9 Things to Do After a Customer or Bank Sends You a Security Questionnaire
From Inbox To Signed: A Security Questionnaire Walkthrough – Vendor Security Questionnaire Help For Houston Businesses
An ordered checklist for Houston businesses with 10 to 200 employees and a form due back this month.
A vendor security questionnaire lands when a customer's procurement team or your bank wants written answers about your IT controls before a contract, a renewal or an account review moves forward. The 9 steps below get a Houston business to answers it can prove, an honest plan for the gaps, and a shorter form next year.
Picture the moment. Your biggest customer's procurement team wants 40 answers about multi-factor authentication, backups and incident response, and the contract renewal is waiting on it. There is a signature line at the bottom with your name under it.
3 options present themselves. Fill it in optimistically tonight. Forward it to whoever handles IT and hope. Ask for an extension and lose a week. Each one skips the same step, which is finding out what you can show before you decide what to say.
Find Out Who Is Asking and What the Answers Decide
Steps 1 and 2: a 15-minute call that changes how long the form takes.
A vendor security questionnaire exists because the sender has to show someone else that its suppliers were checked. Before answering, a business should learn what decision the answers feed, who reads them, and which risk tier the sender has placed it in, because the tier sets how much proof is expected.
1. Know what the answers decide before you write one
The same form can gate a bid, a contract renewal, or nothing more than a yearly file update, and the right amount of effort is different for each. A general contractor's prequalification form decides whether a subcontractor can bid at all. A renewal form from an existing customer usually wants to see progress since last year. Owners who do not ask tend to treat every form as pass or fail and answer accordingly.
- Call or email the sender and ask what the questionnaire is for: new work, renewal, or annual review.
- Get the real deadline, and find out whether partial answers with dates are accepted.
- Find out who scores it: procurement, a security team, or an outside assessor.
- Request any scoring guide or minimum requirements in writing.
2. Learn which tier you are in, because the tier sets the length
Federal bank regulators issued joint guidance on third-party risk on June 6, 2023, and it applies to all banks with third-party relationships. The OCC, the Federal Reserve and the FDIC wrote in that guidance that "not all third-party relationships present the same level of risk or criticality to a bank's operations." Large customers sort vendors the same way. A firm that never touches the customer's systems or sensitive data belongs in a lower tier, and a lower tier means fewer questions.
- Describe in 2 sentences what you access: their network, their data, their site, or none of these.
- Say so plainly when a whole section does not apply, and name the reason.
- Check whether a shorter form exists for your tier before starting the long one.
The 2026 Travelers Risk Index found that fewer than 6 in 10 businesses formally assess their supply chain partners and vendors. A customer that sends you a questionnaire is in the group that does, and 53% of businesses in the same survey said they worry about lost income from a vendor or supplier incident.
Sort Every Question Before Anyone Starts Typing
Steps 3 and 4: the sort takes an hour and prevents the guessed yes.
Most vendor security questionnaires ask about the same 8 topics in different words. Sorting each question into yes with proof, yes without proof, or no, and naming one owner per question, shows a business exactly how much work stands between it and an answer it can sign.
3. Sort the questions into 3 piles so the real workload is visible
A 40-line vendor security questionnaire usually comes down to about 8 topics, each asked several ways. We see the same list on forms from contractors, operators, law-firm clients and banks. Once the questions are grouped, the form stops looking like 40 problems.
- Multi-factor authentication: on email only, or on remote access and admin accounts too.
- Endpoint protection on every computer, including shared and field machines.
- Backups: where the second copy lives and when a restore was last tested.
- Email authentication, so nobody can send mail that appears to come from your domain.
- Administrator access: who has it and how it is removed when someone leaves.
- A written incident response plan with a named person who declares an incident.
- Staff training on phishing and payment fraud, with dates.
- Evidence for all of the above, dated before today.
Mark each question with one of 3 labels. "Yes with proof" means a document or screenshot exists now. "Yes without proof" means you believe it is true and cannot show it yet. "No" means it is not in place. The middle pile is the dangerous one, and it is usually the biggest.
4. Give every question one owner so nothing gets answered by assumption
A 2022 joint advisory from CISA, the NSA and the FBI says a contract with an IT provider should specify "whether the MSP or the customer owns specific responsibilities, such as hardening, detection, and incident response." A questionnaire tests whether that split was ever written down. In a company without an IT department, questions default to the owner or the office manager, who then answers for systems an outside provider or a software vendor runs.
