Is your client asking for ISO 27001?
6 min · March 2026 · Cesar Mella Diaz
Last updated: 3 October 2026
In 30 seconds
- If a large client asks you for proof of security, it's usually because the law requires them to control their suppliers.
- The questionnaire arrives right before signing or renewing: if your answers aren't ready, the contract waits.
- Organise your evidence once around ISO 27001 and answer every client from there, instead of starting from scratch each time.
Your client isn't asking you a favour
If a large client sent you a security questionnaire or asked for your ISO 27001 certificate before signing or renewing, it probably wasn't their idea. It was an obligation.
Companies in regulated sectors (energy, banking, health, digital infrastructure, public administration, among others) are subject to NIS2, and financial entities are also subject to DORA. Both require them to manage the security risk of their supply chain: it's not enough for them to be protected, they have to check that their suppliers are too.
That requirement flows down through contracts. If your company sells them software, services or anything that touches their systems or their data, you are that supply chain.
Outside Europe, something similar happens through a different route. In Chile, Law 21.719 makes a company responsible for how personal data is handled even when a supplier processes it on its behalf, and that also pushes security guarantees into contracts.
Why it lands on you specifically
It's not that your client distrusts you in particular. It's that, if they're covered, they have to assess any supplier with access to their systems or data, and you fall into that category the moment you sign with them.
That explains a pattern you probably recognise: the questionnaire shows up right before signing or renewing. It's not a coincidence. It's the moment your client has to record that they reviewed their supplier.
What a vendor security questionnaire is
It's a form, sometimes 20 questions and sometimes 200, asking things like: do you have a documented security policy? Do you encrypt data? Do you have a tested incident response plan? Do you assess the security of your own suppliers?
If your answers aren't ready, the process drags on for weeks. B2B SMEs spend 9 weeks a year just answering their clients' reviews (Vanta, 2025, survey by a GRC vendor). And meanwhile, your client could be evaluating a competitor who already had them.
How to answer it without hiring a consultant
- Identify which measures you already have, even if they aren't documented. Most SMEs do more than they think; they just haven't written it down.
- Prioritise what you're being asked, not a standard's full checklist. If the questionnaire asks about encryption and continuity, start there.
- Keep the evidence for each measure: a policy, a configuration screenshot, the log of a backup test.
- Organise it all around ISO 27001, not in a one-off document per client. That way, the next time you're asked the same thing (and you will be), you answer from what you already have.
From burden to sales argument
This is the shift in perspective that helps an SME supplier most: compliance isn't just the toll for keeping the contract. It's something you can show before anyone asks.
A company that answers quickly, with organised evidence and a visible Compliance Score, doesn't just clear the hurdle: it stands out from competitors who take weeks or improvise with a spreadsheet. When several suppliers compete for the same contract, that matters.
How Kardu helps
Kardu organises your compliance evidence around ISO 27001, the standard clients ask about most, and reuses it in NIS2, DORA, ENS and GDPR, so you don't repeat work every time a different client asks for something different. You can see what your assessment would look like with the Vendor Security Check tool.
If you want to understand why your client is required to review you, read our NIS2 guide.
Do you have a security questionnaire on your desk right now? Talk to us and we'll look at it together.
Frequently asked questions
What is a vendor security questionnaire?
It's a questionnaire a client sends you to assess your security before signing or renewing a contract with you. It asks about your policies, your backups, your incident response plan and whether you assess your own suppliers, among other things.
My client is asking for ISO 27001. What do I do first?
Identify which measures you already have in practice, even if they aren't documented, prioritise the ones your client asks about in their questionnaire and keep the evidence for each. You don't need to get certified right away to answer seriously: you need organised evidence.
Do I need a consultant to answer the questionnaire?
Not necessarily. Most questionnaires that SME suppliers receive can be answered with a platform that organises your evidence around ISO 27001, without relying on a consultant for every question.

← Back to blog