Vendor security questionnaires change slowly. A template written in 2021 is still in circulation, which is why most of them still ask about antivirus.
Five questions have nonetheless started appearing, mostly from regulated buyers and mostly driven by NIS2 and DORA supervision. They are worth preparing for, because a vendor who has an answer ready stands out sharply against one improvising.
1. “Describe your post-quantum cryptography position.”
What they are asking. Not whether you have solved post-quantum cryptography. Whether data they send you today is being recorded in a form readable later.
The weak answer. “We use TLS 1.3 and AES-256.” This does not address the question. Both are classical.
The strong answer. Name the deployed component: hybrid key agreement with X25519MLKEM768 on public endpoints, which browsers have negotiated by default since version 131. Then state honestly what is not covered, namely that certificate signatures remain classical, and why that is acceptable: signature forgery must happen during a live connection, so there is no harvest-now equivalent.
Give them the command. openssl s_client -connect yourdomain.com:443 -groups X25519MLKEM768. A claim a reviewer can verify in ten seconds is weighted differently from one they cannot.
2. “How would you detect modification of third-party code in your application?”
What they are asking. Supply chain compromise through a CDN or a widget vendor, which bypasses TLS, CSP, authentication, your WAF and your dependency scanner simultaneously.
The weak answer. “We only use reputable providers.” That is vendor selection. They asked about detection.
The strong answer. Subresource Integrity hashes generated at build time, plus Integrity-Policy enforced at the browser so a script added without integrity metadata is blocked rather than silently executed. Violations report to an endpoint that is alerted on.
Why almost nobody can answer this one.
3. “Is mail to your domain protected against transport downgrade?”
What they are asking. Whether an on-path attacker can strip STARTTLS and read mail sent to you in clear text.
The weak answer. Listing SPF, DKIM and DMARC. All three authenticate the message; none protect the connection. Answering with them signals you did not understand the question.
The strong answer. MTA-STS in enforce mode, with TLS-RPT enabled and the daily reports monitored. Name the RFCs, 8461 and 8460, and note that adoption across the top million domains is below one percent, which is why you treat it as a differentiator rather than a baseline.
The distinction the questionnaire itself gets wrong.
4. “How is certificate renewal performed?”
What they are asking. Two things at once: an availability risk, and crypto-agility.
The CA/Browser Forum ceiling is 200 days today, 100 days from March 2027, 47 days from March 2029. Domain validation reuse drops to 10 days on the same trajectory. A manual process does not survive the 2027 step.
The weak answer. “Certificates are renewed before expiry by the platform team.” This describes a person, and invites a follow-up about what happens when that person is unavailable.
The strong answer. ACME automation, with renewal triggered at a fixed fraction of remaining lifetime rather than a hardcoded number of days, so that the next ceiling reduction requires no change. Add external expiry monitoring, because automation that silently stops is worse than none.
This doubles as your crypto-agility evidence: a team that turns over its certificate population every few weeks can execute an algorithm migration.
5. “What continuous evidence can you provide, rather than a point-in-time assessment?”
What they are asking. This is the one driven most directly by NIS2 supervision, where the recurring audit failure is missing evidence rather than missing security.
A pentest report from March proves something about March. A SOC 2 Type II covers a window that has closed. Buyers under continuous obligations increasingly want to know how you would detect drift next month.
The weak answer. Attaching last year’s pentest.
The strong answer. A dated series rather than a snapshot: continuous external measurement with the raw observations retained, mapped to the control framework the buyer works in, plus an alerting path when a control regresses. State the scope boundary explicitly, because an external measurement does not cover encryption at rest, internal traffic or key custody, and claiming otherwise invites a correction.
The pattern across all five
Each question separates vendors who treat security as a document set from vendors who treat it as a running property of a system.
Three of the five can be verified by the reviewer without your cooperation, in under a minute, from a laptop. That changes the economics of answering: a false or inflated claim is not merely risky, it is trivially detectable, and being caught on one answer recontextualises every other answer in the response.
The corollary is the opportunity. Deploying the underlying controls is genuinely cheap. MTA-STS is two DNS records and a static file. Hybrid key agreement is one configuration line. Integrity enforcement is a header plus a build step. None of these is a quarter of engineering work, and all three produce answers most of your competitors cannot give.
The short version
Prepare answers to these five before they arrive, deploy the controls behind them, and hand the reviewer the verification command.
Questions that can be checked independently reward honesty asymmetrically, in both directions.
Ready to put this into practice?
Two ways to start — pick what fits. Free Scan if you want to see your security grade in 60s with no commitment. Free 14-day Growth trial if you're ready to monitor multiple domains, export NIS2 reports, and download Deal Reports — no credit card required.
No credit card · Cancel anytime · GDPR-ready · EU-hosted