you've vetted those vendors too. This is the same due diligence being asked of you, just one layer down. Keep a short list of your critical vendors and what each one can access.
Backup and Disaster Recovery
Not "do you have backups" but "have you tested restoring from them, and how fast can you get back online." A backup nobody's tested is a hope, not a plan.
Patch and Vulnerability Management
This is where a lot of vendors get caught flat. Reviewers increasingly ask how long it takes you to remediate known exploited vulnerabilities once flagged. The 2026 DBIR found the median time to fully remediate a KEV-listed vulnerability sits at 43 days, up from 32 the prior year (as of 2026-08-20) - and if your answer is "we don't track that," it's a red flag worth fixing before the next questionnaire lands.
The Texas Angle: SB 2610 and CIS IG1
Texas businesses with 20 to 99 employees got a real incentive to formalize this under SB 2610, effective September 1, 2025. If you implement the CIS Controls Implementation Group 1 - 56 specific safeguards covering things like MFA, asset inventory, and access control - you're shielded from exemplary damages if you're sued after a breach. It doesn't create a lawsuit where none existed, and it only bars exemplary damages, but it gives you a concrete framework to point to both for the law and for the customer questionnaire sitting in your inbox. Most of what IG1 requires overlaps directly with what these questionnaires ask, which means doing the work once satisfies both.
How to Answer Without Lying (or Panicking)
Don't write "yes" to something you can't back up - reviewers check references and follow up on inconsistent answers. Where you have a real gap, say so and attach a remediation date. A questionnaire answer that says "MFA enforced on all cloud accounts, rolled out Q3 2026" carries more weight than a blank "yes" with nothing behind it. If your internal IT function can't produce evidence quickly, that's usually a sign your managed IT services setup needs a harder look, possibly alongside a broader cybersecurity assessment before the next big customer comes calling.
What Happens If You Fail
Sometimes nothing dramatic - just a request for a remediation plan and a follow-up review in 90 days. Sometimes it's the deal walking. Larger customers, especially in regulated industries touching HIPAA data or subject to the FTC Safeguards Rule, increasingly can't accept vendor risk they can't document, no matter how good the relationship is otherwise.
One Step to Take This Week
Pull last year's questionnaire, or draft one from a competitor's public template, and score yourself honestly against it before the real one arrives. If you're weighing whether your current provider can produce that evidence on demand, our guide to switching IT providers walks through what a real transition looks like. Businesses around The Woodlands and Katy come to us with this exact scenario every quarter, usually with a deadline already ticking.
Frequently Asked Questions
How long does it usually take to complete a big customer's security questionnaire?
If your documentation is already in order, a day or two. If you're starting from scratch - writing an incident response plan, gathering MFA proof, documenting backup tests - budget two to four weeks, longer if you're also closing real gaps.
Do I need a SOC 2 report to pass these questionnaires?
Not always. Many mid-size customers accept a completed questionnaire plus supporting evidence in place of a formal audit report. Larger enterprises or regulated industries may eventually require SOC 2 or ISO 27001, but that's usually a later-stage requirement, not the first ask.
What if we genuinely don't have MFA or an incident response plan yet?
Say so, and attach a remediation timeline. Reviewers respond better to an honest gap with a fix date than to a blanket "yes" that doesn't hold up under a follow-up call.
Does SB 2610 mean we're automatically compliant if we do IG1?
It means you're shielded from exemplary damages in a breach lawsuit if you've implemented the IG1 safeguards - it doesn't create blanket legal immunity and it doesn't replace what a customer's questionnaire is asking for, though the overlap is significant.
If a questionnaire is sitting in your inbox right now and you're not sure how your current setup holds up, start with a free IT assessment or contact us directly - we've walked Texas businesses through this exact deadline more times than we can count.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.