- Put a name beside each question: you, your IT provider, or the vendor of a specific system.
- Send each owner only their questions, with the deadline and the proof you need back.
- Keep policy questions yourself. Nobody outside can attest to what your staff are told to do.
Write Answers You Can Show, Including the No Answers
Steps 5, 6 and 7: proof, scope, and the honest no.
Every yes on a vendor security questionnaire should have a dated document behind it, every answer should match the scope word in the question, and every no should carry a date for when it changes. A customer's assessor can ask for evidence at any time, and a guessed yes is a written misstatement to a customer.
5. Attach a dated artifact to every yes so the answer survives a follow-up
In 2022 a cyber insurance policy was declared null and void from its inception after the insurer alleged the insured's MFA attestation did not match what was running. That case, Travelers v. International Control Services, involved an insurance application, and the same test applies to a customer form: someone can check the answer later. A control you cannot document is, for the customer's purposes, a control you do not have.
- Capture a screenshot of the MFA policy showing who it covers, with the date visible.
- Export the latest backup report and the record of the last test restore.
- Save the incident response plan and the security policy as dated PDFs.
- Pull the training completion report for the last 12 months.
6. Read the scope word in each question so a true answer does not become a wrong one
94% of businesses say they are familiar with MFA, and only 60% use it to validate administrative users, according to the 2026 Travelers Risk Index. That gap is where questionnaires go wrong. The form asks whether MFA is on "all remote access" or "all privileged accounts," the owner knows it is on email, and the box gets a yes.
Scope words to watch are all, every, any and always. For a Houston oil and gas service company or a construction subcontractor, "all devices" includes the laptops in trucks, the shared PC in the yard office and the tablets on the jobsite. If endpoint protection covers the office and not the field, the accurate answer is a partial one with a date.
7. Write the honest no with a date so the gap reads as a plan
An honest no has 3 parts: what is missing, who owns the fix, and the date it will be in place. In our experience, customer security teams are closing their own audit findings and want vendors who know where they stand. A no with a date gives them something to file. A yes they later disprove gives them a reason to drop a vendor.
- Close the cheap gaps before the deadline when you can: MFA on remote access, email authentication records, one real test restore.
- Give a realistic date for the rest. A missed date is worse than a later one.
- Never soften a no into "in progress" unless work has started and you can say what was done.
"Do not answer a security questionnaire the night it arrives. Sort it first. The pile that hurts people is the middle one, the things you believe are true and cannot show. Prove those or change the answer, and write the no answers with a date. A customer can work with a date."
Send It Back Once, Then Keep What You Built
Steps 8 and 9: the signature, and the pack that shortens the next form.
The person who signs a vendor security questionnaire should read every answer before it goes back, and the finished answers and evidence should be filed as one dated pack. The same pack answers the next customer, the bank, the cyber insurer, and the written-program standard in Texas SB 2610.
8. Have the signer read every line so the signature means something
The signature on a questionnaire belongs to the business, even when an IT provider wrote half the answers. In 35+ years doing this, the forms that caused trouble later were rarely the ones with a no on them. They were the ones nobody senior had read. A 30-minute sitting with the owner, the person who filled it in and whoever runs IT is enough.
- Walk the yes-without-proof pile one last time. Each item is now proven, changed to a no with a date, or marked not applicable.
- Return the form with the evidence attached and one named contact for follow-up questions.
- Send it through the channel the customer asked for, and avoid emailing passwords or full network diagrams.
9. File the answer pack so the next questionnaire takes an afternoon
Texas SB 2610 protects a business with fewer than 250 employees from exemplary damages if it maintained a conforming cybersecurity program at the time of a breach. The documents that satisfy a customer questionnaire are most of that program. For a business with 20 to 99 employees the standard is the CIS Controls Implementation Group 1, and the questionnaire topics in step 3 overlap it heavily.
- Store the completed form, every attachment and the list of promised dates in one folder with the year on it.
- Put the promised dates on a calendar with an owner, and send the customer the evidence when each one closes.
- Refresh the screenshots and reports on a schedule you will keep.
- Offer the pack up front next year. A customer who already holds current evidence often sends fewer questions.
One pack answers the customer, the bank and the insurer
The same controls sit behind all 3 forms. See how CinchOps cybersecurity services keep the evidence current for Houston businesses.
