- A supplier list ranked by what each supplier can reach or break — data, systems, production, deliveries
- A named recipient at each supplier who can actually answer, not merely forward
- Your own answers to these same questions, because suppliers will ask them back
Supplier Security Questionnaire
A plain-language questionnaire a small supplier can actually answer — one question per practice area, a Yes / Partial / No scale, and an evidence-requested column — with guidance on reading the answers honestly: a dated Partial beats an unsupported Yes.
Purpose, inputs, and completion
Purpose. Your security now includes everyone who holds your drawings, ships you components, or dials into your machines — and most of them are small businesses who will never complete a 300-question spreadsheet honestly. This questionnaire asks one plain question per practice area, in language a two-person shop can answer truthfully, and requests evidence rather than promises. Its output is not assurance; it is information for your own vendor risk decisions.
When to use it. Send it to suppliers in order of what they can reach or break, addressed to a named person who can answer. When answers return, read them with the section-three guidance — the goal is an honest picture, not a perfect score — and carry the results into the vendor risk assessment worksheet (ATL-028) where decisions get made. Re-issue annually to critical suppliers and compare against last year's answers; the direction of change is the signal.
- Send in criticality order — the machine shop holding your drawings before the office-supplies vendor.
- Ask for evidence with every answer; a dated screenshot or policy page turns an assertion into information.
- Read Partial answers charitably and unsupported Yes answers skeptically — a dated Partial beats an unsupported Yes.
- Right-size for very small suppliers: a two-person shop answering honestly about MFA and backups is worth more than a boilerplate attestation package.
- Decide before sending what you will do with weak answers, so results flow into vendor risk decisions (ATL-028) instead of a folder.
Evidence, validation, and failure modes
- Dated, answered questionnaires per supplier
- An evidence file of supplier-provided attachments
- Structured inputs feeding the vendor risk assessment (ATL-028)
- Pick one returned questionnaire and check every Yes for attached evidence; count how many are unsupported.
- Confirm every critical supplier's answer set is under a year old; older answers are history, not posture.
- The questionnaire goes to every supplier identically, burying the ten that matter under two hundred that do not.
- Answers are filed unread, and the questionnaire becomes a ritual that produces paper instead of decisions.
- It gets treated as a contract instrument — it is not a flowdown, it verifies nothing, and it cannot substitute for contract terms your counsel writes.
Practices and requirements this artifact relates to
Brilliant at the Basics practices
NIST SP 800-171 Rev. 2
NIST SP 800-171 Rev. 3
Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain returned questionnaires for the life of the supplier relationship plus one review cycle; the year-over-year change in a supplier's answers is the most honest trend data you will get.
Preview — exactly what prints
Supplier Security Questionnaire
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
Your security now includes everyone who holds your drawings, ships you components, or dials into your machines — and most of them are small businesses who will never complete a 300-question spreadsheet honestly. This questionnaire asks one plain question per practice area, in language a two-person shop can answer truthfully, and requests evidence rather than promises. Its output is not assurance; it is information for your own vendor risk decisions.
How to use it
Send it to suppliers in order of what they can reach or break, addressed to a named person who can answer. When answers return, read them with the section-three guidance — the goal is an honest picture, not a perfect score — and carry the results into the vendor risk assessment worksheet (ATL-028) where decisions get made. Re-issue annually to critical suppliers and compare against last year's answers; the direction of change is the signal.
Before you send it
This is not a contractual flowdown, and it does not verify anything — it collects a supplier's own statements, which are only as good as the evidence attached to them. Contractual security obligations, DFARS flowdowns, and audit rights are contract matters for your counsel; this questionnaire informs your risk decisions and cannot substitute for any of that.
For a supplier of a handful of people, consider walking through the questions on a call and recording their answers rather than mailing a form. Honest, specific answers from a small shop — 'MFA on email, not yet on the ERP; last restore test in March' — are exactly what this instrument exists to collect.
Questionnaire
One question per practice area. Answer Yes, Partial, or No, and attach the requested evidence — a Partial with a date is a better answer than a Yes with nothing behind it.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Area | Question | Answer (Yes / Partial / No) | Evidence requested |
|---|---|---|---|
| EXAMPLE: Identity and MFA | Do all accounts that can reach systems used for our work require multi-factor authentication? | Partial — MFA on email and VPN, not yet on the ERP | MFA policy export, dated 2026-06 |
| Identity and MFA | Do all accounts that can reach systems used for our work require multi-factor authentication? | MFA policy or settings screenshot, dated | |
| Asset inventory | Do you keep a current list of the computers and accounts used for our work? | Inventory export date and device count (not the list itself) | |
| Patching | Are the systems used for our work updated on a regular schedule — and what happens to systems too old to update? | Patch cadence statement; end-of-life handling | |
| Backup and restore testing | Are those systems backed up, and when did you last successfully restore from a backup? | Date and result of the last restore test | |
| Remote access | How do your staff and your vendors access your systems remotely, and is that access logged? | Description of pathways; MFA and logging confirmation | |
| Incident notification | If you had a security incident affecting our data or our deliveries, when and how would you tell us? | Named contact and committed timeframe | |
| Training | Do the people who handle our work receive security awareness training, including phishing? | Date and audience of the last session | |
| Supply chain | Do you ask your own critical suppliers any of these questions? | An example, or a statement of practice |
Reading the answers
How to read what comes back
- A dated Partial beats an unsupported Yes
- 'Partial — MFA rollout finishes Q4' with a screenshot is a supplier telling the truth; a bare Yes across all eight rows is a supplier finishing a chore.
- Read the evidence column first
- Count answers with real evidence attached. That count, more than the Yes count, is the supplier's actual posture.
- The incident-notification answer is the one you will personally need
- A named contact and a committed timeframe are worth more to your worst week than any other row on the form.
- No answer is an answer
- A critical supplier who will not respond after two asks has told you something; record it in the vendor risk assessment (ATL-028).
For machine builders, maintenance contractors, and integrators, weight the remote-access and incident-notification answers heavily — their access reaches production, and a weak answer there is an uptime risk, not a paperwork gap. If an answer prompts you to change how such a vendor connects, schedule the change with the vendor and the process owner through a maintenance window rather than cutting off access mid-support-contract, and cross-check what they claim against their rows in your remote access pathway inventory (ATL-026).
Document control, version history, and approval
An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.
| Field | Entry |
|---|---|
| Document owner (named person) | |
| Suggested owner role | Procurement lead |
| Approval authority | Executive sponsor |
| Review frequency | Annual re-issue for critical suppliers; at onboarding for every new supplier |
| Next scheduled review | |
| Storage location of the completed document | |
| Retention | Retain returned questionnaires for the life of the supplier relationship plus one review cycle; the year-over-year change in a supplier's answers is the most honest trend data you will get. |
Version history
| Version | Date | Author | Summary of change | Approved by |
|---|---|---|---|---|
Review and approval
| Reviewed by | Role | Date | Signature / initials |
|---|---|---|---|
Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.
This is independent educational material. Completing it documents your work and produces records a reviewer can examine — it does not, by itself, implement a safeguard, satisfy any NIST SP 800-171 requirement, establish compliance with DFARS or CMMC, or replace your own analysis within your defined system boundary. Requirement references are mapped relationships, not equivalence claims. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.