Vendor Risk Questionnaire by Qeluntra

Vendor cyber security questionnaire

Security questions for vendors that hold or can reach your data or systems: controls, access, incidents, and how data is returned or deleted.

11 questions. Each shows the answer you need, why you ask and which kinds of supplier it's for.

1. Cyber security and data protection (11)

  1. Will you store, process or access any of our data or systems?Yes / NoWhy we ask: Determines whether the rest of this section applies. · Sent to: all supplier types
  2. Which security certifications or reports do you hold (for example ISO 27001, SOC 2)?Document requestedWhy we ask: Independent assurance of security controls. · Sent to: IT and software, Professional services
  3. Do you enforce multi-factor authentication for all staff with access to our data or systems?Yes / NoWhy we ask: MFA prevents most account takeovers. · Sent to: all supplier types
  4. Where (which countries) will our data be stored and processed?TextWhy we ask: Data location affects legal obligations and risk. · Sent to: IT and software, Professional services
  5. Is our data encrypted in transit and at rest?Yes / NoWhy we ask: Encryption limits damage if data is intercepted or stolen. · Sent to: IT and software, Professional services
  6. Have you had a security incident affecting customer data in the last 3 years?Yes / NoWhy we ask: Past breaches indicate risk and response maturity. · Sent to: all supplier types
  7. How quickly will you notify us of a security incident affecting our data?TextWhy we ask: Fast notification lets us meet our own obligations. · Sent to: all supplier types
  8. Which subcontractors or cloud providers will have access to our data?TextWhy we ask: Each additional party widens exposure. · Sent to: IT and software, Professional services
  9. How will our data be returned or deleted when the contract ends?TextWhy we ask: Prevents data being left behind after exit. · Sent to: IT and software, Professional services
  10. How often do you run independent penetration tests, and can you share a summary?Document requestedWhy we ask: Shows weaknesses are looked for and fixed. · Sent to: IT and software, Professional services
  11. Do staff receive security awareness training at least yearly?Yes / NoWhy we ask: People are the most common entry point for attacks. · Sent to: all supplier types

Track the answers, not just the questions

Once suppliers reply, Qeluntra keeps due-diligence evidence, remediation owners and deadlines in one place, linked to your contracts.

Free plan: no card, no expiration, one company workspace.

This questionnaire is a starting point, not legal or compliance advice. Adapt it to your contracts, your sector and the laws that apply to you. Question bank last reviewed 2026-09-25.