Customer requirement
How to answer a customer’s security annex
In short
A security annex or supplier assessment almost always asks about the same ten things: management system and policies, access control, encryption, backups, incident management, subcontractors, data processing agreements, continuity, vulnerability management and certifications. Answer truthfully with “yes”, “partly, done by …” or “no”, attach evidence where you have it, and build an answer bank so the next customer takes an hour instead of a week. A “no” without a plan is the only answer that stops the deal.
Last reviewed: September 2026
What the security annex actually asks
The questions derive from the customer’s own requirements — often ISO 27001, NIS2 or an industry framework — translated into supplier questions. Questionnaires are therefore predictable.
| Area | What they want to see |
|---|---|
| Governance | Information security policy, named owner, risk assessment, management commitment |
| Access | MFA, authorisation, offboarding, admin access |
| Encryption | Data at rest and in transit, key management |
| Operations | Backups, restore tests, patching, logging |
| Incidents | Procedure, contact route, deadlines for informing the customer |
| Subcontractors | List, contracts, where data is stored, processing agreements |
| People | Background checks, confidentiality, training |
| Continuity | Continuity plan, RTO/RPO, testing |
| Testing | Penetration tests, vulnerability scanning, how findings are fixed |
| Evidence | ISO 27001 certificate, SOC 2 report, audit reports |
How to answer without lying or losing the deal
- “Yes” only when you can show evidence if asked. A false yes is found in the next audit and hurts more than an honest no.
- “Partly” with a date: “Access policy in place, MFA for all systems by 30 November.” Customers accept plans, not silence.
- “No, not applicable” with a reason: you process no sensitive personal data, you run no data centre of your own.
- Attach evidence where it exists: policy PDF, screenshot of MFA settings, the latest restore test.
- Ask back when something is unclear. A questionnaire written for banks rarely fits a 30-person SaaS supplier, and the customer knows it.
The answers that stop the deal
Three answers almost always lead to rejection or a remediation demand before contract: no MFA on systems holding customer data, no incident procedure with a contact route, and no processing agreement with subcontractors handling personal data. Fix these three before you submit — they take days, not months.
Build an answer bank you reuse
- 1Collect every question you have received, group by the areas above and write one standard answer per question.
- 2Link each answer to its evidence: where the policy lives, which control proves it, who owns it.
- 3Date the answers and set a reminder: last year’s answer about patching is a promise you must keep.
- 4Publish what you can. A trust page with policies, subcontractors and certificates shortens the next assessment.
- 5Once you have ISO 27001, send the certificate and statement of applicability first. Many customers then skip half the questionnaire.
How Isodora helps with security annexes
Isodora keeps policies, controls, owners and evidence together, so the answer to every supplier question already exists — with evidence attached. Trust Center publishes what you choose to share and receives requests in one place.
Answers with evidence, not just words
Every control has an owner, a status and time-stamped evidence. That is exactly what the questionnaire asks for.
Supplier register
Subcontractors, data locations and processing agreements in one register you can export straight into the annex.
Trust Center
A public page with policies, certificates and a contact route for security questions. The next customer finds the answers themselves.
ISO 27001 as the end goal
The same material that answers the annex is what you need for certification. Two problems, one piece of work.
Isodora helps you structure and evidence your security work. Which answers an individual customer accepts is the customer’s decision.
Frequently asked questions
- How do you answer a security annex without ISO 27001?
- Answer honestly per question with yes, partly with a date, or no with a reason, and attach evidence where it exists. Most customers accept a company without a certificate if the basics are there: MFA, incident procedure, backups, processing agreements and a named owner. Add a certification timeline if the customer requires it.
- What is the difference between a security annex and a supplier assessment?
- The security annex is the contract text with the requirements you commit to. The supplier assessment is the questionnaire the customer uses to check that you meet them, often before contract and then annually. The answers in the assessment become, in practice, promises under the annex.
- How long does it take to answer a supplier questionnaire?
- The first time, often one to two weeks of calendar time for a small company, because answers must be written and evidence found. With an answer bank and a tool where evidence already exists, the next questionnaire takes a few hours.
- Can we refuse to answer questions that are not relevant?
- Yes, with a reason. Mark the question not applicable and explain why, for example that you run no data centre or process no sensitive personal data. Customers prefer a clear not-applicable to an invented yes.