Kardu
← Back to blogNIS2

Is your client asking for ISO 27001?

6 min · March 2026 · Cesar Mella Diaz

Last updated: 26 August 2026


Your client isn't asking you a favor

If a large client sent you a security questionnaire or asked for your ISO 27001 certificate before signing or renewing a contract, it probably wasn't their idea. It was an obligation.

Companies operating in regulated sectors — energy, banking, healthcare, digital infrastructure, public administration, among others — are subject to NIS2, and financial entities are also subject to DORA. Both regulations require these companies to manage the security risk of their supply chain: it's not enough for them to be secure themselves, they have to verify their suppliers are too.

Outside Europe, a similar logic shows up through a different route: in Chile, Law 21.719 holds companies accountable for how personal data is handled even when that processing is done by a third party (a supplier). That also pushes security requirements down the contract chain, even though the legal mechanism differs from NIS2's.

That requirement flows down contractually. And if your company sells them software, services, or anything that touches their systems or their data, you are that supply chain.

A single chain link, representing supply chain security

Why it lands on you specifically

It's not that your client distrusts you in particular. It's that the law requires them to assess any supplier with access to their systems or data, and you fall into that category the moment you sign a contract with them.

This explains a pattern you've probably already noticed: the questionnaire shows up right before signing, or right before renewal. That's not random — it's the point in the process where your client has to document that they did their due diligence.

What a Vendor Security Questionnaire is

It's a form, sometimes 20 questions and sometimes 200, asking things like: do you have a documented security policy? Do you encrypt data in transit and at rest? Do you have a tested incident response plan? Do you assess the security of your own suppliers?

If you don't have answers ready, the process drags on for weeks. And during those weeks, your client could be evaluating a competitor of yours who already had them.

How to answer it without hiring a consultant

  1. Identify what controls you already have, even if not formally documented — most SMEs do more than they think, they just haven't written it down.
  2. Prioritize what you're actually being asked, not a full standard's checklist. If the questionnaire asks about encryption and business continuity, start there.
  3. Document the evidence for each control: a policy, a configuration screenshot, a backup test log.
  4. Organize it around ISO 27001, not as a one-off document per client — so the next time you're asked the same thing (and you will be), you answer in minutes, not weeks.

From burden to sales asset

Here's the shift in perspective that matters most for an SME supplier: compliance isn't just the toll you pay to keep the contract. It's something you can proactively show, before anyone even asks.

A company that answers a security questionnaire in a day, with organized evidence and a visible Compliance Score, doesn't just clear the hurdle — it stands out from competitors who take weeks or improvise with a spreadsheet. In a buying process where several suppliers are competing for the same contract, that matters.

Organized compliance documentation, ready to show as a sales asset

How Kardu helps

Kardu organizes your compliance evidence around ISO 27001 — the standard most often asked about — and automatically maps it to NIS2, DORA, ENS and GDPR, so you don't repeat the work every time a different client asks for something different. You can try what your assessment would look like with the free Vendor Security Check tool.

If you want to understand why your client is legally required to audit you in the first place, read Supply chain security: the NIS2 obligation most companies ignore.

Do you have a security questionnaire on your desk right now? Talk to us and let's look at it together.

Cesar Mella Diaz

Cesar Mella Diaz

Kardu Founder

LinkedIn →

← Back to blog