A growing number of our clients have received the same email this year. A customer, usually a larger one, sends a spreadsheet with forty to two hundred questions about information security and asks for it back within a few weeks. The questions cover patching, backups, access control, incident handling, hosting location, encryption and who to call if something goes wrong. The email is polite and non-negotiable, and it lands on whoever runs the website.
The reason is regulatory. The NIS2 directive requires organizations in essential and important sectors to manage the security of their supply chain, and the Cyber Resilience Act, whose first reporting obligations took effect on September 11, adds requirements for anyone who makes or distributes digital products. Neither law targets a small business directly, but both push the questions downstream: if you supply a covered organization, or run a site they depend on, their compliance team now has to ask you. This article is about how a well-run website answers those questions, in an afternoon, with evidence rather than adjectives.
The questions are predictable
Questionnaires differ in format but rarely in substance. Almost all of them want to know:
- How quickly security updates are applied, and how you know they were.
- Whether data is backed up, how often, where, for how long, and when a restore was last tested.
- Who has administrative access, how that is granted and revoked, and whether multi-factor authentication is enforced.
- Where the site and its data are hosted, in which jurisdiction, and under what contract.
- Whether data is encrypted in transit and at rest.
- Whether the site is monitored, whether logs are kept, and for how long.
- What happens when an incident occurs: who is notified, how fast, and what the recovery plan is.
- Whether vulnerabilities are scanned for, and whether there is a way for outsiders to report one.
Read as a list, these are not compliance questions. They are a description of a website that is being looked after, and every item on the list corresponds to something a maintained site already does. The work is not in doing them; it is in being able to show it.
Answering with evidence
The difference between a strong answer and a weak one is specificity. "We keep the site updated" is an adjective. "Security releases for Drupal core and contributed modules are applied within the week of publication; the last five were applied on these dates; here is the release history" is evidence. For every site we maintain, that history exists in the client portal, because every release is on record.
The same pattern applies down the list. Backups: the schedule, the retention policy, the storage location, and the date and duration of the last restore drill. Access: a list of accounts, their roles, and the statement that two-factor authentication is enforced for all of them. Hosting: the provider, the data centers, the jurisdiction, and a copy of the data processing agreement. Monitoring: what is watched, where alerts go, and how long logs are retained. Each answer is a fact with a date next to it.
The hosting questions
Questionnaires from European customers increasingly ask where data lives and under whose law. For sites on our managed platform, the answer is short: infrastructure in the European Union, in Germany and Finland, operated by a European provider, under a data processing agreement we publish. Encryption in transit is universal, storage is encrypted, and the network path between the edge and the application is private. These are single sentences with documents behind them, which is exactly what a reviewer wants.
The incident questions
The section that gives most organizations pause is incident handling, because it asks about something that has not happened. The honest answer describes a process: how an incident would be detected, who is notified and within what time, how the site would be isolated and restored, how customers would be informed, and how the cause would be documented afterward. NIS2 sets notification windows for covered organizations, and their suppliers are expected to be able to feed those windows. A supplier who can say "we would know within minutes, you would hear from us within the hour, and restoration from a verified backup takes this long" is a supplier who can be kept.
Turning the answers into a document you keep
The first questionnaire is work. The second is mostly copying. We recommend that clients keep a short security overview, two or three pages, that answers the standard questions once and is updated when something changes. It links to the evidence rather than repeating it: the release history, the backup drill log, the hosting agreement, the accessibility statement, the privacy policy. When the next spreadsheet arrives, most of the cells are filled from the document, and the remainder are specific to the customer's format.
The document has a second use. It is a good internal checklist. Writing down "two-factor authentication is enforced for all administrative accounts" is the moment you discover whether it actually is, and the sentence you cannot yet write truthfully is the next item on your maintenance plan.
What this means if your site is not there yet
If some of the answers above would be uncomfortable today, that is useful information rather than a crisis. Every item on the list is ordinary work: a maintenance routine, a backup policy with drills, a review of accounts, a firewall in front of the site, monitoring that reaches a person. We do this work as a matter of course, and we help clients assemble the overview document that turns it into answers. If a questionnaire has landed on your desk, or you would like to be ready before one does, talk to us. The first one is the hard one, and it does not have to be hard.
