
A security questionnaire lands with a return date on it. The date was set by someone else, it sits inside the buyer's process, and it is usually the clearest picture you will get of when that buyer intends to decide.
Most organisations treat the form as an administrative task and put it with the other administrative tasks. The date says otherwise.
The buyer is discharging an obligation of its own. Where your service involves processing personal data on their behalf, UK GDPR Article 28 requires them to use only a processor that provides sufficient guarantees, in terms of expert knowledge, resources and reliability, that it will implement appropriate technical and organisational measures.
The ICO is clear about who carries that. It is for the controller to satisfy itself that the guarantees are sufficient in the context of the processing, taking account of the nature of the processing and the risk to the individuals concerned. That assessment has to happen before the processor is appointed, and controllers are expected to check compliance on an ongoing basis to satisfy the accountability principle.
Two consequences for you.
The buyer cannot proceed without an answer. The person chasing you is usually accountable internally for having carried out the check, which is why the chasing continues after you have explained that you are busy.
The buyer's timetable is set by their own decision, not by your capacity. Asking for an extension moves their decision, which is a different conversation to the one you think you are having when you ask for more time on a form.
Questionnaires vary in length and hardly at all in substance. They are asking who has access to what, how you know that, how you would find out if something went wrong, and who is accountable when it does.
The ICO notes that certification and codes of conduct can help a processor demonstrate sufficient guarantees. This is the practical reason a certificate shortens the exchange. It answers a block of questions with one artefact that someone independent has already tested, and it moves the conversation to the parts that are specific to your service.
That works both ways. Where you hold nothing independent, every answer is an assertion, and assertions invite follow-up questions. The second round is where questionnaires lose weeks.
More than most organisations expect, and less than they can prove.
The gap between those two is the real problem. The controls usually exist. Access is reviewed, backups are tested, starters and leavers are handled, and someone knows how an incident gets escalated. What is missing is the record showing when each of those last happened and who confirmed it, in a form you can attach to an answer.
Three checks worth running against the questionnaire in front of you.
For each question, decide whether you are describing a control or evidencing it. Anything you can only describe is a candidate for a follow-up question, so mark it now.
Look for questions you have already answered elsewhere. An ISO 27001 statement of applicability, a Cyber Essentials assessment, a DSPT submission and a previous questionnaire cover much of the same ground, and the answer you gave last time should still be true or should have been updated.
Check the age of what you are attaching. A policy last reviewed two years ago answers the question and raises another one.
Some questions will need work rather than retrieval, and the honest handling of those is what separates a credible response from a slow one.
Name the gap, say what you are doing about it and give a date. Buyers accept that far more often than sellers expect, because a dated remediation plan is something their own risk process knows how to record. A blank field, or an answer that reads as though it is hoping not to be examined, invites the follow-up round.
Where the gap is a certificate, be realistic about the calendar. Certification is issued by a body working to its own audit programme, so an ISO 27001 certificate is not something you can produce inside a two-week questionnaire window. See how long ISO 27001, Cyber Essentials and DSPT take for what sets each timeline.
For the mechanics of holding evidence once and using it in several places, see how to reuse compliance evidence across frameworks.
Naq holds your controls, the evidence behind them and the history of both in one place, which is the material a questionnaire asks for.
Controls sit against the requirements they satisfy, so when a question asks about access review or patching you are looking at the current state and the record behind it together. Every change is captured on the activity stream with previous and new values, and records are archived instead of deleted, so the question of when something was last reviewed has an answer you can point at. Evidence mapped once counts across ISO 27001, Cyber Essentials, the NHS DSPT and your GDPR obligations, so the second questionnaire is faster than the first.
Naq does not send questionnaires or complete them on your behalf. What it does is make the answers retrievable instead of reconstructed.
If a questionnaire is sitting on someone's desk with a date on it, book a fifteen-minute demo and we will look at how much of it your current evidence already answers.