Vendor cyber security questionnaire
Security questions for vendors that hold or can reach your data or systems: controls, access, incidents, and how data is returned or deleted.
11 questions. Each shows the answer you need, why you ask and which kinds of supplier it's for.
1. Cyber security and data protection (11)
- Will you store, process or access any of our data or systems?
- Which security certifications or reports do you hold (for example ISO 27001, SOC 2)?
- Do you enforce multi-factor authentication for all staff with access to our data or systems?
- Where (which countries) will our data be stored and processed?
- Is our data encrypted in transit and at rest?
- Have you had a security incident affecting customer data in the last 3 years?
- How quickly will you notify us of a security incident affecting our data?
- Which subcontractors or cloud providers will have access to our data?
- How will our data be returned or deleted when the contract ends?
- How often do you run independent penetration tests, and can you share a summary?
- Do staff receive security awareness training at least yearly?
Track the answers, not just the questions
Once suppliers reply, Qeluntra keeps due-diligence evidence, remediation owners and deadlines in one place, linked to your contracts.
Track answers and evidence in Qeluntra, free How Qeluntra handles supplier risk
Free plan: no card, no expiration, one company workspace.
This questionnaire is a starting point, not legal or compliance advice. Adapt it to your contracts, your sector and the laws that apply to you. Question bank last reviewed 2026-09-25.