See what is covered →What Does Answering a Vendor Security Questionnaire Cost in Houston?
Mostly hours, and the hours depend on what already exists.
Answering a vendor security questionnaire costs time rather than a fee: an afternoon when a dated evidence pack already exists, and a week of evenings when it does not. Managed IT in Houston typically runs $100 to $250 per user per month, and the reports a questionnaire asks for should come out of that service.
The published CinchOps rate is a flat $100 to $250 per user per month, so a 25-person Houston firm budgets $2,500 to $6,250 a month for managed IT, with no long-term contract, no hidden fees and no cancellation penalty. Ask any provider whether answering questionnaires with you is inside the rate or billed as a project.
The larger cost is the gap work the form exposes. In the 2026 Travelers Risk Index, 40% of businesses had no written incident response plan. A firm in that group meets the question for the first time on a customer's form, with a deadline attached. If the questionnaire turned up more than a few no answers, put the fixes in next year's plan with the 2027 small business IT budget guide.
How CinchOps Can Help a Houston Business Answer a Security Questionnaire
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
For questionnaire season, CinchOps provides managed IT and cybersecurity specifically for 10 to 200 employee businesses in Houston, with help desk requests answered in under 15 minutes by a named engineer who knows the network being asked about.
- Through managed IT support, the patch, account and device reports a questionnaire asks for come from the tools already running your network.
- With cybersecurity services, threat monitoring runs 24/7, and the help desk is staffed Monday through Friday, 8 to 6.
- Top-tier plans under business continuity and disaster recovery include immutable, offsite, verified backups kept outside the Gulf Coast flood zone.
- CTO and CIO services cover the written policy and the incident response plan, drafted once and kept current.
- CinchOps serves Houston, Katy, Sugar Land and Cypress, and works with construction, oil and gas and law firms.
A questionnaire on your desk is a deadline, and the worst answer to it is a confident guess. Sort it, prove what you can, date what you cannot, and keep the pack. If you want someone to go through the form with you line by line, talk to CinchOps and bring the last one you signed.
Frequently Asked Questions
What is a vendor security questionnaire?
A vendor security questionnaire is a form a customer, bank or partner sends to a supplier asking for written answers about its IT security controls, such as multi-factor authentication, backups, incident response and staff training. The sender uses the answers to decide whether to start or continue the relationship, and usually keeps them on file.
Why did my bank send my business a security questionnaire?
Federal regulators expect banks to manage the risk of their third-party relationships. Joint guidance from the OCC, the Federal Reserve and the FDIC, issued June 6, 2023, applies to all banks with third-party relationships. If your business provides a service to the bank, the questionnaire is how the bank documents that it checked.
Can I answer no on a security questionnaire and still keep the customer?
Often, yes. A no that states what is missing, who owns the fix and the date it will be in place gives the customer's security team something it can accept and track. A yes that cannot be supported with evidence when the customer asks is the answer that puts the relationship at risk.
Who should fill out a vendor security questionnaire for a small business?
Whoever runs the technology should draft the technical answers, and the owner or an officer should read every line before signing. Policy questions stay with the business. Questions about systems run by an outside IT provider or a software vendor go to that provider, with a deadline and a request for proof.
What does it cost to answer a security questionnaire in Houston?
The form itself costs time, usually an afternoon when dated evidence already exists. Managed IT in Houston typically runs $100 to $250 per user per month, and the published CinchOps rate is a flat $100 to $250 per user per month. Ask whether questionnaire help is included in that rate or billed separately.
How long should a business keep its questionnaire answers?
Keep the completed form, every attachment and the list of promised dates together for at least as long as the customer relationship lasts. The pack is the starting point for next year's form, the bank's review and the cyber insurance renewal, and it is evidence that a security program existed on a given date.
Discover More
Resource
Sources
- OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management - issued June 6, 2023 by the OCC, the Federal Reserve and the FDIC.
- Travelers, 2026 Risk Index: cyber - vendor assessment, vendor income-loss concern, MFA use for administrative users, and incident response plan figures.
- CISA, NSA, FBI and partner agencies, Cybersecurity Advisory AA22-131A - contracts should specify which party owns hardening, detection and incident response.
- Insurance Journal, Travelers v. International Control Services - policy declared null and void after the MFA attestation dispute.
- Texas SB 2610, enrolled text - under 250 employees, headcount tiers, program in place at the time of the breach.